Live data from Hacker News

Exodus Bitcoin Wallet: $490k swindle

popey.com

141–150 of 297 posts

Re: Exodus Bitcoin Wallet: $490k swindle

#141
The crypto industry has had a serious UI/UX problem, no doubt about that. I also presume this bitcoin holder wasn't a sophisticated one, because the main point of a cold wallet is NOT ever have your seed phrase (12-24 words) go online. That's the real exploit in here.

Crypto has a long way to go and some improvements are being made but it definitely is one of the main pain points.

Re: Exodus Bitcoin Wallet: $490k swindle

#142

In which being your own bank continues to be undesirable. (Never understood why ‘be your own bank’ was meant to be at all appealing. Being a bank is terrible. And still realistically less risky than this sort of thing; apart from truly bizarre edge cases (see the Citi/Revlon drama), this sort of thing simply can’t happen.)

How is being a bank terrible? It's one of the most profitable businesses ever and continues to be.

Re: Exodus Bitcoin Wallet: $490k swindle

#143
post #34

Earlier quoted context omitted.

Reading this, it is bonkers to me that people think cryptocurrencies are ready or appropriate for mainstream use, either as a currency or as an investment. Line could go up, but if you aren’t extremely careful with processes that most people don’t and won’t comprehend—and don’t even realize are something you need to do—you can just straight up lose everything.

Yeah, it's definitely not ready. I agree with everything you are saying. Though, the industry is aware of this and working on it. There is at least one company (Chia Network) where the on-chain language (ChiaLisp) is both capable and secure enough to allow for the sort of management needed to allow for self-custody to happen in a safe, sane manner. GUIs for this sort of thing aren't ready for the general public yet,…

It isn't a software problem.

Re: Exodus Bitcoin Wallet: $490k swindle

#144
post #24

This is scary and even a hardware wallet might not help. When I create a transaction with Electrum on my computer, I use a hardware wallet to sign the transaction. When I sign the transaction, the hardware wallet shows the amounts, and the output addresses. But if my copy of Electrum was backdoored and smart about what it did, it could use an output address for the remaining amount that went to another wallet. And si…

No, you're wrong. The issue you're describing can't be exploited on Ledger devices at least. (Source: I’m a contributor to their bitcoin transaction parsing code) Their hardware wallet checks if the provided change output's address is actually owned by the device owner: - if it does, then the change output is simply hidden from the user validation flow - if it doesn’t it will appear as a second bitcoin transfer to ap…

Ok, and what if you use your Ledger seed phrase to connect / recover on Exodus? Hardware wallet or not, if the recovery seed is exposed, are you in trouble?

Re: Exodus Bitcoin Wallet: $490k swindle

#145

Earlier quoted context omitted.

The claim is that some day innovations, and checks, and some other technologies will fix this and do all of this automatically, somehow. That's why it's still early days.

No, this is usually (apologies if not in your case) a straw man, and representative of the usual HN blind spot for cryptocurrency. Ledger and Trezor hardware wallets do protect against this class of attack. We are rapidly approaching a world in which those with significant assets or job responsibilities should be carrying physical 2FA tokens, which can allow use of private keys while protecting them (a hardware walle…

> The base rule in crypto has always been “not your keys, not your coins”

This is because blockchains have no way of enforcing laws, including property rights. Therefore it comes down to this. Imagine that whoever got hold of your car keys, automatically became the owner. This is what "not your keys, not your coins" means.

Re: Exodus Bitcoin Wallet: $490k swindle

#146

Earlier quoted context omitted.

Do you also consider Bitcoin a pyramid scheme?

No, I don't. But Bitcoin also isn't particularly interesting because it's not (very) programmable and not useful for mainstream use anyway. I don't consider Ethereum itself a pyramid scheme, just useless. The protocols on top of these chains though, nearly all pyramid schemes. The best way to describe Ethereum is that it provides a platform for pyramid schemes.

The base of the pyramid, if you will. I wouldn’t lump all contracts in with this but it does describe a vast majority of them.

Re: Exodus Bitcoin Wallet: $490k swindle

#149
post #121

Earlier quoted context omitted.

In 1980 packet switching had existed for 20 years already. The public Internet wouldn’t emerge for more than a decade after that—and it would take yet another 20 years for the true power of packet-switched networks to be realized, in the form of mobile Internet. In 2000 neural networks had existed for more than 50 years. More than 20 years later their full potential is finally being realized, and many would say it is…

Those comparisons are incredibly mismatched. In 1980 a computer cost as much as a car, and network connections were incredibly expensive and slow. Bill Gates, child of wealth and privilege, famously had to use a shared computer paid for by his elite school because even the child of an IBM board member wouldn’t have access to a computer! The microprocessor revolution unfolded in the 80s, however, so even your timeline…

> Similarly, nobody doubted that neural networks were capable of very interesting things - the holdup was the level of processing power needed to run them. As soon as that changes, useful applications abounded.

This is incorrect. AI has gone through multiple ‘winters’ where there were serious doubts and pessimistic attitudes toward its capabilities.

https://en.wikipedia.org/wiki/AI_winter

Re: Exodus Bitcoin Wallet: $490k swindle

#150

Earlier quoted context omitted.

Yeah, it's definitely not ready. I agree with everything you are saying. Though, the industry is aware of this and working on it. There is at least one company (Chia Network) where the on-chain language (ChiaLisp) is both capable and secure enough to allow for the sort of management needed to allow for self-custody to happen in a safe, sane manner. GUIs for this sort of thing aren't ready for the general public yet,…

Solutions have been on the way for more than five years, but literally nothing has changed and all we've gotten is pyramid schemes and gambling. Chains and protocols have exploded in complexity and technical debt to the point where nobody fully understands the attack vectors. By now I am convinced that anything beyond pyramid schemes is never going to happen.

It's frustrating, I agree. People are obviously going to continue being people with pyramid schemes and the like. At the same time, there are enough who also agree that it's a mess, have closely studied the successes and mistakes of the past, and are building a solid foundation for doing this right. I mean, what we're really talking about here is creating a fundamentally new system for which the financial system operates upon ... it's going to take time ... longer than five years. And the progress that I've seen thus far is encouraging.
Post reply on HN