32 comments

  • plantain33 minutes ago
    How on earth is it possible they can cover a 1.5B loss? Are they really sitting on that much profit, or is the goal to ponzi it out from here, MtGox style?
  • chabes15 hours ago
    From the article:<p>&gt; The wallet in question appears to have sent 401,346 ETH ($1.1 billion) as well as several other iterations of staked ether (stETH) to a fresh wallet, which is now liquidating mETH and stETH on decentralized exchanges, etherscan shows. The wallet has sold around $200 million worth of stETH so far.<p>If you showed me a paragraph like this a decade ago and told me it was from 2025, I would have a difficult time believing you.
    • satvikpendem2 hours ago
      Crypto shenanigans were happening in 2015, even as far back as 2010, so I would have to absolutely believed you to hear that it continues happening, as crypto is a fundamentally unstable platform.
    • netrap14 hours ago
      Just crazy. Bank heists fully online...
    • ratg1311 hours ago
      MT Gox got famously hacked over 10 years ago .. anyone keeping this much money in an online wallet would have to be functionally retarded.<p>Yet here we are.
      • smolder2 hours ago
        It&#x27;s definitely embarrassing that people losing their shirts in crypto didn&#x27;t see it coming. It&#x27;s bad that people think a zero sum game is worth playing against incumbents. The marks aren&#x27;t the worst part, though. Everyone promoting memecoins and utility-free cryptocurrency in general is either ignorant or just a bad person with a warped idea of success. Personal money accumulation is a sad goal compared to actual wealth creation. The parasites who push crypto on the hopeful proto-bag holders are destroying the prosperity that supports them.
        • pfannkuchen2 hours ago
          Yeah on memecoins isn’t that just a loophole for running naked pyramid schemes? I.e. a pyramid where everyone knows it’s a pyramid.<p>Like the weird part about a pyramid is that depending on your risk tolerance it may actually make sense to participate in a pyramid even if everyone involved knows it’s a pyramid. So are that many people being scammed as in tricked (seems hard to believe), or is it just a risky form of gambling that is outlawed in legacy formats.<p>EDIT: Ponzi -&gt; Pyramid
          • ghfhghg1 hour ago
            I&#x27;ve never purchased crypto or had any involvement but acquaintances I know have used that exact argument. They know it&#x27;s a pyramid but believe they can get ahead because they were in early enough.<p>They are usually a lot more vague when I ask about their realized gains.
            • anovikov19 minutes ago
              I have many friends who started from really humble beginnings ~5 years ago (or instance, a typical small business like &quot;an e-shop selling bullshit Chinese gizmos online making 20k per month&quot;), and are now uber rich in crypto. Like, hundreds of millions in net worth and spending 200-400k per month. And yes, they don&#x27;t invest their money anywhere except new and new crypto projects themselves, just because they don&#x27;t know anything that gives near similar returns. Not one-off success, but 5-10 or more different avenues of making money there (but certainly none of them was about &quot;trading coins&quot; or passively investing in them).
        • lottin28 minutes ago
          &gt; memecoins and utility-free cryptocurrency<p>As opposed to what?
          • decimalenough9 minutes ago
            During the previous wave of crypto, there were all sorts of ambitious if doomed plans to do interesting things with blockchains. Even Bitcoin was originally supposed to be a means of exchange, not an &quot;investment&quot;.<p>Now we don&#x27;t even pretend that $DOGE&#x2F;$TRUMP&#x2F;whatever has any utility aside from speculation.
          • xmprt7 minutes ago
            Bitcoin, ETH, and Monero all have utility in one way or another. Bitcoin is accepted by most black markets (and Monero is even better for privacy). And software is built on top of the ETH chain. No one is buying stuff using DOGE or Trump coin. There&#x27;s a clear difference between memecoins and legitimate cryptocurrencies whether you like them or not.
      • redrove2 hours ago
        It was an offline multi-sig wallet. Hackers seem to have musked the transaction when the owners signed it as it looked good to them.
        • cypherpunks012 hours ago
          Wow it must have been really musked then, huh?
          • redrove1 hour ago
            A “musked” transaction consists of payload obfuscation and spoofing, more often than not malicious actors create a genuine looking UI with legit transaction details, while being malicious underneath.<p>It’s basically phishing at a transaction signing level.<p>I only found the term a few weeks ago and thought I was the one left out, sorry for not defining it earlier.<p>It’s got an eerie ring to it though, right?
      • posnet1 hour ago
        And only a few weeks ago the lawsuit started payout the &#x27;early lump sum&#x27; repayment option for creditors.
