Live data from Hacker News

Social engineering scam that nearly cost me all of my ETH

twitter.com

191–200 of 423 posts

Re: Social engineering scam that nearly cost me all of my ETH

#191

Earlier quoted context omitted.

It’s degrees of suspension of disbelief. Software is just tricking sand into to thinking. I have no issue believing that an imaginary consensus stored ledger in thousands of computers all secured by massive amounts of energy and limited to 21M units over 100 years might be valuable. The ability for people to copy this software idea? Not valuable. The ability for people to issue new tokens on existing chains? Not valu…

> I have no issue believing that an imaginary consensus stored ledger in thousands of computers all secured by massive amounts of energy and limited to 21M units over 100 years might be valuable. It's not "secured" by energy. You can't convert a Bitcoin into the original amount of power required to produce it, which is the defining quality of a financial security. It's more accurate to say that Bitcoin's value is ret…

Hmmm, you do agree it has value then!

It’s a little more nuanced, while some component of maintaining hashrate/energy, it’s best be be thought of as a point in time expenditure given the network size, participants and technology available. Once a block is minted at a given difficulty, it can never be undone (with a negligible probability), as a chain reorganization would need to put in more energy than that to undo it.

It’s a conversion, abstractly. Probabilistic finality at a given level of technological and economic resource exploitation.

Re: Social engineering scam that nearly cost me all of my ETH

#192

"She tells me a bit about her metaverse project, Space Falcon. I'm not really sold on it, but I'm not really an NFT person so I didn't have any reason to think it was a bad idea either.[...] It seems kind of like a get-rich-quick scheme, but again, that's kind of how I see a lot of NFTs. With all that she's doing for Arrow, there's no harm in showing a little support." The real takeaway from this is that it's dangero…

Yeah it's pretty ironic that a "legitimate" NFT venture and a project invented solely for social engineering are indistinguishable even for someone who presumably knows a lot about the crypto space.

Re: Social engineering scam that nearly cost me all of my ETH

#193
post #190

Earlier quoted context omitted.

Civil asset forfeiture is a national disgrace. But it's also not a disgrace for traditional finance: it's a disgrace with respect to the latitude our justice system gives to individual LEOs and a sign that the government is willing to extrajudicially punish people instead of pursuing justice through the courts. Put another way: assert forfeiture is not some kind of "gotcha" against traditional finance in favor of cry…

I'm all for the legal process and there is a legitimate way to seize assets. But asset forfeiture is not that. It's only enabled because it is trivial and is done outside of the normal legal process. It doesn't help that the beneficiaries are the very people that can initiate the forfeiture. If someone goes through the legal process and is found to be guilty and their assets are seized that's fine. But if someone is…

I don't think we're in disagreement?

In any case: the really egregious examples of civil asset forfeiture are the petty ones: the government stops someone for the crime of DWB[1], and seizes all of the property they have on their person (including, sometimes, the car itself.) It's a disgusting crime, but one that doesn't typically extend to the victim's bank accounts or other financial resources, unless there's a larger case being pursued against them. And so, once again, it's not clear how cryptocurrency improves the state of affairs: either you're carrying a hot wallet around with you for your day-to-day expenses (in which case you're subject to the same seizure), or it's roughly equivalent to a traditional financial produce and isn't subject to a spurious seizure (but might be subject to a larger one).

[1]: https://en.wikipedia.org/wiki/Driving_while_black

Re: Social engineering scam that nearly cost me all of my ETH

#194

Earlier quoted context omitted.

I have done multiple clawbacks via payment processors. In each case, I escalated (vendor -> processor -> my bank -> CFPB) until the dispute was resolved to my satisfaction. In nearly all cases, no separate restitution was required: the processor or my bank was able to reverse or halt the ACH transaction before the money settled. In the handful of cases where settlement had already happened, they were able to counterm…

Yes but, not sure this is a fair comparison. Doesn't ACH transactions take 1 to 2 business days to settle by design, as they are processed in batch and go through an intermediate clearing house ? Venmo/PayPal/Fedwire transactions should be able to settle in real time, which can be more convenient at the expense of easy reversability

Venmo and PayPal are, to the best of my knowledge, settled via ACH if you use a bank as your source of funds. That's what I've always done, since it provides the greatest amount of personal control over my transactions.

If you use a payment card (debit or credit) with a payment service, then they might use either the payment card's network or ACH, depending on what the card issuer supports.

Re: Social engineering scam that nearly cost me all of my ETH

#195

Earlier quoted context omitted.

If you're asking for the implementation details, there's a group trying to do it right now. You should look them up if you're interested. > IF you just switch from SQL to NFT the organisation will not suddenly become less corrupt, or whatever the issue with them is. It's true that it won't make the managing organization less corrupt - it will make them nonexistent. That's the idea behind decentralized decision-making…

How would you be able to get rid of the organisation? So many people talk about various crypto use cases but they can almost never explain how it would work. From land deeds to insurance to domain registration to in game assets etc etc, people have all these wonderful ideas. It would be interesting to one day have at least one of these ideas explained.

It's literally whoever owns the keys listed as the registrant owns the domain. If you lose your keys you lose your domain. You have no recourse if someone squats on your domain, uses a lookalike domain for phishing, steals your domain, etc.. And for the privilege of having a judgement proof blockchain with no oversight you get to buy your domain from an early adopter that's squatting (investing) and you get to pay fees every time you blink.

