Live data from Hacker News

“Crypto drainer” template facilitates theft

blog.confiant.com

171–180 of 228 posts

Re: “Crypto drainer” template facilitates theft

#171
post #20
post #15

Earlier quoted context omitted.

btw "bad regulation" is usually due to regulatory capture [1] whether in legislation (ie, regulation without teeth, designed to fail) or in practice (ie, revolving door/corruption). Which usually points back to the companies/industries being regulated. [1] https://en.wikipedia.org/wiki/Regulatory_capture

Again, this can be true, but regulatory capture is a problem of democracy, not of regulation powers themselves.

How is regulatory capture a problem of democracy? Surely you only need a regulator and a party to capture them?

For example, what's stopping a company in China lobbying a minister for regulations that harm their competitors? The Minister may not have been elected through democratic means, but regulatory capture can still occur.

Re: “Crypto drainer” template facilitates theft

#172

Earlier quoted context omitted.

"requests a signature for a hex ETH transaction." What an earth does that even mean? It's no wonder people keep messing this up. You need to spend half your life keeping up with the tech just to not get scammed.

You don't know what a digital signature is? This is the equivalent of being mad at banks because you don't understand what a bank routing number is. >It's no wonder people keep messing this up. The type of user that doesn't understand this should not even be using cryptocurrency in the first place.

I'm guessing the confusion is the "hex ETH" part. I know what a digital signature is and I can guess that ETH = ethereum, but have no idea what "hex" means so I can't "keep up" with your comment either.

Re: “Crypto drainer” template facilitates theft

#173
post #170

Earlier quoted context omitted.

The UX is similar to buying something with Apple Pay from a website in my experience.

Apple Pay doesn't run as a browser extension with a nasty habit of granting bad actors full access to drain your funds in a totally irreversible way. Does any of that fall under "user experience" for you?

The distinction between “browser extension” and “baked into Safari” didn’t seem like an important distinction for this discussion.

The similarities are that in both use cases the user is presented with a request to approve or deny.

Re: “Crypto drainer” template facilitates theft

#174
post #76
post #40

Earlier quoted context omitted.

I feel the same way about it I do when I see someone blasting down the freeway on a motorcycle in shorts and t-shirt. If something happens, then we should try to help, but I'm not showing up for the candle lit vigil and pretending it's crazy that 1+1=2.

Seems more like someone walking down the sidewalk at 1am and stopping to buy a drink from a lemonade stand, and getting jumped by a gang and mugged.

Crypto is new and unknown for most people, and high risk-high reward. Lemonade stands are tried and tested, and most people understand them well. I think a better analogy would be someone walking into a trap-house and buying drugs: they might have the high of their life, or they could get robbed. There are no regulations, so it is up to the individual to use their "street-smarts" to be successful. A person who gets robbed buying drugs or loses Crypto in a scam can be criticized, whether this is "victim blaming" or "being realistic" is just semantics.

Re: “Crypto drainer” template facilitates theft

#175
post #77
post #68

Earlier quoted context omitted.

the wallet in question is probably metamask, a browser extension. it injects a web3 provider in `window.ethereum`. connecting the wallet is done by calling `window.ethereum.enable()`, this pops up a dialog asking you to connect an address to the website. it just tels the extension that the website is allowed to interact with the extension This article is about phishing in the context of cryptos. Silent signing doesn'…

I have a CS degree and have worked at FAANG for 6 years and that was straight gibberish to me. I guess maybe because I have only worked at FAANG using traditional tech and not crypto startups?

Some js code makes a popup window appear for user to enter a transaction address (like bank details) so they can clicky click on it. Then it shows those details to confirm.

Is that simple enough for a senior FAANG engineer?

Re: “Crypto drainer” template facilitates theft

#176
post #73

Earlier quoted context omitted.

Nothing stops a person making a new wallet with limited assets for interaction with less reputable websites. Web3 culture has made this quite difficult in practice. For example, it's quite normalised to say "new exciting nft project, only available to existing owners of expensive nfts". This sort of thing is considered an ownership perk. And it's why those discord hacks were so damaging, a statement like that was mad…

Why is the MetaMask UI so dumb that it can't say "This transacation is sending your NFT to address X. Address X has [reputation stats of some sort]. Is that what you want?"

Surely attackers could just make new wallet as soon as they are added to the blacklist? Unless making a new wallet and updating the script is difficult / expensive, a blacklist system would have pretty low benefit:cost.

Re: “Crypto drainer” template facilitates theft

#177
post #74
post #13

Earlier quoted context omitted.

You can create a different wallet for each transaction, and do all sorts of complicated things, but nobody does. Just like you could pay your phone bill with a prepaid Visa each month just in case they overcharged you.

But why isn't it fully automated, like Apple Pay or privacy.com?

The same reason anything isn't automated: the developer estimates the cost of developing the system is higher than the potential upside. At some point, someone will add this functionality to their coin / platform because they think the potential upside will be worth it.

Re: “Crypto drainer” template facilitates theft

#178

Earlier quoted context omitted.

It turns out you're not the first person to realize that this is an issue. If you'd actually read up on cryptocurrency wallets before commenting, you might have found there are multiple solutions for this out already, including one of the most popular Ethereum wallets called Argent, which let's you set limits. Basically the fraud described is a twist on the classic "Musk giving away BTC" scam that's all over Youtube…

> If you'd actually read up on cryptocurrency wallets before commenting, you might have found there are multiple solutions for this out already, including one of the most popular Ethereum wallets called Argent, which let's you set limits. You're making a great example of the victim-blaming I mentioned in my comment: That anyone who is surprised by their money disappearing clearly just didn't do all of the right resea…

It's an app that you download and setting up is so easy an 8 year old can do it. No one has to deploy a smart contract on their own, you just go to the app store and install it. It's inexplicable to me why someone would complain about software they've clearly never used or even looked at.

Of course people can use other wallets if they like to. These are open networks just like the internet itself. No one can stop folks from doing dumb stuff online, input their credit card information where they shouldn't, wire thousands of dollars to a "girl" overseas who "loves" them, visit shady sites with their outdated Internet Explorer on a WindowsXP machine... Why didn't Microsoft prevent this!?

Re: “Crypto drainer” template facilitates theft

#179
post #107

Earlier quoted context omitted.

And not just secure system design. “Undo” is powerful in any app, not just because it can roll a change back with a single click, but because scary dialog boxes (“Really, really REALLY delete this file? It can not be recovered once deleted, so check this box saying you know what you’re doing before clicking OK”) don’t work for regular apps, either.

How would you undo a crypto transfer, and is that a feature that fits in that system?

There are ways it could be built into the contract. But most don't support that operation today.

Re: “Crypto drainer” template facilitates theft

#180
post #179

Earlier quoted context omitted.

How would you undo a crypto transfer, and is that a feature that fits in that system?

There are ways it could be built into the contract. But most don't support that operation today.

On whose authority and why? In this case the customer was promised a product they didn't get. And with traditional banking usually it's the other way around, businesses have to live with chargebacks for products they sell to people with stolen card info.

Always someone getting burned, but in this case it's the "idiots" for lack of better word. Don't try to make cryptocurrencies work like fiat, that's exactly the kind of problems they're trying to solve.

And let's say someone implements your solution, years later you will read how a bad actor did a chargeback for all the coins in those contracts and you will claim it was a retarded feature from the start.

Post reply on HN