Earlier quoted context omitted.
USR is not unbacked. You have a severe misunderstanding of the whole situation if you say that.
To be fair, the article itself says "unbacked" right upfront: > an attacker was able to mint tens of millions of Resolv’s unbacked stablecoins (USR) and extract roughly $23 million in value
The Resolv hack: How one compromised key printed $23M
131–140 of 174 posts
Re: The Resolv hack: How one compromised key printed $23M
#132Why does everything have to be written by an AI?
Re: The Resolv hack: How one compromised key printed $23M
#133Earlier quoted context omitted.
^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM. There's no shortcut to MPC/multisig with 3+ keyholders.
> you still have to secure the HSM Obviously. > There's no shortcut to MPC/multisig with 3+ keyholders. The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.
Re: The Resolv hack: How one compromised key printed $23M
#134If the admins can "lock all transactions", what's the point of it being a crypto?
Re: The Resolv hack: How one compromised key printed $23M
#135If the admins can "lock all transactions", what's the point of it being a crypto?
Stablecoins aren't cryptocurrencies in any sense of the word. It's just electronic FIAT.
Your money is safe with us. We promise. With lot less oversight than most other solutions for holding money...
Re: The Resolv hack: How one compromised key printed $23M
#136Earlier quoted context omitted.
Have you actually tried to run a business this way?
$24m was lost. Setting this up is say $10k in time and materials. Although I would use a rack server. .
Re: The Resolv hack: How one compromised key printed $23M
#137Earlier quoted context omitted.
> you still have to secure the HSM Obviously. > There's no shortcut to MPC/multisig with 3+ keyholders. The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.
Nope, that is the foundation of bad stablecoin. Trustless decentralized stablecoin like DAI exist. People just largely don't do their homework and prefer scams that lure them in with promises of 'yield'
Re: The Resolv hack: How one compromised key printed $23M
#138Earlier quoted context omitted.
Is there any proof, or even indication, that this wasn't an inside job?
Usually I would expect proof for a positive - like that it was an inside job, or there being an indication of it. I'm not saying whether it was or not, just that it seems unusual for you to ask about proof of it NOT being an inside job.
Re: The Resolv hack: How one compromised key printed $23M
#139Earlier quoted context omitted.
It's explicitly mentioned in the article: A step by step breakdown of the attack Step 1. Gaining Access to Resolv’s AWS KMS Environment
The link was changed, the old one did not mention it (apparently): https://news.ycombinator.com/item?id=47498220
Re: The Resolv hack: How one compromised key printed $23M
#140Earlier quoted context omitted.
Stablecoins enable cash-like (instantly redeemable and verifiable) payments for large amounts, for almost free. In EU countries, you can't now buy a car with cash. You have to buy a bearer's check from your bank, which is expensive, requires that both parties have a brick and mortar bank, and doesn't work cross-border. Stablecoins solve this.
How do stablecoins fit in here? You can buy a car with crypto but not cash?