Live data from Hacker News

The Resolv hack: How one compromised key printed $23M

chainalysis.com

81–90 of 174 posts

Re: The Resolv hack: How one compromised key printed $23M

#81

Earlier quoted context omitted.

>I mean they use Blockchain, right? Isn't that like the only real requirement for the name crypto? Absolutely not. Cryptocurrently exclusively refers to permissionless, decentralized, cryptographically secured, irreversible, fungible monetary system with a disinflationary or non-inflationary supply, following a voluntary, collectivized governance model. A vast majority of tokens colloquially referred to as "cryptocur…

If your definition excludes Ethereum your understanding of the term so differs from everyone else's that we aren't talking about the same thing

Ethereum is a great utility token. Smart contracts absolutely have utility in the digital economy. It's just not a cryptocurrency, is all. It had a massive premine, there's no supply cap, it's subject to OFAC censorship, and has effectively demonstrated that just ~4.8% of the total ETH supply can vote to cause rollout and widespread adoption of a fork that reverses transactions.

We need different words for these fundamentally different things, because conflating them causes real confusion, as this very hack demonstrates. People are surprised that an admin can lock transactions precisely because the word "cryptocurrency" led them to assume properties that don't exist in stablecoins.

Re: The Resolv hack: How one compromised key printed $23M

#82

Missing from the article - the hacker first compromised Resolv Lab's AWS account, took a private key from KMS that was used to control minting, then managed to extract $25 million into ETH before all protocol functions were suspended.

Do you have a source for that information? I'd like to read more on it.

https://www.chainalysis.com/blog/lessons-from-the-resolv-hac...

https://xcancel.com/zacodil/status/2035658779706974556

Re: The Resolv hack: How one compromised key printed $23M

#84

Earlier quoted context omitted.

Let’s be honest, it’s principally for illicit use, a tiny fraction of privacy folks and then a lot of people caught in between who don’t understand yield but want to bet on a volatile asset and have to use a stablecoin to go between. (Because the backers of the volatile thing are doing something illicit.)

You are a decade late, nowadays stablecoins are commonly used in international trade. Most Alibaba sellers accept USDT nowadays, same for Indian ones.

> stablecoins are commonly used in international trade

For a rounding error value of "commonly," sure. (Catering to a financially-constrained market is good business. But it, by definition, will never be an important one in the grand scheme of things.)

Re: The Resolv hack: How one compromised key printed $23M

#85
post #80

Earlier quoted context omitted.

One of the two is very close to something that actually happened to me. I tried to open up a bank account for paying immigration related costs to a particular shithole country, which is both legal and was part of a fully legal endeavor, but no bank would do it. The other example is somewhat concocted but rooted in the time I spent in Iraq and noting almost all transactions are performed outside the banking system, in…

Clearly your situation of trying to obtain residency in the Comoros by investment would raise eyebrows at banks whose job it is to monitor tax compliance. I don't think you're describing an everyman kind of scenario. I also don't entirely understand why you're even rationalising the purpose of the account to the bank. Can't you just open an account for any purpose? It takes me five minutes to open an account online,…

Pick an FATF grey list country that isn't sanctioned by your country. Then try to wire money there. Let me know how it goes and whether you really aren't asked to explain anything.

Re: The Resolv hack: How one compromised key printed $23M

#86
post #80

Earlier quoted context omitted.

Clearly your situation of trying to obtain residency in the Comoros by investment would raise eyebrows at banks whose job it is to monitor tax compliance. I don't think you're describing an everyman kind of scenario. I also don't entirely understand why you're even rationalising the purpose of the account to the bank. Can't you just open an account for any purpose? It takes me five minutes to open an account online,…

Pick an FATF grey list country that isn't sanctioned by your country. Then try to wire money there. Let me know how it goes and whether you really aren't asked to explain anything.

[deleted]

Re: The Resolv hack: How one compromised key printed $23M

#87
post #45

Earlier quoted context omitted.

Is there any proof, or even indication, that this wasn't an inside job?

Usually I would expect proof for a positive - like that it was an inside job, or there being an indication of it. I'm not saying whether it was or not, just that it seems unusual for you to ask about proof of it NOT being an inside job.

In a court of justice you'd be right, of course.

But for online armchair speculation, you have to admit it seems a likely explanation.

Re: The Resolv hack: How one compromised key printed $23M

#88
post #78

Earlier quoted context omitted.

Exactly. Stablecoins make zero sense.

Unless you are also trying to prop up the us government by buying treasuries (us based stable coins)

Most Treasuries are held by US banks, investment firms and municipalities. I'm pretty sure those firms hold a good chunk of global stablecoin volume, given the nonexistent regulation of crypto in the US relative to other countries.

Re: The Resolv hack: How one compromised key printed $23M

#90

According to a writeup at https://www.chainalysis.com/blog/lessons-from-the-resolv-hac... this started with a plain old hack that compromised their signing key. They also had a smart contract which didn't do some proper checks, but the hack was only possible with the stolen private key. Whoever held the private key was able to mint a lot of money, unchecked. So there was a traditional hack at the core of this heist,…

We've changed the URL to that link from https://bfmtimes.com/hacker-mints-80-million-worth-of-fake-s... above. Thanks!
Post reply on HN