Live data from Hacker News

The Resolv hack: How one compromised key printed $23M

chainalysis.com

121–130 of 174 posts

Re: The Resolv hack: How one compromised key printed $23M

#121
post #32
post #24

Earlier quoted context omitted.

Not really. At a traditional bank I have to trust n people with varying degrees of access. Et ceteris paribus, any reduction in n is an improvement, even if n is not zero. Of course n can be smaller and the specific people less trustworthy, but that's quite a different thing.

Ok so we are expected to trust; the creator/s, some random hacker, whoever else has the key? So the value here is between 2 and 'many'.

You're expected to do your own research about how it works, who the keyholders are, and what permissions they have. You're free to choose only projects where n=0. If you choose n>0, you have to work out your trust and confidence level. You're always free to use the traditional financial system as well.

Re: The Resolv hack: How one compromised key printed $23M

#122

Earlier quoted context omitted.

If your definition excludes Ethereum your understanding of the term so differs from everyone else's that we aren't talking about the same thing

Ethereum is a great utility token. Smart contracts absolutely have utility in the digital economy. It's just not a cryptocurrency, is all. It had a massive premine, there's no supply cap, it's subject to OFAC censorship, and has effectively demonstrated that just ~4.8% of the total ETH supply can vote to cause rollout and widespread adoption of a fork that reverses transactions. We need different words for these fund…

Where did the 4.8% number come from? Is it based on the validator stake? How does that compare to the number required to fork Bitcoin as a function of it's supply?

Re: The Resolv hack: How one compromised key printed $23M

#123
post #111

Earlier quoted context omitted.

Exactly. Stablecoins make zero sense.

Unbacked stablecoins like USR make no sense - but USDC is one of the few real uses that crypto has.

USR is not unbacked. You have a severe misunderstanding of the whole situation if you say that.

Re: The Resolv hack: How one compromised key printed $23M

#124
post #111

Earlier quoted context omitted.

Unbacked stablecoins like USR make no sense - but USDC is one of the few real uses that crypto has.

Decentralized. Stable. Pick one.

Decentralized > the transfer of authority, decision-making, or operational functions away from a central authority to smaller, local, or distributed nodes, systems, or entities

DAI is decentralized and stable

Re: The Resolv hack: How one compromised key printed $23M

#125
post #54

Earlier quoted context omitted.

you can send them around easily without having to deal with bullshit payment systems

But you do have to deal with bullshit payment systems. I can't receive stablecoins in my regular bank account, I'd have to set up some crypto nonsense on DankRocketBets or whatever for it to even work. Why would I do this when I can already receive actual USD without any extra ceremony? Stablecoins are a solution in search of a problem.

you can receive. you just need to set it up.

there are like 50 (many YC) startups fixing this today trying to offer your the best and cheapest service

Re: The Resolv hack: How one compromised key printed $23M

#126
post #14

And what happened next? He mixed those coins? Transformed them into monero?

first step is to turn them into real crypo like ETH (so its unfreezable)

then probably mix them via different methods

then sell them via OTC-style swap platforms like fixedfloat / changelly etc

Re: The Resolv hack: How one compromised key printed $23M

#127
post #119

Earlier quoted context omitted.

Stablecoins enable cash-like (instantly redeemable and verifiable) payments for large amounts, for almost free. In EU countries, you can't now buy a car with cash. You have to buy a bearer's check from your bank, which is expensive, requires that both parties have a brick and mortar bank, and doesn't work cross-border. Stablecoins solve this.

It was good while ago, but last time I bought a car I just did bank transfer. SEPA transfers are entirely free. Was kinda amazed that they just handed me keys when I showed them the receipt from my own online bank...

It's a calculated risk. They know the VIN number and I assume made a copy of your photo ID.

Re: The Resolv hack: How one compromised key printed $23M

#128
post #123
post #111

Earlier quoted context omitted.

Unbacked stablecoins like USR make no sense - but USDC is one of the few real uses that crypto has.

USR is not unbacked. You have a severe misunderstanding of the whole situation if you say that.

To be fair, the article itself says "unbacked" right upfront:

> an attacker was able to mint tens of millions of Resolv’s unbacked stablecoins (USR) and extract roughly $23 million in value

Re: The Resolv hack: How one compromised key printed $23M

#129
> The attacker compromised Resolv’s cloud infrastructure to gain access to Resolv’s AWS Key Management Service (KMS) environment where the protocol’s privileged signing key was stored.

Ok, but how was the AWS infrastructure compromised? This appears to be the crux of the entire article.

AWS is very hard to break if you are using the IAM roles properly and avoiding manual secret management. If the only thing that can even sign a JWT is a very specific blessed EC2 instance that has exclusive access to KMS, your attack surface is nearly zero by comparison to a similar setup where administrators use email or Discord to communicate API credentials.

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-role...

The protocol around using an HSM is just as important as the machine itself. It seems like some of us are going to be speed running PCI-DSS the hard way.

Post reply on HN