Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

111–120 of 133 posts

Re: Sei pays out $2M bug bounty

#114

Pardon my crypto ignorance, but if someone took over the entire SEI platform, wouldn't the value of SEI coin drop to zero?

Well, like Soros on the Bank of England or the attack on Terra luna, you can short SEI before the attack as well.

This is actually why "proof of stake" blockchains are fundamentally flawed. They only make sense if the value of the system is denominated in the currency of the system. It's self referential and prone to negative feedback loops. They are secure because the token is expensive, the token is expensive because it provides a secure platform. Short the token, take a loan out, compromise the security, tank the value, profit. All the mechanisms to prevent that are built into the system, like delaying the validator pool entry, but the only real backstop is a hard fork and spinning up a new copy.

Re: Sei pays out $2M bug bounty

#115
post #107

Earlier quoted context omitted.

Definitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe. See also all the people pissed at zelle.

Nothing is true in absolute terms but banks care about loss percentages and that’s much better in the real banking sector. For example, the national bank of Bangladesh was compromised in 2016, believed to be a well-resourced attack by North Korea, and the attacker was able to attempt to transfer $1B. That’s about as severe as it gets, but the U.S. Federal Reserve blocked 85% of the transferred funds and of the remain…

The money was only stopped at the Federal Reserve because the address used in some of the wire transactions included the word Jupiter which was a sanctioned entity at the time and the matching was sufficiently fuzzy that this was caught. That was a complete accident. It just as easily could have gone the other way. I just read a case on the layoffs subreddit where a law firm was hacked and one of their clients was tricked into wiring millions of dollars to the wrong account, resulting in the client suing the law firm for negligence and the law firm having to fire a bunch of people. One Latvian guy tricked Google and other large tech companies into wiring him a hundred million dollars total which was only recovered because he was arrested and plead guilty. Business email compromise is a huge plague on society and in many cases the recovered amount is trivial.

The only way you are recovering the bulk of losses if you don't notice the theft very quickly is if the amount is high enough that a prosecutor is interested and it hasn't all been withdrawn as cash yet.

Re: Sei pays out $2M bug bounty

#119
post #51
post #48

Earlier quoted context omitted.

What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.

Everything is wire fraud / securities fraud

Someone has been reading Matt Levine
Post reply on HN