      • jsemrau2 hours ago
        &quot;Bybit CEO Ben Zhou wrote on X that a hacker &quot;took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.&quot;<p>From the article. Not that I endorse crypto, in fact I despise it. But at least per this statement, it seems to have been handled offline. How a hacker could get access to this is another story to unpack.<p>edit: I guess this is the story that &quot;unpacks&quot;. One more reason to not believe in crypto.<p><a href="https:&#x2F;&#x2F;x.com&#x2F;benbybit&#x2F;status&#x2F;1892963530422505586" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;benbybit&#x2F;status&#x2F;1892963530422505586</a>
        • timjver2 hours ago
          By &quot;online wallet&quot; they were likely referring to the Bybit website being the wallet of those customers that held their coins there rather than keeping them in their own private wallets, and not whether the hack involved a hot wallet or a cold wallet. Calling it a custodial wallet would have been more accurate.
  • russnes6 minutes ago
    Kim Jong 1337 hacker strikes again
  • zer0x4d1 hour ago
    I&#x27;m a huge crypto believer but I can admit that we don&#x27;t have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.
    • stouset1 hour ago
      In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”?<p>Put differently, it’s been seventeen years of constant and escalating mayhem. What would finally be enough to shake your faith?
      • throwawayqqq1156 minutes ago
        &gt; what exactly is left to keep anyone a “huge believer”?<p>Bias. I expect believers to have earned a profit or still hold significant quantities of crypto assets.<p>But in their favor, trust in any currency is the foundation of its value. States create it by collecting taxes and paying employees. Crypto currencies generally lack that heavy weight central authority, so they kind of have to believe to the point where they get burned.
      • dandanua55 minutes ago
        &gt; What would finally be enough to shake your faith?<p>Crypto scams run by top government officials? Oh, wait...
    • JTyQZSnP3cQGa8B1 hour ago
      You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?
      • zer0x4d57 minutes ago
        I&#x27;m not too sure but few things come to mind:<p>1. Upgrade protocol to include protections for well known cold wallets held by exchanges (ex: API call has to be made to the exchange&#x27;s security endpoint to validate each transaction out of the wallet. Exchange staff would need to manually allowlist large transactions before they are transmitted).<p>2. Decentralized voting on reversal of transactions (90-95%+ vote needed to reverse to avoid 51% attacks)
        • jeswin51 minutes ago
          This is getting pretty close to the banking system, at which point one needs to ask - maybe just improve existing protocols?
    • silisili10 minutes ago
      Right on. My bank calls me every time I send money out. And I&#x27;m talking like $50. I used to find it annoying, but now I&#x27;m blown away every financial system doesn&#x27;t...
    • JamesLefrere1 hour ago
      Solutions have existed for years (eg Gnosis Safe), they just aren’t being used by that exchange.
      • mhmmmmmm1 hour ago
        Bybit was quite literally using Gnosis Safe for the compromised wallet.
        • zer0x4d56 minutes ago
          I can&#x27;t believe someone posted that without knowing they actually used Gnosis Safe
      • jgilias31 minutes ago
        Can’t tell if you’re trolling here or not, but good one either way!
    • otabdeveloper427 minutes ago
      &gt; let&#x27;s reinvent the banking system except worse in every way
  • Geee58 minutes ago
    There should be something like a &quot;finalizing transaction&quot;, which both the sender and receiver need to sign after the first transaction has been mined, i.e. like an in-built escrow. If it&#x27;s not signed by both, then funds are returned. This wouldn&#x27;t protect against key leakage, but in this case, the tx was signed by accident. This would also protect against sending to wrong address.
    • tromp8 minutes ago
      There are cryptocurrencies in which transactions must be signed by both sender and receiver, such as those implementing the pure Mimblewimble protocol.<p>&gt; Both the sender and receiver need to sign after the first transaction has been mined<p>That makes no sense; miners don&#x27;t mine transactions unless they&#x27;re guaranteed to be valid. All signing must be done before transactions are even published. Otherwise one could DoD-attack the network by having it forward tons of invalid transactions.
    • Mengkudulangsat53 minutes ago
      This would also protect againts dusting attacks.<p>Illicit addresses sending to thousands of random recipients and making them all marked by automated KYC systems.
  • rNULLED1 hour ago
    &gt; have a wallet, work at bybit &gt; understand backdoor &gt; steal money from your account, some from others &gt; bybit pays you back &gt; still have money you stole
  • rkagerer8 hours ago
    There&#x27;s some info and speculation in these two (distinct) articles, but I&#x27;d love to know technical details of where the gaffs were.<p>eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines &#x2F; hardware devices?<p><a href="https:&#x2F;&#x2F;archive.ph&#x2F;YMZrq" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;YMZrq</a><p><a href="https:&#x2F;&#x2F;blockworks.co&#x2F;news&#x2F;bybit-hack-raises-security-questions" rel="nofollow">https:&#x2F;&#x2F;blockworks.co&#x2F;news&#x2F;bybit-hack-raises-security-questi...</a>
    • cypherpunks011 hour ago
      A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what&#x27;s being signed, is my experience using multiple different vendor HW wallets. Not sure if that&#x27;s what happened, but possible this type of problem contributed to the exploit. BTC TXs are simple enough that all HW wallets can basically display what&#x27;s happening, but with turing-complete arbitrary computations in EVM this becomes very difficult.
