Live data from Hacker News

FTX faces potential hack, sees mysterious outflows totaling more than $600M

coindesk.com

751–760 of 890 posts

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#751
post #742

Earlier quoted context omitted.

There isn't zero regulation. An online businesses is subject to the laws of its customers' countries. And the laws may not be up to date enough for some new scams, but they aren't completely naive. For example ponzi schemes are illegal. If they were doing that the govt will go after them (sooner or later...). A quick google search will net you plenty of stories about prosecutions.

I am not subject to laws of a foreign country that isn't willing to hunt me down.

yeah the guy in my home country who broke into my car can say the same thing. Different problem.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#752
post #270

Regardless of whether you are pro- or anti- crypto, the collapse of FTX, SBF's bubble bursting in a rather extreme fashion, and now this hack are more nails in the coffin for mainstream support. I am no fan of crypto myself, but it's interesting to think what would have to happen for crypto to burnish its image. Would key people have to voluntarily form some sort of coordinating council and self-regulate? Would they…

This is a Wall Street corruption story. https://twitter.com/wallstreetpro/status/1591167190996504576 Sam, Caroline, and everyone at the top of FTX and Alameda have very close family ties to key power brokers on Wall Street, which is how they were able to run this scam. FTX has also lobbied extensively for harsh regulations on DeFi, which is a key reason that he was hated by people in the cryptocurrency space, and ado…

Wiki was quiet about Caroline Ellison's family but a random post on the internet just happened by and the claim is her father is Glenn Ellison.

https://economics.mit.edu/people/faculty/glenn-ellison

but p.s. the whole comment is worth a paste:

SEC Chair Gary Gensler’s old boss at MIT was Glenn Ellison. His daughter Caroline Ellison is the CEO of FTX sister-company Alameda Research (and Sam Bankman-Fried’s lover apparently).

The GC of FTX used to be lead counsel to Gary Gensler when he was CFTC Chair.

Sam Bankman-Fried’s mother was Hilary Clinton’s lawyer.

Gabe Bankman-Fried, brother to Sam (also a former Jane Street trader), is founder of “Guarding Against Pandemics”. He was a Legislative Correspondent for the US House of Representatives and an advisor to large political donors in the Democrat party.

The family Aunt Linda Fried is a WEF member on the Global Agenda Council on Aging.

The father, Joseph Bankman, is a Stanford professor who has lobbied on behalf of Hedge Fund managers before Congress before (film records exist).

FTX Head of Ventures & Commercial at FTX Ventures, Amy Wu, started with the Clinton Foundation years ago.

Nishad Singh FTX Director of Engineering has spent over 8 million for Dem candidates.

Obama's Commodity Futures Trading Commissioner, Mark Wetjen, was the head of FTX Policy & Regulation.

Chief regulatory officer of FTX is Dan Friedberg was previously a lawyer at Ultimate bet (a site where they basically cheated against players).

Stuart Hoegner General Counselor at Bitfinex/Tether was previously Director of Compliance at Excapsa which was responsible for the Ultimate bet poker software.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#753
post #717
post #656

Earlier quoted context omitted.

I would consider the moral failure of SBF to be worse than the incompetence of Karpeles. Also, SBF was a billionaire hobnobbing with politicians and celebrated by Forbes. Karpeles was some confused dev on his computer who loved his cat and wanted to build a coffee shop. SBF's failure is going to have larger consequences outside the crypto sphere.

Is there anything happen to Karpeles for what he did with mtgox?

He was in a custody for about a year, he was later sentenced to a suspended year in prison. He still lives in Tokyo, no idea what he does for work now though.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#754
post #18

Earlier quoted context omitted.

In unrelated news SBF just found he had a bunch of crypto in his personal wallet. Totally not at all the pile of crypto that was last seen in the FTX wallet.

A minor problem with the blockchain is that the blockchain is actually an authenticated record of all transactions, so it’s pretty hard to hide where the crypto went unless you never actually exchange it or use it to buy something.

Swap to Monero then slowly trickle swap back to your coin of choice as you need the funds. 'Problem Solved'

There is a reason US regulated exchanged with KYC don't deal in XMR.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#755
post #625

Earlier quoted context omitted.

the fact that it has been executed so poorly to me seems like it is an insider who woke up and thought they could get away with it because they hd access to the keys

Wouldn’t an insider be an expert on crypto markets? They literally ran one

1) this is not the market. It’s just blockchain txns.

2) trust me when I say, no one in crypto except some very very select exchanges actually know how to make a market trading software. They think they can compete with NYSE which is large and employs such incredible talent that it still survives in a really tough industry. They’re likely closer to my grad school project, which even I can tell you, sucked absolute balls.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#756
post #635

The hacker has spent the last 11 hours slowky and incrementally converting all the various tokens they got to ETH. They've been using a variety of different defi exchange and have eaten large slippage fees, at least once over 5M lost in slippage. We're not seeing any else, e.g. laundering through another exchange, splitting into different accounts, automating the liquidation of tokens to ETH, off loading ETH into a c…

what are the best practices for dumping a significant amount of illiquid shitcoins under time pressure?

