Social engineering scam that nearly cost me all of my ETH
twitter.com
twitter.com
Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave when you lend out your assets for interest. The aETH is redeemable for the underlying asset.
The scammers created a fake NFT project associated with space and drones, and proceeded to give Thomas a free one, but asked that he stake it (or deposit it into a smart contract), to earn yield in the form of Armstrong ETH, a token they made up that had the same acronym as Aave's (aETH).
The catch was that when he went to stake his NFT, they asked for an approval for spending aETH from his wallet. Approvals such as this are normal when interacting with smart contracts, since the contract has to be "delegated" responsibility over the tokens in order to move them. However, what wasn't normal is that the approval was actually for Aave ETH.
If he had only looked at the front end of the scam site, it wasn't obvious what was going on. However, a quick glance at Etherscan revealed that he had signed off on an unlimited spend approval for Aave ETH.
Luckily, he had done so on a fresh wallet and not his main wallet that has $100M in aETH. When the scammers tried to get him to stake a second NFT from his main account, he got suspicious and discovered the truth.
This scam was specifically targeted at Thomas, and orchestrated over multiple weeks, for the specific assets in his primary wallet.
Couple takeaways:
- divide your assets across multiple wallets. New wallets are free. Don't put all your eggs in one basket.
- use a hardware wallet or an audited battle tested smart contract such as Gnosis Safe for storing significant sums of money.
- always verify your transactions
- avoid associating your public identity with your main wallet / vault address
- be careful, scammers are getting more creative and advanced in technique including standing up professional front end websites to give the appearance of legitimacy
To think that any of this would then be used to build a trustworthy ecosystem for non-developers to use, seems delusional to me. And building a VTOL taxi airline on top of it seems like it puts the cart 3 miles uphill from the horses.
Billion!
Since this is an allegation, we must presume innocence. However I still cannot imagine what planet would entrust 10 figures to her control. Witness her rap.
https://www.youtube.com/watch?v=7jlSHGAem6g
But I also realize reading this Twitter thread I do not understand the world of crypto at all.
stay away from all of it.
It's the same thing as reading the terms and conditions.
This is making it so there is no "undo", and no escrow agent. There's value, for those looking to take advantage of others.
Smart contracts on a general computing platform can enable anything, including the reversible payments and reliance on trusted third party delegates that you see in traditional banking, so as a consequence of this maximally expansive design space, I assume they will eventually lead to a financial system that offers a much better set of trade-offs than that of any other financial system.
I don’t understand at all how wheels move and what is that round thing near my chest and what do with it. Maybe it’s the fifth wheel. Or why fuel is needed, I can’t even find a mechanic who will look under the hood for me if I can’t. Also since my last car could use my ATM card and sign my cheques I had to be extra careful when turning on the ignition and had to see the gps log whether it drove to my bank when I was taking the afternoon nap.
There was no service warranty and guarantee with the car at all. I had to hire an entire division of technicians and engineers to use it. I think few lawyers and auditors as well.
In fact it felt I also needed a PhD in all things automobile to use my car.
Most importantly I can’t see in front of me at all. Front is opaque. I just drive hoping I don’t run someone over or something doesn’t run me over and my car.
Crypto is neither understandable nor useful.
No mention of the person or the Arrow company on the internet previous to this episode seems to exist. Other than looking at the chain records, how should we believe that any of these stories are true?
- People don't read what's in front of them.
I've seen this emerge in a vast array of fields. No matter how much we highlight specific details, for all our efforts in red-flagging irreversible actions, folks will often blitz past a confirmation dialog, nag screen, or notification message, without internalising the details or the risks. For those in financial technology, as in this specific example, irreversible actions also extend the attack surface for fraud.
Even the brightest minds can be lazy (some might even say it's a feature, not a bug) and one should never rely upon the opposite. We consequently face a design choice, for all irreversible (or hard-to-reverse) actions, the most common options being:
a) allow a grace period;
b) redesign, if possible, to make it user-reversible;
c) build a forcing function for diligence[1]; or
d) expect support tickets about that feature.
The default is (d), and the helpdesk won't thank us, since the workload generally scales linearly with growth at a high opportunity cost.
OTH I'm pretty sure that if the mark had been using such systems years ago, he wouldn't have $100m+ worth of ETH now ; )
Beware the survivorship bias: https://xkcd.com/1827/
We had multiple threads about base rate error on HN just yesterday!