      • tumdum_6 minutes ago
        &gt; with turing-complete arbitrary computations in EVM this becomes very difficult.<p>I have very limited knowledge about EVM, but those computations are bounded by gas, right? Evaluating them is a finite process.
      • rkagerer1 hour ago
        Thanks for spelling this out, the explanation makes a lot of sense.<p>You&#x27;d think they could at least show a blockie representing the contract, or reputational party who cryptographically vouched for it.
    • mhmmmmmm56 minutes ago
      <a href="https:&#x2F;&#x2F;x.com&#x2F;tayvano_&#x2F;status&#x2F;1847877011462901915" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;tayvano_&#x2F;status&#x2F;1847877011462901915</a> This thread has some info about very similar past attacks, should give some insights into the level of sophistication that goes into something like that.
  • Animats34 minutes ago
    Who says ByBit can cover the loss? The article title says that but the article quotes do not. The CEO only said that their other cold wallets are intact and that withdrawals remain normal.<p>Bybit claims to be regulated by the Virtual Assets Regulatory Authority of Dubai.[1] But the lookup page at VARA says they only have &quot;In-principle approval&quot;, not a full license. &quot;Applicants holding an IPA are strictly prohibited from initiating operations, conducting any virtual asset activities, or servicing clients until they have obtained their full VASP licence from VARA.&quot;<p>Uh oh.<p>[1] <a href="https:&#x2F;&#x2F;www.vara.ae&#x2F;en&#x2F;licenses-and-register&#x2F;public-register&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vara.ae&#x2F;en&#x2F;licenses-and-register&#x2F;public-register...</a>
  • mkagenius14 hours ago
    A crypto exchange WazirX was hacked for ~$300M, roughly 50% of the users fund gone.<p>There is no action on the CEO since the hack in July 2024. He sits in Dubai. He just got a nod from Supreme Court of SG to just average out the funds and distribute it among the users.<p>No action has been initiated against the company&#x2F;ceo for losing the fund. He is geared up to launch another company&#x2F;exchange.
  • qingcharles1 hour ago
    Can someone even explain what Bybit is actually about? I searched around when the hack was announced, but I&#x27;m very confused. Mostly what I saw said &quot;scam&quot; on it.<p>This isn&#x27;t your run-of-the-mill Coinbase style exchange, right?
    • cypherpunks011 hour ago
      It&#x27;s the second largest crypto exchange by volume globally, behind Binance. Specialized in derivatives but they have lots of regular retail products that you might find at Coinbase. Basically like a bigger version of Coinbase from Asia.
  • huang_chung15 hours ago
    Society has devolved a bit when not long ago a heist like this would involve sieging Nakatomi Plaza, now it takes just finding a bug in someone&#x27;s defective Python codes.
    • grues-dinner47 minutes ago
      You don&#x27;t even have to break into a wierd high-tech vault to get an unreasonably slow (or fast) billion-dollar progress bar with a snazzy custom UI toolkit these days. Not sure if technology or inflation is most to blame!
    • Klaster_114 hours ago
      I wonder how many programmers resort to crime after they were laid off and couldn&#x27;t find a job. Like soldiers after a war.
      • ooterness2 hours ago
        Relevant comedy sketch? &quot;Secret agent squad, but they&#x27;re all just the hacking guy.&quot;<p><a href="https:&#x2F;&#x2F;youtu.be&#x2F;cL7lhbtWwbY?feature=shared" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;cL7lhbtWwbY?feature=shared</a>
      • wyre14 hours ago
        That might make for a good book or movie plot.
        • NetOpWibby2 hours ago
          Starring Rami Malek, Tom Holland, Kyla Pratt, and George Clooney?
    • ratg1311 hours ago
      You just gotta trust the wrong people.<p>Don’t forget FTX willingly hired the Ultimate Bet “god mode” guy.
  • philipwhiuk15 hours ago
    It&#x27;s obviously not a cold wallet if it&#x27;s connected to the exchange.
    • abuani15 hours ago
      It&#x27;s also not reassuring that the CEO claims cold wallets are safe and secure, just after losing 1.46B
    • cozzyd2 hours ago
      Perhaps their servers have cryogenic cooling
    • javier213 hours ago
      Cold usually means it needs multiple physical people to sign from offline devices to move it. Hot wallet usually is automated. Here it looks like the «hackers» found a way to trick enough people to sign this transaction
    • gnabgib15 hours ago
      It could still be cold. <i>&quot;took control of the specific ETH cold wallet&quot;</i> sounds like stealing the physical hardware. Like someone stealing the vault key, or the HDCP master key getting leaked.
    • vessenes14 hours ago
      They could have gotten the recovery phrase off some paper, then imported it wherever. More likely than guessing the pin on a ledger with a short number of tries before wiping.
    • Etheryte15 hours ago
      Yeah this makes no sense whatsoever.<p>&gt; [The hacker] took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.<p>Did the hacker physically break into their office or what?
