Live data from Hacker News

Social engineering scam that nearly cost me all of my ETH

twitter.com

361–370 of 423 posts

Re: Social engineering scam that nearly cost me all of my ETH

#361
post #9

Earlier quoted context omitted.

Most people who invite me over for a sandwich would be insulted if I entered their house, took the sandwich they made me and left. In fact, I probably would never get invited over again.

Meanwhile I wish someone would come over to take one of my sandwiches. It turns out that human contact in covid’s era is hard to come by. You’re probably right though. But if you ever find yourself near Lake St Louis, MO, feel free to raid our fridge.

Your parents is trying to say the same thing: that you'd appreciate some [meaningful] human contact.

They suspect you wouldn't invite them again if all they did was raid your fridge, and not even say so much as a "hi".

Re: Social engineering scam that nearly cost me all of my ETH

#362

Earlier quoted context omitted.

Low-quality comment.

I'd say GP's comment contributes more to the discussion than yours.

Debatable. GP basically ignores all the interesting parts of the article being posted in order to simply say the usual spiel about how much HN hates crypto. The relevance to the original article is close to nil.

I'm calling them out for that -- perhaps in a way that's too terse, but at least I'm not completely derailing the conversation like they're doing. But thank you for prompting a longer response from me.

Re: Social engineering scam that nearly cost me all of my ETH

#363

I can get behind cryptocurrency and stuff, but the idea that anyone can write a contract that says "I get to do what I want with your money" and then build their own custom, one of a kind UI with no way to limit what the user thinks the button does for you to sign such a transaction, it's got to be the biggest, most massive security hole I've ever seen brushed off. You want me to put the title to my house on it? You…

Yeah. And to take it one level further, a language that let's you lock up / burn a coin in any fashion other than a very explicit Burn() command is equally reckless. The platform needs to provide guardrails for developers too.

Re: Social engineering scam that nearly cost me all of my ETH

#364

Earlier quoted context omitted.

I know of Thomas through the Rocketpool community Discord (a decentralized Ethereum staking pool). He's a regular on there. And I'm one of 90ish members in the Arrow Discord. It's a super early stage startup that's still in the conceptualization phase. I don't know how he got his capital, I don't know his background. But he's been an engaged member of the RPL community and seems genuine in his interest for drone tran…

when he invites you to get in on the ground floor of an amazing opportunity, I suggest you take him up on it. He's rich so it definitely won't be a scam!

My impression of him is that he's a decent guy who got targeted by scammers who knew he was rich. I've participated in the ground floor of plenty of opportunities. Some of them work out, some of them don't. But the ones that do more than make up for the ones that don't.

Re: Social engineering scam that nearly cost me all of my ETH

#365
post #222

Earlier quoted context omitted.

> that you should use systems that have reversible transactions. OTH I'm pretty sure that if the mark had been using such systems years ago, he wouldn't have $100m+ worth of ETH now ; )

If the last lottery ticket winner hadn't bought a powerball ticket, they also wouldn't be worth millions. Beware the survivorship bias: https://xkcd.com/1827/

Ethereum is a technology platform with a rich ecosystem. Investing in ETH isn't a crap shoot.

Re: Social engineering scam that nearly cost me all of my ETH

#366

Earlier quoted context omitted.

What's "totally programmatic"? Is that where programmers never make mistakes, protocols never have bugs, users always remember their secret keys, read and understand the code they're running, on the computer they wholly own and trust, with perfectly functioning hardware? And somehow resistant against the $5 wrench attack and state-level seizure?

Protocols have bugs, yep. Audited and battle tested protocols, less often though. For example, there are hacks every day where people exploit smart contract bugs, yet there are contracts securing billions of dollars that have not been hacked. Both can be true at once. Something like this wouldn't be widely used without lots of iterations to iron out issues like that. $5 wrench attack is easily thwarted by splitting o…

[deleted]

Re: Social engineering scam that nearly cost me all of my ETH

#367

Earlier quoted context omitted.