Most financial activity happens in fiat, and so of course it stands to reason that most fraud is also done in fiat. The real question is whether the legitimate-to-fraudulent ratio is higher in cryptocurrencies than in fiat.
[1]:https://www.lesswrong.com/s/XsMTxdQ6fprAQMoKi/p/DSzpr8Y9299j...
Also here in Belgium, plenty of people are getting scammed by wire transfer, and no way to get their money back.
I think you have overly optimistic view on banks or the court system giving your money back.
If somehow you get through an in-person meeting with a bank branch manager to unwittingly wire millions of dollars, and the topic of how much money you're wiring and the exact purpose of wiring such a high amount isn't brought up, and you somehow still accidentally wire millions of dollars away without anyone ever bringing up the amount and purpose of the transaction, then I'm sure you'll still be able to recover that money back because banks are required to actually validate transactions of that size with KYC, AML, etc. laws. Only cryptocurrencies allow one the ability transmit this amount of money in seconds.
Isn't that only for cash transfers?
> which would likely involve a mandatory in-person meeting with the bank customer
At least at Chase and Fidelity, wires can be done over the phone with no limit.
> to verify their credentials and purpose
I've never seen a banker really help to verify wire instructions, as in contacting the intended recipient. Normally they just ask the sender if they've verified the instructions, if they understand that the wire is irreversible, etc.
Of course when it gets to the bank's wire department, they make some attempt to block suspicious wires. But they're guessing based on limited info, as they don't typically contact the sender or recipient.
> I'm sure you'll still be able to recover that money back because banks are required to actually validate transactions of that size with KYC, AML, etc. laws
From what I've heard, fraudsters will (indirectly) transfer funds to e.g. a Nigerian bank and cash out there. It doesn't always succeed, but it does sometimes, or wire fraud wouldn't exist.
I could find literally thousands of other stories like this in a minute scraping the web.
The fact is wires can also be irreversible and you cannot use the court system as a blunt instrument outside your jurisdiction. The value transmission medium isn’t the problem here.
No, it isn't. It's a reminder that we have all of this financial structure for a reason. The person you're responding to didn't make any light of the potential victim or call them a degenerate.
In traditional finance, you (Joe Shmoe) can't just wire someone ~100M USD, regardless of jurisdiction. There are controls, most of which have been written in blood or tears. Cryptocurrencies will also grow those controls, and we will all rightly question its value when it inevitably does.
Try getting your money back when getting scammed via venmo or PayPal - rarely any better, and if you’re selling you’re more likely to get scammed with those services than crypto.
In nearly all cases, no separate restitution was required: the processor or my bank was able to reverse or halt the ACH transaction before the money settled. In the handful of cases where settlement had already happened, they were able to countermand the transaction.
I'm a reasonably technical dude (senior data engineer at GAMMA/FAANG/whatever we're deciding to use nowadays), yet I don't have a damn clue what this means. And that's not an indictment of your communication. How on earth could I expect my wife, my brother, my parents, my kids, any of my friends, etc., to understand this?
On the other hand, all these people understand the concepts of bank accounts, credit cards, fiat currency, etc.
I'm open to learning more and having my views changed, but I'm so far convinced that there's absolutely nothing about crypto that is a simple, reliable, demonstrably real solution to a problem that isn't already handled by our current financial instruments.
Ideally wallets would have better UX where concepts like this could be handled safely and in an accessible manner. I think crypto isn't really ready for general consumption yet.
You can't ever expose that level to end users without it being an endless fraud source for people.
I’m interested to know whether the con artists could have realistically nabbed $100M, or if there was effectively never any chance of that due to other precautions. I would hope it’s the latter, but crypto’s strangeness stopped surprising me.
Fabulous comment, by the way. Easily one of the top ten in the last month. Thank you for the breakdown.
He could have approved a malicious contract to drain the lot.
But.. why? Isn’t that a remarkably bad idea?
Or is there some crypto advantage to keeping every last coin in the same basket? Other than it being a flex.
It’s a giant flex.
no address reuse is almost impossible as the wallets make it very hard as well
people don't really seem to know that Metamask gives you unlimited addresses, fwiw it is expensive to do approvals in each address
https://zapper.fi/account/0xb1e9d641249a2033c37cf1c241a01e71...
But I'm not worth $100m so I guess the joke's on me.