      • shawabawa314 hours ago
        Possibly yes<p>Or some part of their system failed and the key was compromised without them realising it (like the Debian insecure keys debacle or whatever)
  • nodesocket12 minutes ago
    My understand is that the original transaction was a small fraction of the total balance of ETH in the wallet. How then were they able to liquidate the entire ETH wallet?
  • ArtTimeInvestor14 hours ago
    When even professional companies that have billions of dollars under management can&#x27;t securely manage their crypto assets, how likely is it that individuals can?
    • kangda12314 hours ago
      It&#x27;s a different ball game. The resources that went into executing this kind of hack were probably far higher than most wallets are worth anyway.
      • acc_29714 hours ago
        Maybe not - a number of high-value past hacks have been very low effort<p>I have yet to see a thorough explanation of what specifically was hacked here anyhow
  • sleazebreeze15 hours ago
    What are the chances that a Bybit insider is behind this?
    • hinkley14 hours ago
      Or former insider.<p>I spent several years pointing out to my last employer that every former employee could have walked off with secrets that allowed them access to our backends. The were already slowly working on hardening write access but read access was still being worked on a couple months before I left, when I got to write about half of the last mile code for the user facing bits.<p>This is not a unique experience by any means. I’ve seen this sort of thing enough to pay attention when acquaintances bitch about it too.
      • Falimonda4 hours ago
        Are these business-owned exchanges and managed wallets not fundamentally incompatible with making guarantees of security? Is anyone doing it the &quot;right&quot; way and what does the right way even look like?
        • hinkley4 hours ago
          I don&#x27;t know the answer to that, I only have guesses.<p>But one mistake we make over and over is that we write code that just does its best to answer questions as quickly as possible. And when those questions show up 10x as quickly as they have any other time in our company history, they either just plug right along or maybe throw an error.<p>Someone shouldn&#x27;t be able to empty a billion dollars out of an exchange in 10 minutes, unless they do $250B in daily traffic. And I suspect most of them can be, and in even less time than that.
    • mvdtnz4 hours ago
      10000%. You would have to be soft in the head to not conclude that&#x27;s the case.
  • UncleMeat14 hours ago
    &quot;Please rest assured that all other cold wallets are secure.&quot;<p>Unreal.
    • otabdeveloper420 minutes ago
      He means &quot;...secure. (For now.)&quot;<p>He just left off the implied part.
  • thesumofall1 hour ago
    In case of a state actor just imagine the weapons that could be bought with this kind of money and the potential lives lost due to this mess
  • walterbell14 hours ago
    <p><pre><code> Bybit CEO Ben Zhou wrote on X that a hacker &quot;took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.&quot; </code></pre> &quot;Control&quot; has a specific meaning under UCC Article 12, which was ratified in 2022 and is slowly being adopted by U.S. states. It links some rights to control&#x2F;possession of keys, even if a blockchain asset may have been stolen before being sold, <a href="https:&#x2F;&#x2F;www.clearygottlieb.com&#x2F;&#x2F;news-and-insights&#x2F;publication-listing&#x2F;ucc-digital-asset-amendments-finalized" rel="nofollow">https:&#x2F;&#x2F;www.clearygottlieb.com&#x2F;&#x2F;news-and-insights&#x2F;publicatio...</a><p><i>&gt; Article 12 – dealing directly with the acquisition and disposition of interests (including security interests) in “controllable electronic records,” which would include Bitcoin, Ether, and a variety of other digital assets ... a good faith purchaser for value who obtains control (a “qualifying purchaser”) takes its interest free of conflicting property claims... Control under Article 12 is designed to be a technology-neutral functional equivalent of “possession.” It generally encompasses circumstances when a party has the “private key”</i>
    • acc_29714 hours ago
      I think (I assume but could be wrong) in the average CEO X-tweet &quot;control&quot; likely only means &#x27;control&#x27; nobody was reading through UCC Article 12 while drafting this message<p>As in: &quot;The hacker gained access to&quot; &quot;The hacker took charge of&quot; &quot;The hacker assumed authority over&quot;
      • walterbell14 hours ago
        Those are all equivalent to exclusive control of the private key, which is the meaning within UCC Article 12.
    • adastra2214 hours ago
      What is the purpose of this comment?
      • walterbell14 hours ago
        It describes the legal status of stolen cryptocurrency changing after the first sale. This HN story is about stolen cryptocurrency. In particular:<p><i>&gt; The wallet has sold around $200 million worth of stETH so far</i><p>If some of those sales took place within jurisdiction of a U.S. state that has ratified UCC Article 12, then the buyer of the stolen cryptocurrency is now the new legal owner.
