Live data from Hacker News

$625M worth of ETH drained on Axie Infinity's Ronin Network

roninblockchain.substack.com

581–590 of 761 posts

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#581
post #575

Earlier quoted context omitted.

Everyone who had overseas bank accounts in 2002 Argentina did just fine. Bitcoin on a foreign exchange or in a self-custody wallet would also be just fine. Getting a foreign bank account is too expensive for your average Argentinian because you have to show up in person to set it up, but a self-custody wallet can be had on any minimal smart phone.

People who wanted self-custody could also keep their money under the mattress. The reason why most cryptocurrency users do not do that is because there are many failure modes which result in your money being gone forever. You also left out the other part of the overseas bank accounts: you have to be rich enough not to need to touch the money — otherwise you'll run into the various restrictions on transfers. The same…

You vastly overestimate the effectiveness of the Argentinian government in enforcing currency controls and so forth.

Keeping money under the mattress is done in Argentina, but is not that common for large amounts since getting your hands on physical dollar bills in quantity in Argentina is extremely difficult. It's also difficult to determine if the bills are counterfeit, but Bitcoin does not have this problem.

I have heard stories of people paying their living expenses in Bitcoin and the people who receive it love that because the Argentinian peso is constantly devaluing. The person they pay spends all their money on the person paying them bitcoin because the currency devalues like crazy anyway, so it's much better to pay Pesos and save in Bitcoin.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#582
post #189
post #127

Earlier quoted context omitted.

Unlike traditional banks with their burdensome regulations and gate-keepers, the permissionless, decentralized nature of the blockchain means that they can't get the money back.

The increased risk of total loss in the edge case is in exchange for a more efficient system with lower prices in the average case. Individual users should make an informed decision about the tradeoff. See also http://go/hackernews/item?id=30838572 and https://en.wikipedia.org/wiki/Financial_crisis_of_2007%E2%80...

oh cmon, this comment (gowld's) should not be downvoted like that. It's a reasonable point to make even if you disagree with it

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#583

Earlier quoted context omitted.

> but now they punish my wife with a 10-minute interrogation to prove her identity if she ever has to get them on the phone for a legitimate reason. How is that punishment? If USAA knows you or your wife were a target of somewhat sophisticated attack that ultimately broke their security barriers, wouldn't you yourself actually want some extra protection? If anything, this is a positive sign for USAA, I doubt with my…

I call it punishment because I don't think the attack was really sophisticated, I think USAA's internal training and software was wholly inadequate to defend against a persistent unsophisticated attacker. Why were they still routing his calls to regular bank tellers after the first couple attempts? Why wasn't the security department involved at that point as the only allowable contact point? Why did they actually han…

I guess on the bright side, nobody will ever hack into your USAA account :)

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#584

This is the kind of pain that comes from trusting scammers and nincompoops about unworkable blockchain "scalability" fixes. Here's the sequence. Those dumb enough to ignore it are doomed to repeat the pattern. I'm probably getting some details wrong in this Rube Goldberg scheme, so feel free to correct. 1. Citing "Ethereum network congestion," Axie Infinity announces an ethereum side chain, Ronin.[1] 2. Ronin was a c…

Right now they're immature, but I'm hopeful that advancements in ZK-tech will allow practical ZK-rollups. ZKSync already has a zk-evm testnet running (which I believe is based on zk-llvm), so we're close. Currently all the big rollups have master keys which can be used to steal all the money deposited by them, but there's no reason in principle they have to have this. Polygon has permissionless rollups, so I'm quite…

> Right now they're immature

It's 14 years old.

The community has had a fix for all of these problems just over the horizon for a decade. It just isn't coming.

The real issue is that most of the crypto being held is held by people who don't care about using it as currency or for anonymity, they're using it as an "investment". That's why when coins that work better as cash or privacy or whatever come out, nobody cares, they just keep trucking on with bitcoin. All they care about is that the value of bitcoin goes up.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#585

Earlier quoted context omitted.

You're arguing a strawman.

With all due respect, I don't think you understand the full weight of what you're arguing. Which was the point of my original comment. You don't get to just pick-and-choose which aspects of crypto are beneficial and ignore the side-effects. Crypto, by design, bypasses the legal system. There are some heavy consequences to that design.

