Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No monitoring whatsoever over $600M of funds stored in your system is crazy negligent.


Or malicious...similar to the DAO hack from 2017 suspected of being an inside job (with evidence pointing to the insider who lawyered up to refute it with code-is-law argument), somebody was accountable for security and they deemed it not worth it to secure it.

Axie Infinity was already struggling, and this happens a day or two away from scheduled distribution of rewards & update release.

Cui bono? Who could've known they were carrying funds in a hot wallet other than the people directly involved with the project? Unless there was a way to discover this from the outside?

Somebody at Axie Infinity could have been asking whether they want to get paid 0.025% of that hot wallet yearly or have it all up front, today. After all it isn't cash sitting at a bank they have to rob.


Agreed, the system was designed to say "oops, we lost all of your money, how could this have happened"


It isn't like monitoring would have done anything. Once the transaction goes out it is gone. The core problem here is the massive private-key bounty being created by a ton of organizations that don't have world-class security teams.


True, but you would think they’d notice $650,000,000 missing before a user reported an issue withdrawing $5,000 (edit - 5k ETH). It’s honestly so impossible to believe that I’d wager the real story is they knew and were actively trying to recover the funds.


just a poke: it was 5K Eth ($16,924,050), not 5K USD, but i agree with your wager.


God damn, 17 million stolen forever from 1 person and there is nothing they can do about it.


Even more shocking, is why someone would hand 17 million dollars worth of assets to a random company that has no security apparently.


Ah right you are. Misread the article.


But the attacker used 2 transactions. The first one should have been flagged immediately. Plus the servers themselves were compromised. Four of them. The attacker was able to take control of 4 different servers without even being noticed. This is just one massive secops fail.


Yeah, I'm just picturing a Graphana chart going from $625M to $0. And then admins sitting around like, OK, now what?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: