Live data from Hacker News

A fake job offer took down Axie Infinity

theblock.co

221–230 of 364 posts

Re: A fake job offer took down Axie Infinity

#222
post #114

Earlier quoted context omitted.

what would stop a developer from checking personal email on a work machine?

Themselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines. This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.

Exactly. I was on a meeting a couple of years ago and the co-worker who was presenting his desktop received a personal iMessage that flashed for everyone to see.

Re: A fake job offer took down Axie Infinity

#223

Earlier quoted context omitted.

My understanding of the article was that only 1 person was compromised and that the exploit installed on their computer was then used to access the validator nodes themselves. FWIW, I have no idea what a validator node is but I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up).

> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?

[deleted]

Re: A fake job offer took down Axie Infinity

#224
post #106

Earlier quoted context omitted.

I still can't believe that they opened the PDF on the company computer. I always use my home computer and the poor hacker would get bored of seeing all of my Raspberry Pi projects that I haven't done.

Huh? I've used my company laptops for my personal life for the last 15 years. Why would I want to carry two laptops everywhere? I travel. I barely remember what a personal laptop is.

I hope this is satire.

Re: A fake job offer took down Axie Infinity

#225

I've got to say, this is an incredibly cyberpunk article. > Ronin, the Ethereum-linked sidechain that underpins play-to-earn game Axie Infinity, lost $540 million in crypto to an exploit in March. While the US government later tied the incident to North Korean hacking group Lazarus, full details of how the exploit was carried out have not been disclosed. It's not in William Gibson's style, sounds more like Bruce Ster…

More like Cryptonomicon without the Nazi gold backing.

Re: A fake job offer took down Axie Infinity

#226

Earlier quoted context omitted.

When I first got into crypto, a few things were pretty much drilled into my head: - Not your keys, not your coins; always self-custody - Never use the same machine for trading and for work/surfing the web - Store only funds you want to regularly trade with on a hot wallet. Everything else on a cold wallet.

and this is part of why i think cryptocurrencies should have died before large number of people wasted their money on it. for the average user without the time/knowledge/patience to handle cryptos "properly", the choice is between losing money while handling this shit yourself or losing money while trusting someone else to do it right.

Its an entirely free market. Just because one person doesn't understand the tech and loses his money doesn't mean that everyone else shouldn't be allowed to use it either.

Even if you don't buy into the crypto vision (I don't), a digital-only currency that isn't tied to any nation-state does deserve to exist.

Re: A fake job offer took down Axie Infinity

#227

Earlier quoted context omitted.

> I'm assuming that by compromising one employee's workstation they somehow got access to multiple other machines (which if true is itself a bit of a f* up) Q: If you assume the bad guys have already compromised your workstation, how sure are you that they won't be able to compromise other machines you connect to?

because the workstation was compromised by opening a corrupted pdf, but that vector wouldn't compromise the other machines unless users on them could be induced to open the same pdf. not to say it can't be done, but it was unexplained

It doesn't have to be the same pdf, it could have been an attachments from compromised machine via email/slack. "Hey, can you help me figure this unusual log/transaction summary". How many wouldn't open such an attachment from a "colleague"?

Re: A fake job offer took down Axie Infinity

#228

What an incredible story. In fact it is so incredible that it smells a bit funny to me. Are we sure this heist wasn’t an inside job? Axie was collapsing under its own weight and an employee decided to swipe all of the crypto after making up this crazy job offer PDF story to cover their tracks.

I'm amazed I had to scroll down this far to find the obvious explanation: a rug pull with a press release so the perpetrator doesn't have to fake their own death.

Edit: I thought the lack of details was fishy but the following would be tough to fake:

the FBI has attributed North Korea-based Lazarus Group, highly skilled hackers, to the Ronin Validator Security Breach. The US Government, specifically the Treasury Department, has sanctioned the address that received the stolen funds

Re: A fake job offer took down Axie Infinity

#229

Earlier quoted context omitted.

> The main problem was using a machine that had access to half a billion dollars Going up a level, the main problem was that the company had a system where a single person could irreversibly transfer half a billion dollars away from the company.

The article actually covers that it required 5 out of 9 people to sign off. They got 4 via PDF attacks and 1 via legacy access that was never properly terminated.

I think it's worth noting that the people did not sign off, only the keys did.

The system does not require people to sign off, but for the keys to sign off.

I don't think it's worth calling this a hack, the keys are what owned the moneies, and it's the keys that decided what to do with it. People have access to keys, they don't own them

Re: A fake job offer took down Axie Infinity

#230
post #114

Earlier quoted context omitted.

what would stop a developer from checking personal email on a work machine?

Themselves. I'm saying developers (and employees in general) should not do any personal stuff on work machines or any work stuff on personal machines. This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.

It makes it a bit harder to travel with two laptops, which is one of the nice advantages of working from home.. but I'm otherwise in support of this.

This might just result in employees finding ways to remote access their work computer from their personal computer from wherever they are, but at least that's an additional wall for would-be attackers to hurdle.

Post reply on HN