Live data from Hacker News

The Resolv hack: How one compromised key printed $23M

chainalysis.com

41–50 of 174 posts

Re: The Resolv hack: How one compromised key printed $23M

#41
post #33

Earlier quoted context omitted.

Stablecoins aren't cryptocurrencies in any sense of the word. It's just electronic FIAT.

I mean they use Blockchain, right? Isn't that like the only real requirement for the name crypto? As long as you burn as much electricity as Andorra does in a week just to make a transaction, you're probably a cryptocurrency. And that's their sole benefit it seems.

>I mean they use Blockchain, right? Isn't that like the only real requirement for the name crypto?

Absolutely not. Cryptocurrently exclusively refers to permissionless, decentralized, cryptographically secured, irreversible, fungible monetary system with a disinflationary or non-inflationary supply, following a voluntary, collectivized governance model.

A vast majority of tokens colloquially referred to as "cryptocurrency" couldn't be further from these principles. There are no stablecoins that are cryptocurrency. Ethereum is not cryptocurrency. Any coin issued by a corporation (e.g. Ripple) is not a cryptocurrency.

Re: The Resolv hack: How one compromised key printed $23M

#43
post #25

What is the point of stable coins? Like why does anyone buy them? It seems to me that their initial value is 1usd per token (or some other fiat I guess) and that's also the roof of their value: they kinda guarantee that they won't become more valuable than that. They are less usable than fiat: more businesses accept fiat than crypto, especially weird and small coins like all stable coins are. There isn't really a flo…

They’re not really meant to go up in value.

The main use is just having something dollar-like that you can move around easily. That’s useful outside the US, but also for plenty of people inside the US depending on what they’re doing; especially businesses that have a hard time getting or keeping normal banking (cough gambling, porn, weed cough).

They’re handy inside crypto since you can move in/out of other assets without touching a bank. And sometimes you can earn yield on them, which is part of the appeal (with the usual “this can blow up” caveats).

Also, there’s a reason every company wants to launch one: if you control the stablecoin, you get the float and the rails. That’s a pretty nice business if people actually use it.

If you already have solid access to USD and don’t care about that flexibility, they’re less compelling.

But yeah, not risk-free at all (depegs, issuer risk, etc). And honestly there probably isn’t much real need for dozens of slightly different stables beyond the business incentives.

Re: The Resolv hack: How one compromised key printed $23M

#44
post #24

Earlier quoted context omitted.

Currency isn't a homebrew computer or backyard car project; it is either centralised or not; there is no in between. Blockchain with central authority is the worst of both worlds.

Not really. At a traditional bank I have to trust n people with varying degrees of access. Et ceteris paribus, any reduction in n is an improvement, even if n is not zero. Of course n can be smaller and the specific people less trustworthy, but that's quite a different thing.

That access is to provide account support, no? Reverse fraudulent transactions and the like. A "bank" could just not do that save for if you're a large enough client to merit attention but why would I want to bank there if I'm not a large enough client?

Re: The Resolv hack: How one compromised key printed $23M

#45

According to a writeup at https://www.chainalysis.com/blog/lessons-from-the-resolv-hac... this started with a plain old hack that compromised their signing key. They also had a smart contract which didn't do some proper checks, but the hack was only possible with the stolen private key. Whoever held the private key was able to mint a lot of money, unchecked. So there was a traditional hack at the core of this heist,…

Is there any proof, or even indication, that this wasn't an inside job?

Re: The Resolv hack: How one compromised key printed $23M

#46
post #30
post #25

What is the point of stable coins? Like why does anyone buy them? It seems to me that their initial value is 1usd per token (or some other fiat I guess) and that's also the roof of their value: they kinda guarantee that they won't become more valuable than that. They are less usable than fiat: more businesses accept fiat than crypto, especially weird and small coins like all stable coins are. There isn't really a flo…

To take advantage of the ability to send money that way without the volatility

Let’s be honest, it’s principally for illicit use, a tiny fraction of privacy folks and then a lot of people caught in between who don’t understand yield but want to bet on a volatile asset and have to use a stablecoin to go between. (Because the backers of the volatile thing are doing something illicit.)

Re: The Resolv hack: How one compromised key printed $23M

#47
post #25

What is the point of stable coins? Like why does anyone buy them? It seems to me that their initial value is 1usd per token (or some other fiat I guess) and that's also the roof of their value: they kinda guarantee that they won't become more valuable than that. They are less usable than fiat: more businesses accept fiat than crypto, especially weird and small coins like all stable coins are. There isn't really a flo…

They’re not really meant to go up in value. The main use is just having something dollar-like that you can move around easily. That’s useful outside the US, but also for plenty of people inside the US depending on what they’re doing; especially businesses that have a hard time getting or keeping normal banking (cough gambling, porn, weed cough). They’re handy inside crypto since you can move in/out of other assets wi…

Ah, so we're basically battling the prudishness of VISA and MasterCard?

That... Actually makes sense.. Which is a rare feat for crypto!

Re: The Resolv hack: How one compromised key printed $23M

#48
post #34

Earlier quoted context omitted.

you can send them around easily without having to deal with bullshit payment systems

No-one in the real world wants to be paid with a $USR. Most everyone wants a cashapp/zelle/PayPal/wire transfer. The bullshit payment systems gained ground on crypto while crypto became more difficult/less usable

PYUSD is run by PayPal afaik.

Re: The Resolv hack: How one compromised key printed $23M

#49
post #19
post #5

But guys, what you don't understand is that the code IS the contract!!! That means you don't even NEED regulation!!

Yeah, people who genuinely believe that don't have any problem with smart contracts getting exploited. Of course there are people who _say_ that because it's financially expedient at the time, then change their tune. But both groups exist and this is not really a gotcha.

I dont mind smart contracts getting battle tested.

I also dont mind the whole chain coming together to vote to reverse the transaction.

I also dont mind a bunch of people being unhappy with that and forking.

Re: The Resolv hack: How one compromised key printed $23M

#50
post #4

Tl;dr another bug in a smart contract exploited, hacker got away clean.

Not that it matters much, but this summary isn't right. The contract wasn't "exploited." The company's AWS account was compromised, giving the attacker access to a (off-chain) private key.

The contract relied on the key to mint new tokens. The hacker gained access to the key (through AWS) and with it minted as much as they'd like. It is certainly a valid take that a contract that only required the private key to mint an unlimited amount of the token isn't a good one, but you don't exploit someone's front door lock by grabbing the key from under the welcome mat.

Post reply on HN