Live data from Hacker News

XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

hackernoon.com

1–10 of 50 posts

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#3
> I want to make one point clear: I believe that EtherDelta, in concept, is safer and more “trustworthy” than a traditional exchange. Everything about how EtherDelta functions is transparent and verifiable by users.... The attack detailed in this piece could have been identified by anyone before it was exploited, and if there had been a security review protocol in place, it would have been easily prevented.

Even "in concept", releasing fintech software without doing the security basics verges on professional misconduct.

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#8
post #2

>thousands of dollars The article is out of date. People are saying the amount is now $6 billion.

This linked to an 'unlisted' token (a token which doesn't have enough recognition to be 'officially listed' on Etherdelta, and thus doesn't have its own ticker symbol), which the vast majority of token buyers have no interest in, so there's no chance that many people were interested in purchasing it, let alone through Etherdelta (which still has very little volume relative to centralized exchanges).

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#9
post #2

>thousands of dollars The article is out of date. People are saying the amount is now $6 billion.

It is out of date, but the author created a followup post[1] on Medium:

> Which as of this writing, has over $130,000 worth of Ethereum and over 88,000 transactions.

[1] https://medium.com/@decktonic/following-the-trail-what-we-kn...

Re: XSS Attack Embedded in an ERC20 Token Contract Steals Thousands

#10
post #3

> I want to make one point clear: I believe that EtherDelta, in concept, is safer and more “trustworthy” than a traditional exchange. Everything about how EtherDelta functions is transparent and verifiable by users.... The attack detailed in this piece could have been identified by anyone before it was exploited, and if there had been a security review protocol in place, it would have been easily prevented. Even "in…

[deleted]
Post reply on HN