Live data from Hacker News

$625M worth of ETH drained on Axie Infinity's Ronin Network

roninblockchain.substack.com

431–440 of 761 posts

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#431
post #149

Earlier quoted context omitted.

No, $625M transfer out of a single bank account would raise tons of eyebrows. No way it’s authorized by some env vars.

If the hackers are sophisticated, I would think they would start wiring in much smaller amounts and thru accounts so tracing is harder. Much like what they are going to have to do with the funds in that wallet. If they setup some plausible 3rd party company the game studio could use and started transfers of $10k a pop it might be some time before anyone catches it.

That is slow anything over 10,000 in bank transfers will reviewed, and there will be a dedicated account manager for a 600m account.

They are going to review and flag it. You might loose few hundred thousands but not all 625m.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#432
post #369
post #119

Earlier quoted context omitted.

> Fort Knox gold reserves in your spare room What do you mean a wooden safe isn't good enough?! Joke aside. This is the reality we live in. Almost makes heist movies pale in comparison. The failed Die Hard heist was planned in order to steal $640M. I wonder how long until Hollywood will start making movies about these hacks.

There is a whole genre of teen thriller movies that play out entirely in the medium of messages sent back and forth on phone screens. It's exactly as exciting as you can imagine.

Probably about as exciting as stacking icons on ingame maps.

https://youtu.be/W12zKDvHsQI

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#433

This is the kind of pain that comes from trusting scammers and nincompoops about unworkable blockchain "scalability" fixes. Here's the sequence. Those dumb enough to ignore it are doomed to repeat the pattern. I'm probably getting some details wrong in this Rube Goldberg scheme, so feel free to correct. 1. Citing "Ethereum network congestion," Axie Infinity announces an ethereum side chain, Ronin.[1] 2. Ronin was a c…

Right now they're immature, but I'm hopeful that advancements in ZK-tech will allow practical ZK-rollups. ZKSync already has a zk-evm testnet running (which I believe is based on zk-llvm), so we're close. Currently all the big rollups have master keys which can be used to steal all the money deposited by them, but there's no reason in principle they have to have this. Polygon has permissionless rollups, so I'm quite…

The crypto(graphy) is rarely the weakness in these situations, so declaring faith in (insert new tech buzzword here) is almost certainly not going to be the answer. It comes down to operational and human factors, like poorly written code. (new tech buzzword) will involve lots of new code, and why do people think this time the new code will be error-free?

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#434
post #47

In a system run by people, the transaction could be reversed, traced, and the culprits eventually brought to justice. In a system run by algorithms, designed to avoid oversight by people (governments), there is no such powers. There's no reversal. There's no checking the name on the account the transfer was to. It's just gone. I do not understand why people who have legal intentions would want to be part of the crypt…

> I do not understand why people who have legal intentions would want to be part of the crypto economy. There's nothing but more risks with zero benefits. I agree 100% on the risk, and my main problem with it is the avg person getting caught up in it. But at the same time, you see all the "PayPal froze my funds" posts, etc, so obviously the current system is flawed in its own way. You could imagine a future in which…

I agree. The crypto industry has made a lot of progress toward securing private keys, with another 5-10 years of cryptography I think it will be a somewhat 'solved problem', thereby allowing companies like PayPal to offer their own custodial / layer 2 services with minimal risk.

Institutional-quality digital asset custody and signing was basically non-existent until Fireblocks launched just over two years ago, and there is still a lot of progress to be made on cryptography primitives and infrastructure best practices.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#435

Earlier quoted context omitted.

This incident reinforces the rule never to use your debit card for credit card transactions.

Ever, never, never use your debit card where credit card can be used in its place. The mechanisms for restoring the charge on your credit card are much stronger than on your debit card. And a credit card is a FUTURE charge, so you have time to fix the problem. Whereas a debit card is your CURRENT money, so it's just gone unless you get it back. I do not understand why people use debit cards linked to their actual ban…

100%. The account linked to my debit card is empty unless I want to make an immediate withdrawal at an ATM. This being 2022, I can transfer whatever funds are necessary into the account in a minute or two using an app on my phone. I also have a separate checking account for linking to external services like Cash App, Venmo, or third-party bill pay systems. Again, the account remains permanently empty except for the brief window where I'm moving money between these services or paying a bill.

Given how quick and painless it is to transfer money between accounts, leaving substantial amounts of money in accounts linked with mechanisms that can remove that money is insane to me.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#436

Earlier quoted context omitted.

Right now they're immature, but I'm hopeful that advancements in ZK-tech will allow practical ZK-rollups. ZKSync already has a zk-evm testnet running (which I believe is based on zk-llvm), so we're close. Currently all the big rollups have master keys which can be used to steal all the money deposited by them, but there's no reason in principle they have to have this. Polygon has permissionless rollups, so I'm quite…

The crypto(graphy) is rarely the weakness in these situations, so declaring faith in (insert new tech buzzword here) is almost certainly not going to be the answer. It comes down to operational and human factors, like poorly written code. (new tech buzzword) will involve lots of new code, and why do people think this time the new code will be error-free?