Hell, given my distaste for crypto, if I were more unethical I may even attempt such scams, but I’d balance it out by donating the stolen money to environmental initiatives to combat global warming (after giving myself some fair compensation, I don’t have the skills to get away with hiding $100+ million).
Unless you flex with your $100M in aave on your main with an ENS name, how will your victims know you are rich and worthy?
It seems like this is becoming the minimum standard for scam operations. For example, there is currently a BTC phishing scam going around that tries to convince the user they've accidentally received an email meant for someone else, which just happens to include a link to a million dollars worth of BTC. The website looks legitimate, albeit amateurish, to the point that it could even be convincing to another web developer. The rest of it is much like the OP's scam.
It starts with an email from the hacked account of a real bank manager in an Italian town, and is addressed to a real self-proclaimed stock market "guru" from the UK, now living in the US. The email states that 19 BTC has been deposited into an account that was created for them on a site called Coinlux, and they provide the username and password for the account. The Coinlux name was even used by an actual company at one point, so searching for any of the names or details surrounding the scam generates very real and convincing results.
Upon visiting the page, you're presented with a moderately professional-ish looking site that asks which fiat currency you want to use and lets you login. You're then prompted to enter a phone number to "secure the account" which, surprisingly, initiates an actual phone call from a number in the UK using a Twilio-like service. After confirming the verification number, you're allowed to view the account, which has some realistic dummy transactions in the history and other features that make the site somewhat believable (it even has a fake chat system and working account recovery).
After initiating a withdrawal of any amount, it provides a warning that you should make a small test transaction first (of 0.0001/$4), to ensure that you're sending to the correct BTC address -- after all, you wouldn't want to send 19 BTC to the wrong place and lose it all. It takes much longer than a normal transaction (likely because the scammers are manually initiating them), but it does eventually go through, and they've now succeeded in convincing the user that there is real BTC in the account and you can actually withdraw it.
However, if you try to make a larger withdrawal (or a second one at all), you're now presented with an error stating that you're not withdrawing enough, because of a "minimum withdrawal amount" defined when the account was created. This minimum amount happens to be 19.01 BTC, or 0.01 more than is in the actual account currently. So you've successfully withdrawn ~$4, but you have to deposit ~$400 if you want to access the entire 19 BTC.
As if it weren't obvious enough at this point, checking the address[1] which sent the 0.0001 makes the entire scam plain as day. This means that anyone with any amount of tech knowledge is probably not susceptible to the scam, though I do think that certain personality types could get caught up in the excitement of potentially "stealing" a million dollars. On the other side, non-techies will likely fall for this in droves, and the transaction history on that address does show there have already been successful victims -- though this particular person's scam has been massively unsuccessful so far, and they may actually be in the red overall.
[1] https://www.blockchain.com/btc/address/bc1qt80xra3r2df8gvzr0...
This shit isn't ready for the mainstream, and some of these architectural decisions are indicative of engineers who are in over their heads (but that's almost all code nowadays, even mine).
They build a mechanism that enables me, at the click of a button, to give away control of my fortune, and they designed the system so that anyone can design whatever interface they like to get you to sign any transaction they like. It's laughable. I'm in disbelief. And this is web3? No thanks, I think I'll stick with bitcoin or whatever, keep it simple. At least I can tell what a bitcoin transaction does without having to learn a programming language.
Well said. This goes hand-in-hand with the victim blaming that goes on in cryptocurrency circles. Any time a story like this appears, defenders come out of the woodwork to insist that it's the victim's fault for doing something or not doing something else. Even the linked Twitter thread is full of replies from people suggesting that the author was "asking for it".
Crypto seems to appeal to people who like to think that they are smarter than the average person and therefore will succeed by self-managing their finances right down to the private keys. Adding smart contracts to the mix basically opens up a can of worms that makes it unrealistic to actually control every detail of your money unless you strictly limit each contract to a separate wallet and only transfer funds into that wallet before activating the contract. That's honestly a good strategy if you're sitting on $100mm+ in cryptocurrency and the transaction fees are negligible (as was the case with the Twitter user). However, when transaction fees are $10/each or more, the average crypto user isn't actually doing anything of the sort. They're clicking the buttons and hoping for the best.
I've been calling them Dunning Krugerrands for this reason, and I suggest others do as well.