        • adastra228 hours ago
          The hacked coins are not &quot;free of conflicting property claims.&quot;
          • walterbell7 hours ago
            <i>&gt; The hacked coins are not &quot;free of conflicting property claims.&quot;</i><p>2023, American Bar Association, <a href="https:&#x2F;&#x2F;www.americanbar.org&#x2F;groups&#x2F;business_law&#x2F;resources&#x2F;business-law-today&#x2F;2023-june&#x2F;how-to-create-a-floating-lien-on-digital-assets&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.americanbar.org&#x2F;groups&#x2F;business_law&#x2F;resources&#x2F;bu...</a><p><pre><code> .. “take free” regime introduced by the 2022 UCC Amendments for these assets. Under these rules, a person who acquires a CER for value, in good faith and without notice of any conflicting property claims, is deemed a “qualifying purchaser” and, as such, takes it free from any preexisting property claims. The 2022 UCC Amendments draw heavily from the UCC Article 3 provisions for negotiable instruments, and these provisions have the effect of making CERs negotiable. It follows that if a secured creditor obtained a security interest in CER inventory and only perfected by filing, that creditor would be at risk of the debtor disposing of the collateral and transferring control to a qualifying purchaser that would take it free from any competing claim.</code></pre>
            • paul_h2 hours ago
              I think you&#x27;re saying this is different to theft-of-car. A stolen car could be sold&#x2F;bought a number of times, but any amount of years later the car belatedly identified as the one stolen from the rightful owner means it is returned. A fraudulently created title isn&#x27;t enough to protect the bagholder from having to return the car.
      • beefnugs12 hours ago
        It is important everyone is thinking real hard about how this is different from traditional theft: there is no way to actually prove the operators didn&#x27;t just steal everything themselves vs actual real hack theft.
        • jgilias25 minutes ago
          There is. ZachXBT has already gotten a bounty for unambiguously pinning this on the Lazarus Group (North Korea).
    • khdzer34531 hour ago
      [dead]
  • insane_dreamer13 hours ago
    Given how many of these exchanges have been hacked (or were fraudulent), how is it that people still use them?
  • scrlk14 hours ago
    I wouldn&#x27;t be surprised if Bybit cuts a deal with the hacker to return the funds. There&#x27;s no way that $1.46 billion of marked ETH can be liquidated and off-ramped to fiat.
    • adastra2214 hours ago
      That’s well within the daily trading volume.
      • plantain34 minutes ago
        Well within <i>real</i> daily trading volume is less clear.<p><a href="https:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;javierpaz&#x2F;2022&#x2F;08&#x2F;26&#x2F;more-than-half-of-all-bitcoin-trades-are-fake&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;javierpaz&#x2F;2022&#x2F;08&#x2F;26&#x2F;more-than-...</a>
      • scrlk14 hours ago
        Exchanges will blacklist the addresses that hold the hacked ETH. They won&#x27;t be able to deposit, or if they can deposit, the ETH will be frozen by the exchange.
        • medellin2 hours ago
          It is on eth and they can use decentralized exchanges.
        • theamk14 hours ago
          I am sure there are still plenty of suckers who believe the whole &quot;cryptocurrencies are fungible&quot; narrative, and would get those ETHs with a discount.
    • mvdtnz4 hours ago
      [flagged]
  • throwaway_v2 hours ago
    woops
  • jauntywundrkind12 hours ago
    Terrifying to imagine how much funding terrorist states might be getting by hacks like this.
    • a_tartaruga1 hour ago
      One in particular gets about 1 billion dollars a year. Already hit their quota in February
  • fjjjrjj14 hours ago
    More like byebit.<p>Unregulated asset exchanges. Haven&#x27;t we been there before a loong time ago?
  • mvdtnz14 hours ago
    Remember the golden rule that when it comes to crypto it is a scam 100% of the time. Congrats to the Bybit CEO on his newfound wealth.
  • tombert14 hours ago
    The entirety of the cryptocurrency world is so obviously a &quot;Chesterton&#x27;s Fence&quot; situation.<p>Every pseudo-intellectual thinks that the fiscal world is &quot;too complicated&quot; and they&#x27;re going to &quot;simplify&quot; it by making some token, only for people to realize that the monetary world <i>is just complicated</i>, and they have to reinvent everything that already existed in the traditional banking system.<p>I had to do some work on an ACH system a couple years ago [1], and I read through a large chunk of the ACH standard, which was about 800 pages. It&#x27;s easy to see and hear that and think &quot;that&#x27;s way too complicated, what could possibly be so hard about money transfers that necessitates an 700 page specification??&quot;, but as I read it and saw how many edge cases it took into account, it was easy to see why it got so huge. It turns out that dealing with money is just a really hard problem at scale.<p>I fell for the cryptocurrency hype of 2021, and I will fully acknowledge that that came out of a complete lack of understanding of how fiscal systems work. I wish everyone else would just grow up already.<p>[1] Usually disclaimer: not hard to find my work history, it&#x27;s not hidden, but I ask that you do not post anything about it (or at least any proper nouns about it) here.
    • medellin2 hours ago
      I don’t know anyone working in crypto who complains about the physical world being too complex. Imaginary dragons are easily slayed.
