Live data from Hacker News

Developer posts secret key on GitHub, loses $40K in 2 minutes

cointelegraph.com

11–20 of 93 posts

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#12
post #4

> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...

A delay or just that it polls every 5 minutes?

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#13
post #5

Earlier quoted context omitted.

>Some cryptocurrency isn't a safe store of value to begin with... If I may, I would posit all crypto is not a safe store of value to begin with. An EMP taking out the entire world power grid would render crypto pretty useless almost immediately, while gold will just sit there. Even paper money is resistant to decentralized unwindings as they are physical and people are conditioned from birth to accept their value.

An EMP taking out the entire world power grid would be a complete disaster for everyone. Goldbugs and people with cash in their mattresses included.

I don't disagree with you that it would be a disaster, I'm just saying that fundamentally crypto is not a store of value. But don't listen to me, I only deliberately burned my early Bitcoin after evaluating it on its merits, weeks after it came out. Nothing, repeat nothing, has ever moved the needle on my opinion of crypto, although I will say that cryptobros will not stop at anything to try and convince people that crypto serves the 3 functions of currency.

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#14
post #4

> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...

A delay or just that it polls every 5 minutes?

It's delayed. You can poll it continuously and you get live events "from 5 minutes ago".

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#15
post #4

> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...

Given the obvious incentive, I expect multiple groups to be scraping simultaneously, out of sync with each other.

Also, I expect anyone working on high-value systems to be under more targeted scraping.

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#17
post #7
post #4

> When a community member inquired about how long it took for the funds to be drained, the Web3 founder responded that it took just two minutes for someone to withdraw the funds. The public events API is delayed by 5 minutes[1]. Unless someone was actively scraping his profile rather than doing large scans on GitHub, this is not possible. [1] https://docs.github.com/en/rest/activity/events?apiVersion=2...

They don't need to proactively scan all of GitHub to exploit this kind of mistake, just active accounts that are known to be involved with cryptocurrency. GitHub even lets you find them easily: https://github.com/search?q=language%3ASolidity&type=users

[deleted]

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#18
If you’ve got that much money in a project, it’s not a prototype.

This repo should have had all types of static analysis running automatically.

Hell, GitHub has built in secret scanning. Apparently it was only set as the default for all new repos in March 2024[].

[] https://docs.github.com/en/code-security/secret-scanning/con...

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#19
post #11

This is your reminder that every crypto"currency" using a transaction fee is fundamentally a scam and everything that is happening using them is merely hype to get you involved in them.

I'm all for bashing crypto bros, but really? The fundamental benefit of crypto currencies is being independent of central authorities. Do you think it has failed in that regard?

Re: Developer posts secret key on GitHub, loses $40K in 2 minutes

#20

I don't know about anyone else here but if I had 40k laying around in Cryptocurrency I would have taken some of that and bought a MacBook pro that didn't have my personal information on it for coding, for a start.

A hardware token would be even cheaper while still allowing signing.
Post reply on HN