Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

271–280 of 364 posts

Re: A fake job offer took down Axie Infinity

#271

> Validators fulfill various functions in blockchains, including the creation of transaction blocks and the updating of data oracles. Ronin uses a so-called “proof of authority” system for signing transactions, concentrating power in the hands of nine trusted actors. This paragraph perfectly encapsulates everything wrong with the way promoters sell Ethereum. Smart contracts can do little of interest beyond straight m…

Oracles that connect to off-chain data are usually understood as points of centralization, I don’t think Ethereum or it’s developers are selling otherwise. Most Ethereum developers are advising against relying on bridges across security zones that would be upheld by multisigs and oracles, they are vulnerable to attacks. A better model than a bridge to sidechain would be a rollup - posting proofs on chain without givi…

You can't prove anything from the outside world.

I still remember in 2017 shills on arkcoin slack trying to sell agricultural insurance that paid based on weather. They kept selling how decentralized it was but at the end of the day they just admitted that a central authority would input that data and we were back at square 0.

Re: A fake job offer took down Axie Infinity

#272

Earlier quoted context omitted.

I'm trying to imagine a setup at any company whose primary business is controlling extremely valuable digital assets having a security setup that could be entirely undone with keyloggers, and it's difficult. No necessary VPNs, keys on devices, or other non-password authentication? One engineer's password should not be the keys to the kingdom. Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian K…

I’m of the view that the completely illogical nature of their entire business and the absence of any meaningful security are deeply interwoven. Rather than think of their primary business as securing digital assets, think of their primary business as convincing people that a perpetual money machine in the shape of a video game is possible. The valuable digital assets are just a narrative tool — and so it follows that…

> Nobody capable of building a secure system for digital assets would waste their time working for a company like Axie

Someone with low ethics interested in a very good paycheck?

Re: A fake job offer took down Axie Infinity

#273

The other major cause of the failure was that one dev had access to 5 signing keys. That shouldn't have happened, because than that one dev could have run off with $540 Million... And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.

> shouldn't have happened, because than that one dev could have run off with $540 Million

And that's why I don't believe the story. No owner of such business would make this possible.

Re: A fake job offer took down Axie Infinity

#274

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

I think one shouldn't discount the attack vector that is just working in the Crypto industry, especially when you're someone who works with startups rather than the big guys. In the "Web2 Sector", it would be very easy IMO to snuff out a fictitious company. I've gotten a handful of "offers" in the past and you can see straight through them, because the company doesn't exist in real life and you can't find any info on…

No post body was provided.

Re: A fake job offer took down Axie Infinity

#275

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

No post body was provided.

Re: A fake job offer took down Axie Infinity

#276
post #68

The other major cause of the failure was that one dev had access to 5 signing keys. That shouldn't have happened, because than that one dev could have run off with $540 Million... And remember, it wasn't just that one dev - it was everything running on his computer - think of the probably tens of thousands of developers who wrote the code that runs as root on his PC, much of it unreviewed.

> In a post-mortem blog post on the hack, published April 27, Sky Mavis said: “Employees are under constant advanced spear-phishing attacks on various social channels and one employee was compromised. This employee no longer works at Sky Mavis. The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes.” The company fully blames the employee. I wish so…

Whatever happened to blameless root cause analysis?

Re: A fake job offer took down Axie Infinity

#277
post #99

Two points to highlight from this article: 1. LinkedIn is an absolute godsend for bad guys, allowing easy targeting of everyone in the company with spear phishing emails and texts. I know many security professionals no longer use their real name, and don't list the real name of their company, because they know it's such a great hacking vector. Not sure what/whether LinkedIn can do anything about this. 2. I wish there…

The main problem was using a machine that had access to half a billion dollars to also browse the web and do stuff like applying for jobs. If you're gonna have access to such amount of money, it's worth buying a dedicated machine and using it very, very cautiously.

Not money. Crypto.

Re: A fake job offer took down Axie Infinity

#278

Earlier quoted context omitted.

and this is part of why i think cryptocurrencies should have died before large number of people wasted their money on it. for the average user without the time/knowledge/patience to handle cryptos "properly", the choice is between losing money while handling this shit yourself or losing money while trusting someone else to do it right.

Its an entirely free market. Just because one person doesn't understand the tech and loses his money doesn't mean that everyone else shouldn't be allowed to use it either. Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.

Not a free market. An unregulated market.

"Free market" in the Smithian sense is not what we have here.

Re: A fake job offer took down Axie Infinity

#279
post #169

Earlier quoted context omitted.

I don't think you can generalize Web3 companies to all software companies. Web3 companies have shown time and time again that they don't care much about security or good software development practices. I'm not sure if it's because the industry is so nascent or because the people joining are simply incompetent or because they don't care (or a combination of all three) but it's clear that Web3 companies have major inci…

> clear that Web3 companies have major incidents at higher rates than most other software companies I won't argue this, but I think that it depends on where you look. Cryptography audit services are books out for months or years because of the demand from cryptocurrency projects. There's never been a vulnerability in the Bitcoin or Ethereum networks that allowed an attacker to steal funds or execute a double-spend. A…

Except you know that time Ethereum forked because the core contract on Ethereum was stolen.

Re: A fake job offer took down Axie Infinity

#280
post #229

Earlier quoted context omitted.

The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.

I think it's worth noting that the people did not sign off, only the keys did. The system does not require people to sign off, but for the keys to sign off. I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them

This is a preposterous position. It's clearly a hack. Keys cannot legally own anything. People and organizations own things and in this case the people were hacked and the funds stolen.
Post reply on HN