1) Spend more tokens than the amount you approved. 2) Spend any other tokens besides the specific type that you approved. (E.g. can’t steal your NFT or USDC) 3) Spend tokens at any other wallet address even if you own those other addresses (and creating a new address for a specific purpose is trivially easy)
In addition the only approve() technology is already being replaced with the modern EIP-2612 standard. (USDC already implements it.) In this workflow instead of pre-approving a contract, you sign a specific transaction-specific message. With EIP-2612 you know exactly how much you’re spending on each transaction and there’s zero after the fact risk.
I'm glad the standard for approval of control of wallets is being deprecated for one with more granularity and security, and I hope it solves this problem.
But that is how it works. The idea that I have a wallet as an extension in my web browser, and people can deliver me any transaction they like, with a "yes" button decorated however they like in the form of a web app, it absolutely does mean that I need to know how to read solidity to be safe and that I must audit every transaction I'm interested in signing. And an engineer would take that for granted, but if that's the standard UX, again, this isn't ready for grandma, not even close.
What ethereum should've done was be a little more slow moving with adding features and maintain mist so that a standard UI feature set could be expected by users.
I have seen contracts approve your entire supply though without mentioning it. That would allow the contract to come back at any time, with no user action, to take more coins out.
Just be wary of "Approving" contracts before using them on DeFi apps. That first approval confirmation is the most important as you're basically handing them that much coin and trusting them to give it all back.
Also this guy seems rather green in term of internet scams,
> Scammers are getting smarter. Before now, the best scam I've really encountered is basically "hi this is tech support please share your private key so we can help"
No, for the same reason you don't check the code on every website you visit, if you want to be even more secure then just stick to blue chips like aave, curve, etc you can see how much is sitting in popular defi contracts here: https://www.defipulse.com/
You also don't give an ethereum contract full access to your wallet, you need to approve access to however much you want the contract to have access first then you get a second prompt to allow the contract to run.
You're talking like one accidental misclick and all your money is gone.
If you're super duper paranoid you might want to look at something like argent wallet (https://www.argent.xyz/) which lets you do common trades, defi, staking etc from within the app so you don't have to worry about random contracts and there's no seed phrase so no need to worry about that either.
This went on way longer than i expected
This is literally happening right now all over the place. Just go to any reddit cryptocurrency sub and do a search for "free token scam." People are finding free tokens in their wallets, trying to spend them and having their wallets emptied.
I don't check code on every website I visit because websites can't just empty my life savings with no recourse.
Ignorance is unbecoming.
At least Chrome tracks malicious websites.
By comparison, there seem to be no checks in place to prevent writing an ethereym contract that drains a victim’s wallet.
Who said it needed to be a real bank?
> At least Chrome tracks malicious websites.
That's not TCP/IP, the chrome equivalent would be on Trustwallet, argent, metamask etc to implement.
This isn't Ethereum's job.
It's an L2's job. Whichever ones you choose to engage with. But, they'll all be interoperable.
The thing that struck me about it is the scam didn't work for a few reasons:
1. He typically had a practice of not using his main wallet for things like this.
2. He got wary and actually read the smart contracts.
This is a level of technical competence required that's going to mean most people have to offload this to a trusted intermediary. And then what's the point of all the decentralization ideology? Because we just re-invented banks.
There's nothing wrong with centralized services built on a decentralized network. Take a look at the web. Sure you can use a centralized service like facebook to make a facebook page, but if you want you can host your own website.
It is a systemic failure that most users must "fail over" to a centralized service to publish on the web.
The conceptual improvement enabled by blockchain is that the data layer is a neutral plane and this theoretically gives users portability. But, to say that centralization is fine because it has happened on the web and that was also fine is rationalizing a bad thing as good actually.
sending http and json over the internet is just as neutral of a technology as the blockchain. the reason people build centralized services on top of it is that we're collectively better off by specializing.
As a writer you're better off writing your content full-time than running a server, becoming a smart contract expert, casual coder and server administrator. no technology on earth is going to change that fact and it's why people buy their bitcoin on coinbase and their nfts on opensea.
Specialization doesn't come into it, although it is worth observing: your comment presupposes that in order to benefit from specialization, one must subject themself to exploitation.
I'm fact when discussing both privacy and censorship resistance I often cite cash as a target goal.
1000 USD bills exist but are very rare. 1000 euro note exists but I think that’s on the way out.
Your point that cash is censorship resistant is good, yes and we need to make sure it remains, however the physical limitations are defacto censorship.
