A fake job offer took down Axie Infinity
221–230 of 364 posts
Re: A fake job offer took down Axie Infinity
#222Earlier quoted context omitted.
what would stop a developer from checking personal email on a work machine?
Themselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines. This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
Re: A fake job offer took down Axie Infinity
#223Earlier quoted context omitted.
My understanding of the article was that only 1 person was compromised and that the exploit installed on their computer was then used to access the validator nodes themselves. FWIW, I have no idea what a validator node is but I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up).
> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
Re: A fake job offer took down Axie Infinity
#224Earlier quoted context omitted.
I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.
Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.
Re: A fake job offer took down Axie Infinity
#225I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…
Re: A fake job offer took down Axie Infinity
#226Earlier quoted context omitted.
When I first got into crypto, a few things were pretty much drilled into my head: - Not your keys, not your coins; always self-custody - Never use the same machine for trading and for work/surfing the web - Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.
and this is part of why i think cryptocurrencies should have died before large number of people wasted their money on it. for the average user without the time/knowledge/patience to handle cryptos "properly", the choice is between losing money while handling this shit yourself or losing money while trusting someone else to do it right.
Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.
Re: A fake job offer took down Axie Infinity
#227Earlier quoted context omitted.
> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?
because the workstation was compromised by opening a corrupted pdf, but that vector wouldn't compromise the other machines unless users on them could be induced to open the same pdf. not to say it can't be done, but it was unexplained
Re: A fake job offer took down Axie Infinity
#228What an incredible story. In fact it is so incredible that it smells a bit funny to me. Are we sure this heist wasn’t an inside job? Axie was collapsing under its own weight and an employee decided to swipe all of the crypto after making up this crazy job offer PDF story to cover their tracks.
Edit: I thought the lack of details was fishy but the following would be tough to fake:
the FBI has attributed North Korea-based Lazarus Group, highly skilled hackers, to the Ronin Validator Security Breach. The US Government, specifically the Treasury Department, has sanctioned the address that received the stolen funds
Re: A fake job offer took down Axie Infinity
#229Earlier quoted context omitted.
> The main problem was using a machine that had access to half a billion dollars Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.
The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.
The system does not require people to sign off, but for the keys to sign off.
I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them
Re: A fake job offer took down Axie Infinity
#230Earlier quoted context omitted.
what would stop a developer from checking personal email on a work machine?
Themselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines. This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
This might just result in employees finding ways to remote access their work computer from their personal computer from wherever they are, but at least that's an additional wall for would-be attackers to hurdle.