Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

231–240 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#231
post #138

Earlier quoted context omitted.

He can buy half a house in Sunnyvale, California. (And after he pays his income tax, 1/3 or 1/4 of a house.) https://www.zillow.com/sunnyvale-ca-94087/luxury-homes/?sear...

Don't forget the property tax. Also, some of those are fix-er-uppers, and basic remodels are $100k's out here. Edit: Don't want to sound too negative. This is a great windfall. Simply sticking it into an investment account should pull in financial independence/retirement by 5-20 years, depending on his age.

> basic remodels are $100k's out here

My _kitchen_ remodel in 94087 cost over $100k

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#232

Earlier quoted context omitted.

Not even close. There's no reliable way to get a fixed income, and inflation is very high.

>no reliable way to get a fixed income You could buy an annuity from an insurance company. A quick Google search shows that $2mil should buy a 40 year old about $70k/year for the rest of their life.

An annuity would not be a good deal unless you're in extremely good health and over 75 or so.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#233
post #102

Earlier quoted context omitted.

If you're poor and gambling, then you're making a stupid financial decision. So the odds of you being financially stupid seem likely to be high.

No. People buy lottery tickets for a lot of reasons. It is a fun bit of escapism and entertainment that costs just a few dollars. You're making the assumption that everyone plays the lottery because they think it is a smart financial decision.

My only beef with lottery players is that they always take forever in the convenience store line.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#234
post #75

> Had the issue not been promptly resolved, malicious users on the chain could have exploited the flaw. This means a cyber actor could have gained access to the unlimited generation of fresh ETH tokens. I am curious, would it be easy to detect an individual who was exploiting this vulnerability?

In my post-mortem I go into this a bit: someone had actually triggered the bug (on accident while debugging the Etherscan block explorer) but it hadn't been noticed by anyone (and the person at Etherscan didn't realize the ramifications). I believe, due to the atypical mechanism used to store the account balance state on Optimism (which is discussed in detail in my post-mortem as this is also what I claim to be the r…

Thanks, I only read the article linked and had not yet dug any further. I appreciate how much work you put into this!

For anyone who may have missed the link in the article or thread, this is it: https://www.saurik.com/optimism.html

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#235
post #93

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

Poor people aren’t stupid

No, but they usually don’t have great money management skills due to not having said money to manage. It’s not any different than warning first time farmers about all of the ways running a farm can go bad.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#236
post #219

Earlier quoted context omitted.

Time to trot out my favourite paraphrase of Babbbage: I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a statement. Suppose another ape and I are out enjoying the State of Nature, and we both should have a round troy ounce of silver in our pockets, with heads and tails as an agreed convention. Suppose I were to say to the other ape, "on whose face does Fortune shine her rays?"…

Why would I prevent this encounter? Did two adults consent to behavior they both felt benefited them? Who are you or I to suggest our ideals are better than theirs? All I've said is that you, nor I, should be responsible for making this behavior possible - you seem to have misinterpreted my intent completely if you think the absence of a right is the same as a mandate against someones ability to participate freely as…

You’re confusing rights and entitlements.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#237
post #199

Earlier quoted context omitted.

Or, the criminal could buy goods and services with the monero directly. The IRS will ask questions of those people, but not the black hat "security researcher".

I want a mansion. How do I buy that with monero?

You could fly to Dubai.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#238

This just proves how insecure the blockchain / web3 / cryptocurrency space is. It's good to see white hat hackers in this space trying to fix what is already broken. But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid.

Do you think that a bank or a government would've handled fixing such a flaw as well has optimism did? All tokenization schemes are ponzi scams including USD, it's just that some use violence to stay relevant, and other use bug bounties.

To be fair we should be weary of both systems. Crypto isn't something sustainable in the long run. USD isn't a ponzi scheme, it is backed by commerce. Crypto isn't the multi sales and trades of goods are what dictate the value of the currency.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#239

Earlier quoted context omitted.

>But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid. Seems like just an opinion to me, and a poorly opinionated one at that.

Can you name any examples of cryptocurrencies being used that are not scams, ponzi schemes or for speculative purposes? All I see are people holding coins and not using them at all for anything else other than 'I want coin to go up'.

https://thegraph.com is one example.

Tokens are used to have a stake as an indexer (data provider) and to pay for query fees (data consumption), and if indexers tamper with the data they lose their stake.

It was released last year and has a long way ahead to mature, but it's an amazing product and tokens/blockchain is essential to its decentralized nature. Simply put, there is no way to accomplish this if the network didn't adopt its own cryptocurrency.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#240
post #32

Earlier quoted context omitted.

IRS doesn’t care as long as you pay taxes on the money. KYC and AML? Just lie that you mined the monero on a now defunct pool. I have a plenty of coins that I genuinely acquired in such manner and haven’t had issues selling them. The bank only cares about hearing a vaguely consistent story, they aren’t cops. The KYC stuff will only become a problem if you get caught via some other means, because lying to the bank is…

> IRS doesn’t care as long as you pay taxes on the money. Lol, you never actually handled the sums the submission is about right? The IRS will definitely ask questions about where the money you spend come from, if you end up on their radar. And if the answer is not satisfactory, they will grill you on it.

IRS isn’t going to do a deep dive into your purported monero mining activities unless you go out of your way to give them cause to do so.

And even if you did, there’s no way for them to ever prove where your monero came from unless you fucked up during either the hack or the swap to monero.

Even if the IRS suspected that you’re lying to them, how could they prove it?

Post reply on HN