€500 was the largest, but as of April 2019 is no longer being issued.
Technically, $500, $5000, and $10000 also exist in private collections. They were last printed in 1945, and stopped being issued in 1969. They're worth far more than their denomination to collectors, understandably.
Also, technically, $100k bills exist. They, however, were printed during the Great Depression and intended solely for transfers between federal reserve banks, and were never circulated. It's illegal to hold them privately, though there are some museums and things that have one.
Also I’m not sure that “censor” means what you think it means.
The real takeaway from this is that it's dangerous to break your moral compass and sense of reality to the point where you think helping out people who are pushing an obviously fraudulent business, is ok and normal.
And FWIW I'm not sure "fraudulent" is the right word. NFTs are not a fraud, you usually get what you pay for, a mediocre jpeg, and perhaps a really primitive game.
And to be fair, what are the odds his VTOL company will ever produce anything either?
And NFT part adds anything substantial and is not replaceable by regular transfer (either transfer of money or BTC-like)?
I have no issue believing that an imaginary consensus stored ledger in thousands of computers all secured by massive amounts of energy and limited to 21M units over 100 years might be valuable.
The ability for people to copy this software idea? Not valuable. The ability for people to issue new tokens on existing chains? Not valuable. The ability for people to post and sell jpegs, Not valuable.
Only original ideas are scarce. It’s the first step vs the n-th step.
Discussion on Reddit's r/metaverse [1]
[1] https://www.reddit.com/r/metaverse/comments/sr0sqz/what_meta...
If you don't know much about NFTs but think they're kinda scammy, maybe you shouldn't default to "support / lend your reputation to them."
I guess you can argue that get-rick-quick does not necessarily imply scam, but it certainly reflects poorly on a person to ignore their doubts because the source of the doubts is useful. Its not a unique problem to NFTs, its a similar problem that a founder might face when, say, entertaining an acquisition by Meta.
at 1:22:50 Smart contracts are just code, they’re software, there’s no reason they can’t be viruses or worms, the primary limitation is processing power. But, also, it’s a virus that someone can drop directly into your bankless bank account and just wait for you to activate it. And, yeah, that’s right, there’s no offer/confirmation step in sending tokens back and forth, someone who knows your wallet can just drop stuff right into it, so, like, pin that somewhere in your brain.
Line Goes Up – The Problem With NFTs
While it's true that NFTs can be sent without permission and can contain code, users normally invoke contracts via (hopefully trusted) dapp websites, such as app.uniswap.org. Invoking code from an NFT I found in my wallet is possible, but not part of any normal/legitimate workflow that I'm aware of.
It looks like the message in this case would have given the attacker permission to transfer the victim's aWETH, which represents ETH that has been deposited into an Aave lending pool. These transfer permissions are something all ERC-20 tokens support.
Typically users will only sign messages sent from trusted websites, just as they would only install software from trusted sources. Or they can sign a questionable message from a separate wallet which doesn't hold much value, as the victim did here.
Granted, this isn't a great situation. It can be hard to know which websites to trust, and even trusted websites can be hacked and then send malicious messages to unsuspecting users.
[1] Think of these as being similar to Word or Excel macros embedded in a document... nothing bad ever happened with them, did it? ;-)
There's nothing broken here. A smart contract is just a piece of code that moves money. You better be sure about what it's doing before you allow it to run. There's blue chip smart contracts that are proven and thoroughly audited, but anything else you need to read the code. Same as reading a contract before you sign it.
I'm still not convinced that Ethereum isn't just a strange RPG that people who don't really want to play are accidentally getting involved in.
We had illegal p2p sharing where you could download a virus from bad people and then Jobs came along and made iTunes which set the standard for streaming. I am sure someone will come along in the crypto space and make crypto easy for the rest of us.
People wanted easy access to music, itunes provided that service.
Right now with the world of crypto is confusing to the average guy, so hopefully in the future someone will create a good UX and the underlying to protocol for instant decentralised payments.
So... Napster and LimeWire?
You can't break cryptocurrency's weakness for this kind of adoption without dropping decentralization. Same conclusion that iTunes came to. People wanted downloadable music, not a specific implementation detail about how that music is delivered.
I wouldn't touch it with a ten foot pole. I just don't see any sense or reason in the concept.
It's mighty arrogant from crypto enthusiasts to assume that everybody will jump on it as soon it just can be made mainstream and "safe".