I acknowledge the higher risk associated with crypto and self-custody. I just think the capability it provides is valuable. Like most things it's a nuanced issue and it's not all good or bad.

A lot of your argued side-effects are also true of cash. Yet most (at least for now) are not arguing to get rid of cash because not every transaction can be monitored and controlled.

Crypto gives more capability to individuals which is good (similar to cash). It creates a store of value outside of government monetary policy (in the BTC case more similar to gold).

People tend to simplify these things into "crypto is entirely bad" or "crypto is entirely good". I think it's a new tool that gives individuals new capabilities, but also has its own risks. I value the new capabilities and acknowledge the risks.

> "Crypto, by design, bypasses the legal system. There are some heavy consequences to that design."

This is mostly false. In the case of public ledgers - it's even easier to see transaction history than it is with cash (though this is less true of Zcash). It doesn't bypass the legal system it just requires a higher degree of intervention for your money to be taken from you (which is often desirable, especially if living under an oppressive government). Does cash bypass the legal system by design?

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#587
post #278

5 of 9 validator nodes? The Byzantine Generals Problem Leslie Lamport, Robert Shostak, and Marshall Pease (1982) ACM Transactions on Programming Languages and Systems, Vol. 4, No. 3, July 1982, Pages 382-401 https://lamport.azurewebsites.net/pubs/byz.pdf From the abstract: ... It is shown that, using only oral messages, this problem is solvable if and only if more than two-thirds of the generals are loyal; so a singl…

This is not a Byzantine fault problem. Consensus was achieved as designed.

It was just the "wrong" consensus.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#588

Earlier quoted context omitted.

Voluntarily transferring money is very different from having it stolen. The bank should protect your money while holding it from theft. They can't protect you from your own decisions on how to use your money.

They voluntarily accepted a contract wherein they would transfer money in exchange for receiving a bicycle. No bicycle was received, so this voluntary decision does not mean that the money transfer was voluntary. They did not accept a contract wherein they would transfer money in exchange for nothing. Since they did not accept this contract, this does not make the money transfer be voluntary. Being a victim of fraud…

In the old American paper check system there was an important but subtle distinction between "fraud in the making" and "fraud in the inducement". If a criminal stole your checkbook and forged a check then an intermediary (like a bank or a grocery store) which cashed a stolen check could be on the hook for the money--if you protested to your bank the transaction could be reversed. However if the criminal simply induced you to write them a valid check (e.g. as payment for a non-existent bicycle) then any intermediary that cashed the check is not on the hook, and the only recourse is to get the money back from the criminal.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#589

Earlier quoted context omitted.

Right now they're immature, but I'm hopeful that advancements in ZK-tech will allow practical ZK-rollups. ZKSync already has a zk-evm testnet running (which I believe is based on zk-llvm), so we're close. Currently all the big rollups have master keys which can be used to steal all the money deposited by them, but there's no reason in principle they have to have this. Polygon has permissionless rollups, so I'm quite…

> Right now they're immature It's 14 years old. The community has had a fix for all of these problems just over the horizon for a decade. It just isn't coming. The real issue is that most of the crypto being held is held by people who don't care about using it as currency or for anonymity, they're using it as an "investment". That's why when coins that work better as cash or privacy or whatever come out, nobody cares…

ZK rollups are not anywhere near 14 years old

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#590
post #477

Earlier quoted context omitted.

In this case, the weakness was that the keys that controlled the bridge were somehow stored insecurely. When attackers gained access to the keys, they were able to steal from the bridge. In a properly-implemented rollup, there are no keys to secure, so this attack vector is ruled out. But more broadly, there is really nothing else with the same security properties as a smart-contract-enabled cryptocurrency. Paypal wi…

You are misinformed. With most cryptocurrencies (except Monero) it is very easy to blacklist wallets, and since tx history is public you can't just move your coins to a new address to get around it either. You don't actually even need decentralized systems for private transactions, digicash with blind signatures would be private and vastly more efficient.

On Ethereum you can you decentralized tumblers like Tornado Cash
Post reply on HN