Live data from Hacker News

“Crypto drainer” template facilitates theft

blog.confiant.com

201–210 of 228 posts

Re: “Crypto drainer” template facilitates theft

#201

I absolutely despise crypto scammers, but looking at those asinine graphics they use to lure in their suckers, it make it VERY VERY VERY difficult to have any empathy for their victims. If that whole "Amazing Pandaverse" theme template appeals to your aesthetic sensibilities and primal urge to get rich quick and screw everyone else and the environment while wearing kewl sunglasses and dollar sign bitcoin logo bling j…

Lol come on, not everyone who falls for these are douchebags. Many is min wage jobs just trying to get out of it and 'make it', I bet they think its childish looking too but hey I can make double my meager savings

I totally agree, it's victim blaming, but the incredible level of self sabotage and tolerance for douchbaggery the victims exhibit is a huge drain on my limited supply of empathy, after so many years of trying to deprogram and empathize with gullible racist fuckhead suckers who got scammed by Trump, and have been programmed to view empathy as a weakness, so don't deserve it themselves. And there's probably a huge overlap between people who admire golden toilets and bored ape jpegs.

At any rate, they'll probably reskin these templates to feature Hummel figurines, then I can feel sorry for the victims again.

https://www.youtube.com/watch?v=57nge8q8CKk

Re: “Crypto drainer” template facilitates theft

#202
post #77

Earlier quoted context omitted.

I have a CS degree and have worked at FAANG for 6 years and that was straight gibberish to me. I guess maybe because I have only worked at FAANG using traditional tech and not crypto startups?

I bet a whole lot of your day to day technical and administrative work is gibberish. Your yearly evaluation alone probably would require training for an outside person to understand. Which is to say... don't assume jargon is pointless.

Unless it's crypto jargon, in which case it's carefully designed to be pointless and indecipherable. That's the whole point.

https://mashable.com/article/multiple-slurp-juices-single-ap...

>'Multiple slurp juices on a single ape' meme perfectly captures the stupidity of NFT culture

>If I know anything to be true is this mixed-up world, it's that ape holders can absolutely use multiple slurp juices on a single ape. Any fool knows that. It's as simple as two plus two equals four. An ape holder can use multiple juices on a single ape; this is fact.

Re: “Crypto drainer” template facilitates theft

#203
post #93

Earlier quoted context omitted.

All connecting a wallet does is allow the app to see your public keys. Private keys are not directly exposed. The app can then request the user sign transactions, but they must be explicitly approved by the user. Where fraud typically happens is when a user thinks they're signing an innocuous transaction, when in fact they're signing a malicious one. This is generally a hard problem, but it's very clear from the wall…

Where do the private keys reside in this scenario?

Most common three subscenarios: A hardware wallet connected by USB/Bluetooth; locally on disk/memory; in a third-party application.

Only on the second case does the browser extension handle primitives like private keys and in no scenario do they get exposed to a site.

The more common crypto-thefts are phishing (user gives away their recovery phrase) or malware (scanning for on-device keys and recovery phrases).

Re: “Crypto drainer” template facilitates theft

#204
post #75
post #66

Earlier quoted context omitted.

What does a user see? How should a user investigate a transaction to check what it does? Is there any good automated explanation/visualization of the effect of a transaction?

This is what I do: When a site initiates a transaction, you can see the address you're interacting with. You should then look up the address on etherscan to see if it has public code and a lot of transactions. Then you should search that address in google and see if the main site links to it. A lot of projects have a list of addresses in their github. You can also inspect the function code. Once you're comfortable, y…

> Also you can create a new throw away address, transfer just a little bit of coins to it and interact with the contract. If it does what you think it should do, then you can create a new account and do it again.

How much money would you be spending on this scheme (in transaction fees)?

Re: “Crypto drainer” template facilitates theft

#205

Earlier quoted context omitted.

I bet a whole lot of your day to day technical and administrative work is gibberish. Your yearly evaluation alone probably would require training for an outside person to understand. Which is to say... don't assume jargon is pointless.

