Poly Network hacker returns $258M after stealing $600M
71–80 of 303 posts
Re: Poly Network hacker returns $258M after stealing $600M
#72Re: Poly Network hacker returns $258M after stealing $600M
#73Earlier quoted context omitted.
I have to agree. I was going to counterargue that technically all hacking is executing permissible actions in the sense that the system you're hacking into ends up allowing you to do what you want. That leads to why we have laws around unauthorized access etc., and that leads to digital contracts that need to be interpreted by a human with some ability to enforce their interpretation. So yes. As the main point of dig…
I've wondered about things like this with video games. I played RuneScape a while back and one of the things my brother and I would do is lure unsuspecting players into the wilderness to kill them and take their stuff. That stuff, RuneScape gold, weapons, and armor, has some real world value. We took it from other people, often by lying to them (e.g. "follow me into the wilderness, I'll show you something cool"). Cou…
Re: Poly Network hacker returns $258M after stealing $600M
#74Earlier quoted context omitted.
> doesn’t mean they haven’t been improved on in some way. In what way specifically ?
In that the specifications are formally specified, and thus can be objectively and automatically verified.
The implementation can be formally written and verified, but the specification itself cannot be automatically verified.
That's effectively what a contract is anyway - it's a specification for a 'legal agreement' which is this sort of invisible obligation that is created after it is signed (for instance, the time spent in contract negotiations is usually spent debating what should happen in edge-cases).
Re: Poly Network hacker returns $258M after stealing $600M
#75I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…
agreed
> A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it
I kind of disagree in philosophy here. If there's a bug in a bank API that lets me transfer funds to my account, I'm still "hacking", even if I'm doing exactly what the API lets me do, because I know very well that I'm not supposed to.
Then again, as you say, the whole spiel of digital contracts is that theyre far too clever to need silly courts and judges and common sense and all that, so... meh
Re: Poly Network hacker returns $258M after stealing $600M
#76From what I recall, the hacker basically doxxed himself by accident by signing a message from his real wallet, linked to exchange wallets which presumably has his KYC info. From there, it was all over. Even if he could launder all that money, international authorities would find him. In fact, the writing style of his messages provide a pretty big clue where he is - Ukraine or Russia.
I think we're past trying to assume peoples identities based on writing styles, it's too easy to fake for the hackers, simply drop 1% of the words you're using and now suddenly people think you're no longer a native English speaker.
And not only is it easy to guess wrong or easy for the hacker to fake, it also adds absolutely nothing to the story/evidence/history by trying to guess the country they are from. If you're right, nothing has been gained. If you're wrong, you've just blamed the wrong nationality, again with no gain if you're right.
Re: Poly Network hacker returns $258M after stealing $600M
#77From what I recall, the hacker basically doxxed himself by accident by signing a message from his real wallet, linked to exchange wallets which presumably has his KYC info. From there, it was all over. Even if he could launder all that money, international authorities would find him. In fact, the writing style of his messages provide a pretty big clue where he is - Ukraine or Russia.
Re: Poly Network hacker returns $258M after stealing $600M
#78Earlier quoted context omitted.
I have to agree. I was going to counterargue that technically all hacking is executing permissible actions in the sense that the system you're hacking into ends up allowing you to do what you want. That leads to why we have laws around unauthorized access etc., and that leads to digital contracts that need to be interpreted by a human with some ability to enforce their interpretation. So yes. As the main point of dig…
I've wondered about things like this with video games. I played RuneScape a while back and one of the things my brother and I would do is lure unsuspecting players into the wilderness to kill them and take their stuff. That stuff, RuneScape gold, weapons, and armor, has some real world value. We took it from other people, often by lying to them (e.g. "follow me into the wilderness, I'll show you something cool"). Cou…
This is all about the level of abstraction
The ‘laws of physics’ in a game may allow you to do unintended things, it’s a complex system. Doesn’t mean that it’s OK at a higher abstraction.
Re: Poly Network hacker returns $258M after stealing $600M
#79From what I recall, the hacker basically doxxed himself by accident by signing a message from his real wallet, linked to exchange wallets which presumably has his KYC info. From there, it was all over. Even if he could launder all that money, international authorities would find him. In fact, the writing style of his messages provide a pretty big clue where he is - Ukraine or Russia.
Unless it’s a decoy dox
Re: Poly Network hacker returns $258M after stealing $600M
#80I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…
It’s so funny to me when everyone touts crypto + smart contracts as revolutionary™ then when you follow a system implemented with them to its logical conclusions you have analogs to everything that already exists. Lawyers to audit the contracts for bugs (and yes there can be bugs in a formally verified spec as well), courts to arbitrate disagreements, and an authority to enforce rules when someone finds a security ho…
i.e. just because analogs exist, don't expect their performance characteristics to be invariant