    • erikpukinskis14 hours ago
      For what it’s worth, I’m a “crypto believer” and I have never considered ease of use to be one of its selling points.<p>What you are describing are the systems of power which create a stable financial system. That is, one where you can put a nickel into a bank account and expect it to be there in a year or a hundred years.<p>That indeed requires a complex web of power structures, because its top line goal is to be stable and dependable. And stability within a complex landscape requires an equally complex network of power.<p>Crypto provides the exact opposite value: it cannot be controlled, no matter how robust your power structure is. It can be <i>insured</i>, at a significant cost, but not <i>controlled</i>.<p>That means in the face of even totalitarian powers someone could still move crypto across any boundary that is permeable to information, which it turns out is a set that roughly approximates the set of all boundaries.<p>This is a terrible way to pay for candy bars, because candy bars are not worth insuring.<p>But what I think the crypto opponents miss is that there is a set of transactions—some criminal, some legal, some immoral, some righteous—which cannot be made in a state controlled financial systems.<p>And that these transactions are what gives crypto value as a currency.<p>To me, where I would like the debate to go is not “is crypto a scam?” but “how does society protect people from the violence facilitated by crypto?”<p>Yes, financial “violence”, which can be insured against, but also real violence: human trafficking, extortion, etc.<p>We anarchists sometimes like to pretend that without rulers we will be freed to care for each other. But in the shadow of a history of violence, there will be more violence too.<p>And the “crypto is a scam” argument I fear is a red herring that distracts from this, the real issue.
      • theamk13 hours ago
        Power structures can absolutely control crypto. They can make it illegal - it won&#x27;t eradicate it altogether (see: war on drugs), but it will severely decrease its influence. No one is bragging about investing their retirement savings into cocaine, and Paypal does not offer it to me either.<p>Or if government is smarter, they can slowly gain control over it. Allow trading traceable currencies via official channels, but with good KYC measures. Do not allow fully anonymous systems. Go after mixers. Prosecute exchanges which do not verify their customers. Once there are plenty of government-sanctioned exchanges in the country, there will be little incentive to create unsanctioned ones, and someone with coins that were marked &quot;North Korean-originated&quot; won&#x27;t be able to spend them in the country.
    • htrp14 hours ago
      The crypto community continues to speed run the history of traditional finance. [1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=31777761">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=31777761</a>
      • a_tartaruga1 hour ago
        It&#x27;s only a matter of time until we get a railroad track laying network secured by proof of railroad track (PoRT) and recreate the panic of 1873.
  • tw198415 hours ago
    another &quot;exchange was hacked&quot; story, why I am not surprised.
    • notfed14 hours ago
      &quot;Oops, we were hacked, hehe, guess we&#x27;ll have to shutdown. Oh and our CEO will be moving to another country.&quot;
  • faefox15 hours ago
    [flagged]
    • dang3 hours ago
      Maybe so, but please don&#x27;t post unsubstantive &#x2F; snarky &#x2F; tropey comments here. It leads to generic &#x2F; repetitive &#x2F; nasty discussion, and we&#x27;re hoping to avoid that here.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html</a>
    • tombert14 hours ago
      The genius behind crypto is that it&#x27;s <i>not</i> just the extremely gullible. I know a fair number of really smart people, academics even, that have bought into the cryptocurrency hype.<p>It has this kind of veil of &quot;high techness&quot; to it that is appealing to smart-but-uninformed people (like me in 2021). I&#x27;m embarrassed that I fell for it, but on the bright side it does make me a bit more sympathetic for other people who also fell for it.
      • michaelt14 hours ago
        <i>&gt; The genius behind crypto is that it&#x27;s not just the extremely gullible.</i><p>I don&#x27;t know about you, but I barely follow cryptocurrency news, and I&#x27;ve <i>still</i> been hearing about major players getting &quot;hacked&quot; several times a year for over a decade.<p>Either it&#x27;s Mt Gox or FTX or The DAO or Bitfinex or QuadrigaCX or Terra&#x2F;Luna or rug-pull meme coins or dollar-backed coins that actually aren&#x27;t or any of a dozen other things.<p>Anyone who isn&#x27;t being extremely careful to avoid scams, given the constant drumbeat of reports about how you have to be <i>extremely</i> careful to avoid scams when dealing with cryptocurrency, is pretty gullible.
