Live data from Hacker News

Exodus Bitcoin Wallet: $490k swindle

popey.com

161–170 of 297 posts

Re: Exodus Bitcoin Wallet: $490k swindle

#161
post #144
post #24

Earlier quoted context omitted.

No, you're wrong. The issue you're describing can't be exploited on Ledger devices at least. (Source: I’m a contributor to their bitcoin transaction parsing code) Their hardware wallet checks if the provided change output's address is actually owned by the device owner: - if it does, then the change output is simply hidden from the user validation flow - if it doesn’t it will appear as a second bitcoin transfer to ap…

Ok, and what if you use your Ledger seed phrase to connect / recover on Exodus? Hardware wallet or not, if the recovery seed is exposed, are you in trouble?

I'd say the fact that you can not enter a seed phrase into an app on computer or website should be like "level 1" required crypto knowledge. I understand that many are still failing at this daily.

Re: Exodus Bitcoin Wallet: $490k swindle

#162
post #34

This is scary and even a hardware wallet might not help. When I create a transaction with Electrum on my computer, I use a hardware wallet to sign the transaction. When I sign the transaction, the hardware wallet shows the amounts, and the output addresses. But if my copy of Electrum was backdoored and smart about what it did, it could use an output address for the remaining amount that went to another wallet. And si…

Reading this, it is bonkers to me that people think cryptocurrencies are ready or appropriate for mainstream use, either as a currency or as an investment. Line could go up, but if you aren’t extremely careful with processes that most people don’t and won’t comprehend—and don’t even realize are something you need to do—you can just straight up lose everything.

People(old and young) give away their entire life savings to scammers every day, everywhere in the world. You don't hear about it on the internet all the time because we either got used to it or they don't want the publicity. You hear about big cryptocurrency scams more often because people invested are more into tech and spend time on the internet. Do you say that cash is not ready or appropriate for mainstream use? What about that cashier that never has that 1c of change back? Clearly a sign of not being appropriate for mainstream.

Those generic arguments can be applied to literally everything we already have. People get scammed via their bank accounts every day too, people literally get scammed by the phone. You have to use your brain when it comes to _anything_ that involves a real world value these days, saying 'crypto bad cause scams' is pointless as there are way more scams involving real world money everywhere.

Re: Exodus Bitcoin Wallet: $490k swindle

#163
post #34

Earlier quoted context omitted.

Reading this, it is bonkers to me that people think cryptocurrencies are ready or appropriate for mainstream use, either as a currency or as an investment. Line could go up, but if you aren’t extremely careful with processes that most people don’t and won’t comprehend—and don’t even realize are something you need to do—you can just straight up lose everything.

Yeah, it's definitely not ready. I agree with everything you are saying. Though, the industry is aware of this and working on it. There is at least one company (Chia Network) where the on-chain language (ChiaLisp) is both capable and secure enough to allow for the sort of management needed to allow for self-custody to happen in a safe, sane manner. GUIs for this sort of thing aren't ready for the general public yet,…

What's the name of the function in ChiaLisp that returns true if this is an illegitimate transaction initiated by a hacker and false if it's being done by the real owner of the funds?

Re: Exodus Bitcoin Wallet: $490k swindle

#164
post #24

Earlier quoted context omitted.

No, you're wrong. The issue you're describing can't be exploited on Ledger devices at least. (Source: I’m a contributor to their bitcoin transaction parsing code) Their hardware wallet checks if the provided change output's address is actually owned by the device owner: - if it does, then the change output is simply hidden from the user validation flow - if it doesn’t it will appear as a second bitcoin transfer to ap…

Ok. I use Ledger. And I would not have thought of being suspicious of there being two addresses to confirm. So rather than being “wrong”, maybe I am more similar to most regular user of hardware wallets, and that this kind of attack would indeed be a disaster for a lot of users who have hardware wallets. Myself included.

But.... if you did confirm two addresses, wouldn't the second one be suspicious solely because... if you're confirming it... it means you actually did something besides click a button right? And if it wasnt an address you owned?

Re: Exodus Bitcoin Wallet: $490k swindle

#165
post #156

The operational security measures one has to take these days to secure crypto is insane. You have to build your own mini intelligence agency just to protect your digital crypto assets. You have to do: - Principle of least privilege. - Zero Trust. - Compartmentation. - Hardened Operating Systems with no malware and strong endpoint defense. - Firewalls that whitelist only your IP and disavow everything else. - 2FA/MFA/…

> Are people up to the task of doing all this?

No. Anyone who thinks they are is deluding themselves. There is no such thing as a setup that is 100% secure against human error (and nobody is infallible) or a sufficiently motivated and skilled attacker (and there are supreme amounts of motivation here).

