Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

141–150 of 364 posts

Re: A fake job offer took down Axie Infinity

#141
post #114
post #48

Earlier quoted context omitted.

The right move here would have been to have separate work/personal computers so that this PDF never landed on a system with access to the Ronin network. I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.

what would stop a developer from checking personal email on a work machine?

Or more to the point, what would stop someone from sending malicious documents to the employees' work emails?

Figure out a company uses register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details.

If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?

Re: A fake job offer took down Axie Infinity

#142

Earlier quoted context omitted.

> The main problem was using a machine that had access to half a billion dollars Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.

The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.

The compromised employee had access to that 5th factor it was just not as direct as as him having a 5th private key.

Re: A fake job offer took down Axie Infinity

#143

Curious if anyone has been able to find technical details of how this attack works/worked. I'm under the impression most PDF viewers would prevent this sort of attack (e.g. opening a PDF in your browser should sandbox it to the browsing context), but really keen to know what PDF viewer / OS was used by the dev.

Likely this was a standalone PDF reader hack (rather than a browser), since those can have many more features and a much larger attack surface. It says it was an offer letter, so my guess is that opening it in the browser came up with an error like "to be able to digitally sign this offer letter, please open it in a desktop PDF reader with full scripting support enabled :)"

I guess we all need to be opening anything remotely phishy in VMs to avoid similar issues

Re: A fake job offer took down Axie Infinity

#144
post #82

Earlier quoted context omitted.

> LinkedIn is an absolute godsend for bad guys I am listed as the Principal on a couple of companies, and get constant approaches that are obviously fake (like an attractive young "stewardess" from Dubai, who just happened to like my picture (which is actually my logo)). I've given up reporting them, as LI always responds with "This is not in violation..."

Isn't LI owned by MS?

Is there a “Best of” archive for HN comments?

Re: A fake job offer took down Axie Infinity

#145
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

lol

do you at least dual boot?

have a separate user account?

I guess its fine as long as your computer doesn't have the credentials to the company slush fund.

Friend of mine I traveled with carried 3 macbooks with her: school issued, work issued, and personal. They had different software licenses tied to the machine, whadyagonnado?

Re: A fake job offer took down Axie Infinity

#146

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I deactivated my LI after my last job search, it hasn't affected my life at all since then. I don't know why you need one at all most of the time. Even without one, I think it would be perfectly easy to get interviews at companies, most interviews I've done in the past have been the ones I got by just going to the company's website and applying directly anyway.

Re: A fake job offer took down Axie Infinity

#148
post #79

Earlier quoted context omitted.

Cyberpunk is now, just sans the 80s fashion inspirations :)

Where are my mantis blades?

The people in this review seem to think they're alright, but they look very silly to me: https://www.youtube.com/watch?v=tB4DDM8VHVg YMMV. But hey, maybe you can ask them for their design.

Re: A fake job offer took down Axie Infinity

#149
Seems like there would be market demand for a super locked down PDF viewer that basically ignores all the silly extensions/additions that Adobe has added to the format over the decades. The vast majority of documents don't need Turing complete code capabilities or embedded videos or interactive 3D models. Something that safely (using sandboxing and other methods) turns the document into totally static pixel data that still feels nice to read would mitigate this extremely common attack vector.

Re: A fake job offer took down Axie Infinity

#150

Earlier quoted context omitted.

They already know where the money went: https://home.treasury.gov/policy-issues/financial-sanctions/... And it has already been moved: https://www.blockchain.com/eth/address/0x098B716B8Aaf2151299...

This doesn’t mean it wasn’t an inside job. Dude could have a nice payday for “oops I got PDF hacked”, plus giving away enough information about their internal organization to make the attack feasible.

Or the dev could be simply setup to take the blame. Everything’s possible. Or an ex employee could have surveyed the system and shared data with a larger group to perform the operation.
Post reply on HN