All the crypto bros printed (mined) a bunch of monopoly money (coins), invented assets (NFTs), bought (allocated to themselves) all the assets (NFTs) using their monopoly money (coins), and want us to buy into these crappy systems with real money so they can sell us the assets (NFTs) while still being the landlords (transaction processors) that charge us rent (fees) on everything forever.

Re: Social engineering scam that nearly cost me all of my ETH

#196
post #147

Earlier quoted context omitted.

You ever heard of asset forfeiture? There's two sides to everything. Not really "owning" something is great if you're the victim of fraud, but has its downsides when you become a target and someone wants to arbitrarily capture your wealth https://en.wikipedia.org/wiki/Asset_forfeiture

Civil asset forfeiture is a national disgrace. But it's also not a disgrace for traditional finance: it's a disgrace with respect to the latitude our justice system gives to individual LEOs and a sign that the government is willing to extrajudicially punish people instead of pursuing justice through the courts. Put another way: assert forfeiture is not some kind of "gotcha" against traditional finance in favor of cry…

Forteiture scenario 1: cops take your cash. It's on you to sue them and prove to a court that it's legitimately yours.

Scenario 2: they take your hardware wallet, then they must prosecute you and prove to a court that the money is not legitimately yours, to get the key. IANAL, but am I wrong?

Re: Social engineering scam that nearly cost me all of my ETH

#197

Earlier quoted context omitted.

> I have no issue believing that an imaginary consensus stored ledger in thousands of computers all secured by massive amounts of energy and limited to 21M units over 100 years might be valuable. It's not "secured" by energy. You can't convert a Bitcoin into the original amount of power required to produce it, which is the defining quality of a financial security. It's more accurate to say that Bitcoin's value is ret…

Hmmm, you do agree it has value then! It’s a little more nuanced, while some component of maintaining hashrate/energy, it’s best be be thought of as a point in time expenditure given the network size, participants and technology available. Once a block is minted at a given difficulty, it can never be undone (with a negligible probability), as a chain reorganization would need to put in more energy than that to undo i…

The wonderful thing about economic value is that, for better or worse, we get to decide what has it. A large number of people have decided that Bitcoins have economic value, and it's not particularly salient to my arguments as to whether that's true or not.

The rest of what you've written doesn't really concern me, because all I was interested in was pointing out that Bitcoin doesn't securitize energy.

Re: Social engineering scam that nearly cost me all of my ETH

#198

Earlier quoted context omitted.

Civil asset forfeiture is a national disgrace. But it's also not a disgrace for traditional finance: it's a disgrace with respect to the latitude our justice system gives to individual LEOs and a sign that the government is willing to extrajudicially punish people instead of pursuing justice through the courts. Put another way: assert forfeiture is not some kind of "gotcha" against traditional finance in favor of cry…

Forteiture scenario 1: cops take your cash. It's on you to sue them and prove to a court that it's legitimately yours. Scenario 2: they take your hardware wallet, then they must prosecute you and prove to a court that the money is not legitimately yours, to get the key. IANAL, but am I wrong?

The answer to this probably depends on your local jurisdiction, thanks to America's unique system of legal devolvement.

Instead, I'll point out that the answer does not matter: from the moment that they have my hot wallet instead of me, I can no longer use it. It doesn't matter to me whether they can actually liquidate it or not. And, as I pointed out earlier, I'd harm my own case by attempting to liquidate my assets with a separate copy.

Re: Social engineering scam that nearly cost me all of my ETH

#199

This was a multi-week long social engineering scam targeted at Thomas. Thomas has a Discord for a drone transportation startup, and the scammers proceeded to embed themselves in the community and provide valuable labor such as web design and graphics design in order to earn his trust. Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave whe…

There's a more general takeaway, and it's one every developer discovers for themselves, sooner or later:

- People don't read what's in front of them.

I've seen this emerge in a vast array of fields. No matter how much we highlight specific details, for all our efforts in red-flagging irreversible actions, folks will often blitz past a confirmation dialog, nag screen, or notification message, without internalising the details or the risks. For those in financial technology, as in this specific example, irreversible actions also extend the attack surface for fraud.

Even the brightest minds can be lazy (some might even say it's a feature, not a bug) and one should never rely upon the opposite. We consequently face a design choice, for all irreversible (or hard-to-reverse) actions, the most common options being:

a) allow a grace period;

b) redesign, if possible, to make it user-reversible;

c) build a forcing function for diligence[1]; or

d) expect support tickets about that feature.

The default is (d), and the helpdesk won't thank us, since the workload generally scales linearly with growth at a high opportunity cost.

[1] e.g. https://en.wikipedia.org/wiki/Two-man_rule

Re: Social engineering scam that nearly cost me all of my ETH

#200
post #161

This was a multi-week long social engineering scam targeted at Thomas. Thomas has a Discord for a drone transportation startup, and the scammers proceeded to embed themselves in the community and provide valuable labor such as web design and graphics design in order to earn his trust. Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave whe…

For somebody with $100M+ I find it strange how excited Thomas got about the prospect of some strangers setting up a meeting with some random founders. With that much money would it be that difficult for Thomas to set up a meeting with them on his own?

He might have the wealth, but he is nouveau riche. He probably doesn't have the connections and hasn't experienced enough of the rich people world to see what those connections look like. He probably (subconsciously) thought this was a start of that sort of thing.
Post reply on HN