In this case, the weakness was that the keys that controlled the bridge were somehow stored insecurely. When attackers gained access to the keys, they were able to steal from the bridge. In a properly-implemented rollup, there are no keys to secure, so this attack vector is ruled out.

But more broadly, there is really nothing else with the same security properties as a smart-contract-enabled cryptocurrency. Paypal will delete your account any time they want, Visa and Mastercard will blacklist whatever industries they feel like blacklisting, etc. If you want a system that's decentralized and where these attacks aren't possible, you have no alternative. The problem is that current blockchain-based systems can only handle a certain number of operations/second while remaining decentralized. The appeal of scaling solutions like ZK-rollups is that they give us the same security properties as the main chain without any security compromises (relative to the main chain). That's all conditional on their code being correct, but given that there's such a large payout to hacking e.g. bitcoin or ethereum or zksync and it still hasn't happened, we can guess that the coders have done their jobs well and such problems are at least very difficult to find.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#437

This is the kind of pain that comes from trusting scammers and nincompoops about unworkable blockchain "scalability" fixes. Here's the sequence. Those dumb enough to ignore it are doomed to repeat the pattern. I'm probably getting some details wrong in this Rube Goldberg scheme, so feel free to correct. 1. Citing "Ethereum network congestion," Axie Infinity announces an ethereum side chain, Ronin.[1] 2. Ronin was a c…

This is exactly why crypto is such a disaster. Every week there is yet another scam where people losing their money. The feedback from crypto enthusiasts is well look at those idiots for putting their money into some scheme or you are not smart enough use this thing. Look "nobody" understands what you are talking about. These financial systems are inscrutable and the problem is getting worse. You are building systems…

> You are building systems that are ruining peoples lives and making things worse for everyone.

Don't invest more than you can afford to lose, it's the basis of any investment strategy. If someone puts enough money into highly risky, speculative assets such as these that it would ruin their life, then they only have themselves to blame if you ask me... People have to take responsibility for their own choices.

Edit: -4 that's a new record for me, thanks guys!

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#438

Earlier quoted context omitted.

I am blaming the developers. Perhaps this is not a popular view, but this "blameless" culture is fine and good when it's a random service going down for 15 minutes and you're trying to collaborate and prevent it from happening again. There must be limits though. If you're handling that amount of money in a bank and you fuck it up like this, your ass is on the line, together with the ones who incentivized you to move…

This is like the contractors working on the Death Star when it was blown up.[1] They knew what they were working on. They knew the dangers. Can't cry for them when they're blown to smithereens. I've been asked on two separate occasions to work on some crypto startup idea. Aside from my skepticism that they were even worthwhile projects, I declined because hell no I'm not writing code that touches other people's money…

In the real world a lot of army is conscription. Typically it not freelance mercenaries it can also be prisoners or threatened/coereced labour. Star wars actually highlights this in Rogue one.

Also in many economies this is literally only job available, same reason why syrian fighters are ready to go to Ukraine.

While death star attack wasn't a war crime, they weren't civies after all, it wasn't a simple as they knew the dangers

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#439
post #411
post #351

Earlier quoted context omitted.

not your keys, not your crypto :) your crypto won't get stolen if you have good opsec

Well, in this particular case, the keys got stolen. Which is a massive crypto UX issue.

If its a UX issue then are you implying that wallets should have certain security levels that limit their maximum account balance? I mean mandatory multi sig for anything above $1 million.

Because I don't see how else you are going to solve this problem other than by refusing to accept that much money.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#440

Earlier quoted context omitted.

> I don't recall last time seeing news on someone's bank account being hacked and drained, if anything its mostly family fraud. Anecdote time. My wife and I have a shared checking account that got hacked and drained. First her debit card got skimmed. Then the perp called USAA a half dozen times claiming to be her and asking for account credentials. Finally they got a helpful account rep to reset the password, disable…

> but now they punish my wife with a 10-minute interrogation to prove her identity if she ever has to get them on the phone for a legitimate reason. How is that punishment? If USAA knows you or your wife were a target of somewhat sophisticated attack that ultimately broke their security barriers, wouldn't you yourself actually want some extra protection? If anything, this is a positive sign for USAA, I doubt with my…

I call it punishment because I don't think the attack was really sophisticated, I think USAA's internal training and software was wholly inadequate to defend against a persistent unsophisticated attacker. Why were they still routing his calls to regular bank tellers after the first couple attempts? Why wasn't the security department involved at that point as the only allowable contact point? Why did they actually hand out the login name and password for an account without doing the 10 minute deep-dive identity verification they now make my wife do?
Post reply on HN