Unless it's crypto jargon, in which case it's carefully designed to be pointless and indecipherable. That's the whole point. https://mashable.com/article/multiple-slurp-juices-single-ap... >'Multiple slurp juices on a single ape' meme perfectly captures the stupidity of NFT culture >If I know anything to be true is this mixed-up world, it's that ape holders can absolutely use multiple slurp juices on a single ape. An…

It's reminiscent of conspiracy theories. You can sit there and untangle the jargon until you understand all the oblique references to events, and it's still nonsense.

Re: “Crypto drainer” template facilitates theft

#206

Earlier quoted context omitted.

Yeah, I think the main differences are: * Phished Apple Pay transactions can be reversed. Crypto transactions can't be reversed. * Actors who phish Apple Pay transactions will be banned. Crypto bad actors generally can't be banned.

Banned from what? If somebody sets up a phishing website in the US with intent to steal funds, they are equally as liable whether their target is a crypto wallet or Apple Pay.

Banned from the banking network. You can't receive credit card payments directly.

Re: “Crypto drainer” template facilitates theft

#207
post #94
post #70

Earlier quoted context omitted.

CBDC has never been about blockchain or cryptocurrency. That's what the first "C" means, and why the "D" isn't a C". It's Venmo or Zelle but run by the government bank.

Here's the Fed's Project Hamilton experiment [1]: > In our design users interact with a central transaction processor using digital wallets storing cryptographic keys. Funds are addressed to public keys and wallets create cryptographic signatures to authorize payments. The transaction processor, run by a trusted operator (such as the central bank), stores cryptographic hashes representing unspent central bank funds.…

> transaction processor, run by a trusted operator

> there are no intermediaries

Except the transaction processor.

Which part doesn't sound like Venmo?

"Signed transactions" is essentially SSL/SPIF/I don't know the details but it's regular Internet security encryption and signatures.

The only difference from Venmo is that users get a proper PK instead of phone or email address id, and it's vertically integrated.

Re: “Crypto drainer” template facilitates theft

#208
post #187

Earlier quoted context omitted.

How is regulatory capture a problem of democracy? Surely you only need a regulator and a party to capture them? For example, what's stopping a company in China lobbying a minister for regulations that harm their competitors? The Minister may not have been elected through democratic means, but regulatory capture can still occur.

I didn't mean exclusively. I meant it's an existing problem, the distance between the regulator and the authority, which in democracy is quite distant, but in other form of government can also be quite distant.

I think we're getting closer but I still don't understand. What do you mean by "the authority"?

Re: “Crypto drainer” template facilitates theft

#209

Earlier quoted context omitted.

It's pretty well known that individuals _do_ need protections against this while institutional investors do not. When crypto gets on the news, regular, uninformed people go and dump their life savings in to it. No matter how much you tut tut and say they should have done their research, they will still do it. And preventing people from losing their life savings on scams is good for society in general.

No. If you invest your money in something you do not understand, you deserve to lose it. I'm sorry you think that you need some authority to put their thumb on the scale and tell you what you can and can't do with your own money.

Do you feel the same way about violent crime? I.e., if a person through their own stupidity or naivete puts themselves in a position where they become a victim of armed robbery/assault/murder/rape, did they get what they deserved?

Re: “Crypto drainer” template facilitates theft

#210
post #21
post #14

Earlier quoted context omitted.

How exactly would regulation help in this case? Most countries already regulate pretty strongly against theft.

Again, the purpose of blockchain-as-capital is exactly to escape regulatory requirements. One of the main reasons why we are able to use the banking systems like we do, is the ability, generally, to unwind translations that were fraudulent. There are also disclosure forms that must be presented as a double-check, to transactions that cannot be unwound. With most blockchains, this is entirely not feasible. The irony i…

No need to condescend-- the gap isn't that I didn't read what you wrote, or even that I disagree. Your point is just unrelated to the situation we're talking about.

A wallet is not like a bank. It's like.. well, a wallet. If you hand a wallet full of cash to a thief, no banking regulation will protect you. The tradition digital equivalent is a Visa gift card or Western Union.

Post reply on HN