        • tombert13 hours ago
          Ironically I think being more educated might sabotage you more with cryptocurrency.<p>My parents, both smart people but neither of which know much about distributed systems or concurrent computing or cryptocurrency, see the news reports about Mt Gox or BitConnect and think &quot;that sounds like a scam&quot;, avoid it, and put money into a Vanguard or something.<p>On the other hand, you have people like me (and probably a not-insignificant percentage of people on HN), who have learned a fair amount of distributed and concurrent programming, and see the &quot;neatness&quot; factor of cryptocurrency, and since the crypto is laundered through interesting tech, we fall for it.<p>I haven&#x27;t touched any cryptocurrency since I fell for the unregistered security calling itself Gemini Earn [1] (so almost three years now), but I did think that stuff like Filecoin was pretty cool. Hell, I&#x27;ll <i>still</i> acknowledge the coolness factor of stuff like Filecoin and Storj and Sia. I just think that the currency itself is wishful-thinking-at-best, and fraudulent at worst (probably somewhere in between).<p>I don&#x27;t think I&#x27;m an especially gullible person, but no one thinks that they&#x27;re gullible, so I&#x27;ll acknowledge that I probably am, but I think a lot of the educated people who got into crypto got into it because they kind of had horse-blinders on when looking at the interesting tech.<p>[1] Not my opinion, but the SEC&#x27;s for what it&#x27;s worth: <a href="https:&#x2F;&#x2F;www.sec.gov&#x2F;newsroom&#x2F;press-releases&#x2F;2023-7" rel="nofollow">https:&#x2F;&#x2F;www.sec.gov&#x2F;newsroom&#x2F;press-releases&#x2F;2023-7</a>
        • joezydeco13 hours ago
          This essay scared me away from Ethereum, among other coins, for good:<p><a href="https:&#x2F;&#x2F;www.paradigm.xyz&#x2F;2020&#x2F;08&#x2F;ethereum-is-a-dark-forest" rel="nofollow">https:&#x2F;&#x2F;www.paradigm.xyz&#x2F;2020&#x2F;08&#x2F;ethereum-is-a-dark-forest</a>
      • tdb789314 hours ago
        Being smart or academic does absolutely not mean these people aren&#x27;t gullible.
        • tombert14 hours ago
          I know, but it is inversely correlated.<p>I don&#x27;t think most academics would fall for the &quot;Nigerian Prince&quot; chain emails, or the &quot;Romance Scams&quot; you see on YouTube, which are things I usually associate with extremely gullible people.
      • akritrime14 hours ago
        To be honest, a distributed logic execution engine is an interesting tech, it just isn&#x27;t something to build any high value economy on top of.
        • tombert13 hours ago
          Sure, I&#x27;ll totally acknowledge that some of the distributed algorithms that have spun out of the blockchain are pretty cool, and I&#x27;ll even go as far as to say that maybe someday we&#x27;ll find some very cool high-value uses from them.<p>Pretend money, at least in my opinion, is not one of those uses.
          • phil2113 hours ago
            It’s been about 15 years now. The killer app for blockchain is Bitcoin.
            • tombert13 hours ago
              I don&#x27;t know, I think some of the papers for distributed consensus might lead to something cool; if nothing else it does seem to be increasing the use of formal methods, which I think is neat.<p>These things can take time; it might be thirty years or more before someone does anything <i>actually</i> useful with the stuff learned from the crypto world.
      • hinkley14 hours ago
        Crypto: where Kernighan’s Law meets con artistry.
    • adastra2214 hours ago
      What is the gullibility here?
      • amatecha14 hours ago
        Thinking you can store your crypto with some 3rd party that _definitely_ won&#x27;t get hacked (or &quot;&quot;&quot;hacked&quot;&quot;&quot;), also thinking your crypto won&#x27;t become worthless from a singular unusual event. Actually the most gullible are the people who think of cryptocurrency as an &quot;investment&quot; XD
        • SirMaster12 hours ago
          I don&#x27;t know. I always store my crypto offline. I bought $1000 worth of bitcoin when it was less than $100 per bitcoin because it seemed like something that could get big at some point, and I was willing to risk $1000 on that thought.<p>My thought was it will some day either be worth a lot or be worth 0 and I&#x27;m OK with both of those possibilities. I don&#x27;t really think I was gullible about anything and yes I thought about it as a risky investment that turned out to pay off quite well.
        • garciasn13 hours ago
          It’s an investment the same way that playing the lottery is. I had a family member win ~$30MM back in the 80s, but he had played the same numbers for decades; someone who knew of this stole the winning tickets and he ended up only getting 7.5MM of the winnings after a protracted court case.<p>Crypto is the same thing. You put money in and you may cash out quickly with a big number, but someone who knows can swoop in and steal your money in a way that is much easier than if you used more traditional investment and banking vehicles.<p>¯\_(ツ)_&#x2F;¯
  • toomuchtodo15 hours ago
    <a href="https:&#x2F;&#x2F;www.web3isgoinggreat.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.web3isgoinggreat.com&#x2F;</a>
  • gosub10015 hours ago
    [flagged]
    • acc_29714 hours ago
      ^Yep<p>When you decentralize finance like this what becomes okay to do according to system rules is exactly what is possible to do according to system rules. We don&#x27;t have humans in that loop anymore to enforce moral judgments about what constitutes unlawful theft (except for 1 or 2 rare &quot;hard-forks&quot; of various blockchains to reverse devastating transactions).<p>I feel bad for people who lose large volumes of cryptocurrency to malicious actors in the same way I feel bad for people who lose large volumes of real money to a casino.<p>It is 2025 now and we all know that anyone who can somehow get your private-key to whatever blockchain backed assets you have &quot;owns&quot; those assets just as much as you do and they are permitted to take them under the rules of the system so whatever you do do not lose that key.<p>There is no higher arbiter of justice in this space so use it at your own risk.
