Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

211–220 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#211
post #206

Earlier quoted context omitted.

At the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?

What’s the reason of holding USDC, isn’t that same as holding cash in bank?

Keeping your money on chain but not subject to price fluctuations.

There’s also pro and anti arguments for being in control of your assets.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#212
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

It's so nice to hear from you. Hope you are doing well.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#213
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

So, while I knew that this had been offered in back channels, I failed to realize that this was not only confirmed to me in e-mail as well as publicly announced: Boba (one of the forks of Optimism that was affected by this same bug) has additionally extended to me their maximum bug bounty reward of $100k, making the "updated total" awarded for this bug (so far ;P) $2,100,042 (which more firmly might be setting a new record).

https://twitter.com/bobanetwork/status/1491989915336388618?s...

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#214
post #2

It's not just any white hat hacker, it's saurik who was behind the original jailbreaking tools for iOS and the creator of Cydia, the unofficial app store back then. He is also now the "CTO" (if the term applies) of a well-known blockchain-based VPN, Orchid. Edit: He has a great write-up about the vulnerability and its discovery on his blog: https://www.saurik.com/optimism.html (which was on HN a couple days ago)

CXO titles in organizations do not exist without a board of directors. Businesses otherwise simply have members, managers, employees, contractors or vendors, or volunteers. You can pretend you're a CEO/CTO, but if you answer to no board, you're not.

Orchid is a Delaware C corp with SEC filings for its offering. Do you think it lacks a board of directors?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#215
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Why not just hack and watch the world burn?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#216

Earlier quoted context omitted.

CXO titles in organizations do not exist without a board of directors. Businesses otherwise simply have members, managers, employees, contractors or vendors, or volunteers. You can pretend you're a CEO/CTO, but if you answer to no board, you're not.

Orchid is a Delaware C corp with SEC filings for its offering. Do you think it lacks a board of directors?

> (if the term applies)

I'm responding to whether the term applies.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#217

Earlier quoted context omitted.

I strongly disagree with that. You really can't claim to speak for everybody.

If you don’t play ball in certain parts of the world, you end up in a river. The price tag is just different. Yours would likely be family or close relatives. I think you’d take money to do something untoward if that was the alternative. Almost everybody would. And there’s nothing wrong with admitting that.

> If you don’t play ball in certain parts of the world, you end up in a river.

OP branched here: "it's not as if the choices were 'commit crime / get bounty'."

Any example relevant to OP's branch cannot end with the subject in a river. The very fact that you are discussing it proves we've jumped to the other branch of the conditional-- the one where the choice is exclusively between `commit crime / get bounty` (by threat of death in your example)

tldr; goto considered harmful on HN

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#218
post #100

Earlier quoted context omitted.

But you could drain out all the ETH in the Optimism reserve by asking to withdraw, since you've fooled the network into thinking you own an arbitrary amount of OETH? Which would keep working until the main L1 Eth network rejects transactions for transferring ETH it doesn't have?

Or until someone notices... All the balances and stuff are public on the blockchain. It only takes one person to write a script to verify that the locked up amount matches the number of tokens out there. and when it doesn't, alert. That then means any attacker will have to be very quick with their theft, and if so, there is still a good chance whatever coins they get will end up blacklisted or the transactions revers…

Just get the ETH into Tornado Cash ASAP, that should avoid any potential blacklisting.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#219
post #134

Earlier quoted context omitted.

Gambling is not a human right, no one deserves to be able to waste resources they have no matter how much they may or may not enjoy it.

Time to trot out my favourite paraphrase of Babbbage: I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a statement. Suppose another ape and I are out enjoying the State of Nature, and we both should have a round troy ounce of silver in our pockets, with heads and tails as an agreed convention. Suppose I were to say to the other ape, "on whose face does Fortune shine her rays?"…

Why would I prevent this encounter? Did two adults consent to behavior they both felt benefited them? Who are you or I to suggest our ideals are better than theirs?

All I've said is that you, nor I, should be responsible for making this behavior possible - you seem to have misinterpreted my intent completely if you think the absence of a right is the same as a mandate against someones ability to participate freely as they wish with other consenting adults.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#220
post #187

Earlier quoted context omitted.

What? So startups should not be allowed? 90% of them fail after all. The odds of a startup being successful is literally gambling.

Are you being sarcastic? I said it is not a human right - no one should guarantee anyone the ability to start a business as it isn't societies responsibility to pay the cost of some individuals risk tolerance. I'm saying the opposite of what you seem to be implying. I'm saying anyone can gamble or start a business, but it's no ones responsibility to make sure they have the option to do so.

Who are you arguing against? I don't think anyone is implying that gambling itself is a fundamental human right.
Post reply on HN