For those that don't want to read the whole thing, (supposedly) the attackers reached out on linkedin to a bunch of employees asking them to apply to a fake company. One of them did it, went through a bunch of fake interviews, and then got a fake offer, in the form of a PDF. They opened the PDF and that installed a keylogger on their system (it doesn't explain how). The attackers then used that engineer's credentials…
I'm trying to imagine a setup at any company whose primary business is controlling extremely valuable digital assets having a security setup that could be entirely undone with keyloggers, and it's difficult. No necessary VPNs, keys on devices, or other non-password authentication? One engineer's password should not be the keys to the kingdom. Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian K…
Rather than think of their primary business as securing digital assets, think of their primary business as convincing people that a perpetual money machine in the shape of a video game is possible. The valuable digital assets are just a narrative tool — and so it follows that they wouldn’t have the expertise in securing digital assets.
Nobody capable of building a secure system for digital assets would waste their time working for a company like Axie, after all, the entire premise of their business is flawed so people with the critical thinking skills necessary to build a secure system would apply that critical thinking to the viability of the company — and, of course, conclude it’s destined for failure and not hitch their wagon to it.