> At $10k in America, KYC and AML laws force banks to step through extra layers of verification Isn't that only for cash transfers? > which would likely involve a mandatory in-person meeting with the bank customer At least at Chase and Fidelity, wires can be done over the phone with no limit. > to verify their credentials and purpose I've never seen a banker really help to verify wire instructions, as in contacting t…

Yes, the banking industry won't do much to prevent Aunt Senile from wiring $80k to Nigeria, although I doubt they make it easy. Hell, I couldn't even phone-authorize a wire of 8k to buy a car two states over, but I guess that's just my bank. Had to bloody pay for the car on credit card, no joke. But the scenario in the OP is only possible in cryptocurrencies. You can't put a button on a website "Click here to send a…

It's a fair criticism. But the reverse is also true, in that money is frictionless to raise and coordinate in cryptocurrencies, such as the $45M attempt at buying a copy of the Constitution (which failed, but people simply got a refund), or the $56M that was raised for Julian Assange's defense last week.

I'm able to work with total strangers, raise money, sell products, contribute to causes, commission art work etc, etc, hold those funds in a smart contract treasury and encode rules to govern the spending of those funds.

Safe guards do exist for the aforementioned issue. Number one is not holding significant sums of money in a single wallet, unless it's a multi-sig that requires multiple parties to agree to transactions (like Gnosis Safe wallets, which store $100B+ in assets and are battle tested at this point).

Re: Social engineering scam that nearly cost me all of my ETH

#368

Earlier quoted context omitted.

What's "totally programmatic"? Is that where programmers never make mistakes, protocols never have bugs, users always remember their secret keys, read and understand the code they're running, on the computer they wholly own and trust, with perfectly functioning hardware? And somehow resistant against the $5 wrench attack and state-level seizure?

Protocols have bugs, yep. Audited and battle tested protocols, less often though. For example, there are hacks every day where people exploit smart contract bugs, yet there are contracts securing billions of dollars that have not been hacked. Both can be true at once. Something like this wouldn't be widely used without lots of iterations to iron out issues like that. $5 wrench attack is easily thwarted by splitting o…

If you think it's so easy, maybe you should do it to demonstrate.

If you mean that it'll become easy enough over time, that's an assumption I don't buy.

Re: Social engineering scam that nearly cost me all of my ETH

#369

Earlier quoted context omitted.

easier than you think. https://www.cnbc.com/2020/10/15/how-one-familys-nightmare-il... https://www.nar.realtor/wire-fraud

Those are all intentionally sending money; you just have had someone tell you the wrong account. Which is just as easy with crypto. And, just like with crypto, you can always reach out to the party you are trying to send money to via another means to confirm the address. When I purchased a house, I Googled the recipient, confirmed the certificate, Googled the number found on their website separately to confirm it was…

It's rare that buyers of houses and property are that thorough. On the contrary, my friend recently bought a plot of land for which the sellers did not own the title. The title company, who's only job is to verify this, completely missed it. The fake sellers made out with tens of thousands of dollars and the real owners, who are from Germany, are still haggling with my friend and trying to get her or the title company to pay for their lawyer fees, and she still doesn't have title to the land!

At least with crypto, the chain of ownership is transparent and can't be faked. So validation is cheap and easy to do.

Re: Social engineering scam that nearly cost me all of my ETH

#370

Earlier quoted context omitted.

There’s no advantage, just laziness. A wallet like that shouldn’t be easy to access and should never be used for for anything other than funding their other hot wallets.

Concentration of funds is a great advantage for borrowing.

In this case, liquidity is pooled across the Aave protocol. There's no difference in the interest rate for someone lending / borrowing $50M or $50. It's easier, but you should probably never have more than 10-20% of your portfolio in a single wallet. And probably should shrink that down even further as your net worth grows.
Post reply on HN