The harmony bridge hack by Lazarus group (north korean actor) is a good example:

The first address used is 0x0d043128146654c7683fbf30ac98d7b2285ded00

It's a bit harder to trace using public tools because they immediately start splitting off the various coins to other addresses, but looking at just the USDC:

They split it off into a single purpose address that is just responsible for converting it to ETH. They do this via private transactions utilizing uniswap v3 and a set amount just about every minute (they settled on ~2M). If you scan through them their slippage is very good here. If you wait a bit of time you let the arbitrage bots move funds from wherever is available so your slippage isn't so bad.

account responsible for USDC conversion: https://debank.com/profile/0x58f4baccb411acef70a5f6dd174af78...

This account was also responsible for a number of liquidations: https://debank.com/profile/0x9e91ae672e7f7330fc6b9bab9c259bd...

They again show good slippage and also show that they use 3 different exchanges

After they've converted everything to ETH with good slippage they then fan out to multiple accounts that then do a series of deposits into tornado cash at 100 ETH each.

They were done with the liquidation within 2 hours. This attacker is still liquidating as far as I can tell

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#757

Earlier quoted context omitted.

I honestly don't understand why any speculators get bailed out ever. They're in it for above-market profits, how is it that they don't have to accept the risk?

Madoff's victims weren't bailed out with Government money, they recovered assets from Madoff. (It was with Government effort though, including "clawing back" money from other Madoff customers who had actual gains!)

Then it's not a bailout, it's asset recovery. That's fine with me - somebody rips you off, take them to court like everybody else has to.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#758
post #538

Earlier quoted context omitted.

Retail investors are creditors right? Though I guess you mean only the larger creditors. I think the bigger difference is that bankruptcy proceedings take a long time and to a retail investor ‘you might get some money back in N years’ isn’t so different from ‘you get nothing’.

> bankruptcy proceedings take a long time and to a retail investor ‘you might get some money back in N years’ isn’t so different from ‘you get nothing’. Does anyone actually remember MtGox? It wasn't actually that long ago!

Karpelès never went to jail. He was convicted of poor recording keeping, not of embezzlement, and given a suspended sentence.

If - hypothetically - someone else wanted to take a similar path, the odds of jail time are actually pretty low.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#759
post #725

Earlier quoted context omitted.

Weird. Why ETH and not Monero? ETH can be traced.

They're largely ERC-20 tokens, which can be swapped for ETH on DEXes. Monero is a whole separate blockchain, and cross-chain swaps are still in their infancy and don't have markets to convert ERC-20 tokens to Monero, or definitely not with any sort of volume. The ETH will probably eventually be laundered and some of the cleaned coins sent places they could eventually be traded for XMR and eventually cashed out, but t…

"still in their infancy" implies they will eventually mature. Non-zero chance we're watching the final implosion of blockchain based cryptocurrency.

Re: FTX faces potential hack, sees mysterious outflows totaling more than $600M

#760
post #120

It gets worse: somebody has pushed what appears to be a malicious update to the FTX app, and the official FTX telegram channel is warning people not to even browse to the website! https://twitter.com/zachxbt/status/1591293813519253504

I’ve been trying to figure out the technicalities there. Neither the ios nor android apps have updates since the crash. The update box is clearly based on their pre existing popup used for things like 2FA. Could this popup have been modified with new text and linked to a new malicious site without an app update on ios or android? Or, could the popup only function if it was already coded into the app waiting to be act…

A couple quick searches for “ftx app react native” makes me believe at least part of their app, if not the entire thing, is react native (it’s possible to have a hybrid native/react native app). It’s totally possible and quite common to be able to load the JavaScript bundle from a remote server. Microsoft has a service to do exactly that called Codepush. Expo also has a service and it’s not very complex to roll your own. How a react native app works is all the native code is compiled into a “shell” of an app and then a JavaScript bundle is loaded (it can be shipped in the binary or loaded from a server) and that’s where all the layout and logic lives. Not only is it possible to make small changes, you could conceivably ship an entirely new app this way as long as you don’t need to add any new native dependencies. Of course the App Store/Play Store don’t allow “major” changes, but they have no real way of knowing. In Apple’s case, you need to provide them with a login for them to review the app (not sure about the play store, but possibly them too). It would be trivially to load one bundle for Apple and another for everyone else. If you had control of the backend you could even target specific accounts and load a compromised bundle with no one else the wiser. It’s fairly easy to strip out the JS bundle to examen, so I’d say targeted attacks would be the smart way to do it. It would give you a lot of time before people caught on vs compromising everyone. I’m sure there’s folks out there already tearing into the js bundle looking for shenanigans.
Post reply on HN