    • unyttigfjelltol15 hours ago
      Yes!<p>A &quot;cleverly masked exploit that altered the smart contract logic&quot;[1] = congratulations!! the contract gives you $1.46B free money!!<p>I anticipate that the defi community will celebrate the inexorable operation of their logical contracts.<p>[1] <a href="https:&#x2F;&#x2F;cryptonews.com&#x2F;news&#x2F;bybit-crypto-exchange-faces-1-5-billion-suspicious-outflows-whats-going-on&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cryptonews.com&#x2F;news&#x2F;bybit-crypto-exchange-faces-1-5-...</a>
    • drak0n1c15 hours ago
      In this case yes - everything went by the design and law of the underlying code. There was no exploited bug or vulnerability flaw besides human laziness here.<p>1) Their multi-signature wallet signing employees lazily clicked through in unison to approve a new smart contract without examining the contents to see if it was unusual.<p>2) Bad security architecture to keep too much in a single wallet that wasn&#x27;t properly kept cold. There should have been a few fully cold wallets, that only rarely transact with mostly-cold intermediary &quot;airlock&quot; wallets which are also separated from the exchange operations and wallets. The signers also need to be different combinations of people for each of those wallets - preferably some of those signers being additionally liable 3rd party technical experts.
      • fsckboy14 hours ago
        &gt;<i>There was no bug or vulnerability flaw</i><p>when code is law, there can&#x27;t be any bugs or vulnerabilities, only features.
    • bryceneal7 hours ago
      I see this quote repeated here often, but working in the industry I&#x27;ve never heard it said unironically by any of my peers or thought leaders in the space. Best I can tell it is a sort of lazy straw man repeated by skeptics. Does it have an origin?
      • consumer4512 hours ago
        <a href="https:&#x2F;&#x2F;blockchain-society.science&#x2F;?p=218" rel="nofollow">https:&#x2F;&#x2F;blockchain-society.science&#x2F;?p=218</a><p><a href="https:&#x2F;&#x2F;ethereumclassic.org&#x2F;blog&#x2F;2024-04-03-ethereum-classic-etc-is-the-leading-smart-contracts-proof-of-work-blockchain-in-the-world" rel="nofollow">https:&#x2F;&#x2F;ethereumclassic.org&#x2F;blog&#x2F;2024-04-03-ethereum-classic...</a><p>Are those appropriate sources?
    • yapyap15 hours ago
      “skibidi is toilet”<p>what r u talkin ab?
  • guluarte14 hours ago
    [flagged]
    • vessenes14 hours ago
      So salty! And yet...How&#x27;s ETH Classic doing? It was the right move at the time to fork. And pretty obviously would be the wrong move today.<p>For context, guluarte is referring to a moderately contentious hardfork done by the Ethereum developers and mining community to reverse TheDAO Hack in 2016 or so. The stakes were much larger then -- Ethereum was newer, not yet battle tested, and TheDAO had something like 10% of all ETH in it.<p>A fork was formed -- &quot;ETH Classic&quot; -- ticker ETC -- which did not reverse the DAO hack, and you can see from valuations that the public preferred the reversal.
      • 0cf8612b2e1e14 hours ago
        I mean, the public comprised of the developers of Ethereum who had significant financial incentive to pretend the hack did not happen and to forever publicize their chain of history.<p>Code is law, up until it costs me.
        • kinakomochidayo14 hours ago
          it was actually up to the node operators to update their clients or not, which resulted in a contentious chain split. just like Bitcoin. decentralization worked as intended.
    • kinakomochidayo14 hours ago
      let’s not forget that Satoshi rolled back Bitcoin in 2010, whereas Ethereum was a surgical state change within a smart contract
      • adastra2214 hours ago
        What are you talking about in 2010?
        • kinakomochidayo14 hours ago
          <a href="https:&#x2F;&#x2F;en.bitcoin.it&#x2F;wiki&#x2F;Value_overflow_incident" rel="nofollow">https:&#x2F;&#x2F;en.bitcoin.it&#x2F;wiki&#x2F;Value_overflow_incident</a><p>Other transactions besides the one that created 184 billion BTC in that block was effectively “rolled back” on the working chain.
  • medellin2 hours ago
    Old man yells at cloud vibes every time a crypto post comes on HN.<p>No interesting discussions ever. Just axes being sharpened and people who dislike it taking the opportunity to gloat. I would characterize the pro crypto people but I don’t see any. Which is said because over the last 5 years I have found crypto, bitcoin, and stable coins to be extremely useful when helping family members in emerging markets.<p>But hey it’s all trash, the west doesn’t need it so let’s all dance on its grave.. i guess we will keep dancing for another 15 years.
    • ddorian432 hours ago
      There&#x27;s no interesting discussion to be had. That&#x27;s the simple reason you always miss.