The core problem is the lack of legal recourse. Anonymous, irreversible, distributed transactions for money are a really fucking stupid idea.

Re: Exodus Bitcoin Wallet: $490k swindle

#166
post #8

One point I would make: > it connects to some API at https://www.exchangerate-api.com/ This is not necessarily right. The exchangerate-api.com site is hosted behind Cloudflare, so I don't know where it's actually hosted, but the IP addresses shown in bandwhich could be unrelated. You also said: > Visiting one of those IPs redirects to https://www.exchangerate-api.com/ It is common for malicious sites to redirect to l…

Another way IPv6 could make things better: no need to point multiple domains at the same IP address, so you could have a one-to-one relationship between domain and address and prevent shady things from hiding behind legit things.

Re: Exodus Bitcoin Wallet: $490k swindle

#167
post #164

Earlier quoted context omitted.

Ok. I use Ledger. And I would not have thought of being suspicious of there being two addresses to confirm. So rather than being “wrong”, maybe I am more similar to most regular user of hardware wallets, and that this kind of attack would indeed be a disaster for a lot of users who have hardware wallets. Myself included.

But.... if you did confirm two addresses, wouldn't the second one be suspicious solely because... if you're confirming it... it means you actually did something besides click a button right? And if it wasnt an address you owned?

Does each address show the amount transferred? If it doesn't, with my current knowledge of how things work, I would maybe assume the second address is used for a commission. Depending on what funds I would be transferring, maybe I would be suspicious and cancel the whole thing to find out why 2 addresses are displayed.

Re: Exodus Bitcoin Wallet: $490k swindle

#168
post #156

The operational security measures one has to take these days to secure crypto is insane. You have to build your own mini intelligence agency just to protect your digital crypto assets. You have to do: - Principle of least privilege. - Zero Trust. - Compartmentation. - Hardened Operating Systems with no malware and strong endpoint defense. - Firewalls that whitelist only your IP and disavow everything else. - 2FA/MFA/…

That's precisely why I never bothered with crypto. I figured even back in the days of early Bitcoin I would at the very least need a dedicated device like a mostly air-gapped laptop running my own wallet software to do transactions. Storing coins on an exchange had always struck me as fundamentally idiotic, even before MtGox occured.

The problem has gotten much, much worse, not better, over the past decade.

Re: Exodus Bitcoin Wallet: $490k swindle

#169

Earlier quoted context omitted.

Solutions have been on the way for more than five years, but literally nothing has changed and all we've gotten is pyramid schemes and gambling. Chains and protocols have exploded in complexity and technical debt to the point where nobody fully understands the attack vectors. By now I am convinced that anything beyond pyramid schemes is never going to happen.

It's frustrating, I agree. People are obviously going to continue being people with pyramid schemes and the like. At the same time, there are enough who also agree that it's a mess, have closely studied the successes and mistakes of the past, and are building a solid foundation for doing this right. I mean, what we're really talking about here is creating a fundamentally new system for which the financial system oper…

> there are enough who also agree that it's a mess, have closely studied the successes and mistakes of the past, and are building a solid foundation for doing this right.

People who "closely study mistakes and successes of the past" are in a very rare supply in the crypto space, and for a good reason: because people who actually closely study mistakes and successes of the past don't want to touch that space even with a 10-yard stick.

The reasons were spelled out in no uncertain terms 7 years ago in https://medium.com/@kaistinchcombe/ten-years-in-nobody-has-c... and followup here https://medium.com/@kaistinchcombe/decentralized-and-trustle... 17 years in, all those reasons remain the same.

Re: Exodus Bitcoin Wallet: $490k swindle

#170
post #145

Earlier quoted context omitted.

No, this is usually (apologies if not in your case) a straw man, and representative of the usual HN blind spot for cryptocurrency. Ledger and Trezor hardware wallets do protect against this class of attack. We are rapidly approaching a world in which those with significant assets or job responsibilities should be carrying physical 2FA tokens, which can allow use of private keys while protecting them (a hardware walle…

> The base rule in crypto has always been “not your keys, not your coins” This is because blockchains have no way of enforcing laws, including property rights. Therefore it comes down to this. Imagine that whoever got hold of your car keys, automatically became the owner. This is what "not your keys, not your coins" means.

“Enforcing laws” with regard to what? Censoring transactions? Freezing accounts?

If people want a system where this as well as excessive inflation are close to impossible, they now have an option, with the clear caveat of that ownership.

It’s not like there aren’t other options to choose - custodial services and multi-signature wallets. Banks are custodial services too, and that’s fine.

Post reply on HN