Thanks, but no thanks
Scammers ripping off scammers.
Why would you waste time with open source aircrafts. Aircrafts are a regulated thing. Nobody wants to fly in your science project. Put some of that 123 million into starting an actual company. DAOs are bullshit.
Yeah, start an actual company so you can raise billions with no profits and then IPO and dump on retail traders
If you legitimately wanted to develop an aircraft taxi service, you do not need to involve crypto in any way. Even if you wanted to accept it for payments it's an auxiliary component that merely accounts for it and converts to fiat at some point.
The DAO or whatever crypto bullshit is intertwined with it is absolutely a scam.
I don’t think this is legit at all.
I don't necessarily think the author is a scammer, but the whole project is the equivalent of "I'm going to launch a rocket to the moon" and then the first thing you do is open a nice website and launch a new token.
But DAO's do look attractive to me fyi. I wish I could do something similar in regular "fintech" ( and with c#)
The most reasonable conclusion is that the hacker was sent from the future to try to avert the creation of DAO-controlled flying cryptodrones.
It's just the Trust Problem all over again. Decentralized reliance on automatic software still requires trust that the authors of the software won't scam you. It all comes down to trust. And I trust banks, mostly. Who in their right mind trusts contracts someone sends you on Discord? And yet...
Exactly. That's where the gullibility is really visible... This is basically a steroid version of "I am Nigerian royalty and I need you to give me money" emails. Your first instinct should always be skepticism.
No one.
> It's just the Trust Problem all over again. Decentralized reliance on automatic software still requires trust that the authors of the software won't scam you. It all comes down to trust.
It does, but you get to decide who you trust rather than being forced to trust one of a small number of large institutions. If you want, you can delegate your trust to a third party who will be responsible for vetting anything you interact with.
You can also choose to trust yourself or other members of your community.
This person shouldn’t trust themselves since they are too willing to go along with people who say positive things about them.
And if you trust the wrong people? Per the linked twitter thread, the author trusted the scammers! They only avoided the scam because they were competent to read the contract code for themselves. Is that the standard you want applied to all transactions? Does that seem likely to lead to good outcomes?
I admit that the Approval UX for wallets and tokens needs to be improved. Unlimited spend approvals should always be flagged in the UX. And approvals should be atomic (single transaction only, with a clearly listed cap, by default). There are some EIP proposals addressing this, but they will be a ways off from standardization.
The protest is illegally blocking much of downtown Ottawa, as a result GoFundMe decided to refund the donors. That's far from a "rug"
Worth noting, though, that for all the fancy footwork the point of failure for the scam is him being willing to work with his main wallet rather than a one-off, and when he showed hesitation, they got too impatient. Good security practices were still the answer.
This seems to be the common factor among scams, cons, and social engineering strategies. Rushing people will have them bypass protocol, training, and security practices. It's a universal "hack" for our brains; we do things we otherwise wouldn't when rushed. Security practices are like a rituals, standards of behavior that we just don't have time for right now.
"The funds are only available for the next hour"; "You will be prosecuted if you don't do X"; "Per the CFO, we need to spend these funds before end of day."
Great story though. I never realized these smart contracts could be so obtuse and malicious. That needs to be fixed.
It's still pretty impressive how competently these scammers were able to discuss and deliver the VTOL work, the Space Falcon game, and entrepreneurial strategy.
While NFTs probably have some useful purpose that will emerge eventually, for now you should consider any proposal or offer that involves the term 'NFT' as having about the same value as any offer involving the term 'Nigerian prince'.
Certainly not a great look to have >$100 million in an asset sitting in a single account of any form, though.
Just one example, but this entire thread is Greek to me. What the hell is “staking an NFT”? I am feeling so left behind by this crypto nonsense. Is this what getting old is like? (I’m not yet old)
My really basic understanding after reading very slowly is he got some crypto asset from scammer, and he needed to approve lending it out to get some sort of crypto interest on it. But approving the "lending X out" action apparently looks exactly like the same as the "give Y away" action if you don't look closely at the contract.
Maybe it's just ignorance, but the whole system seems like a mess to me.
As far as I understand, it's just a synonym for "lending" here. They even use the word "leasing" for the people on the other side.
Whether that’s cryptocurrency or a sandwich.
You’re probably right though. But if you ever find yourself near Lake St Louis, MO, feel free to raid our fridge.
They suspect you wouldn't invite them again if all they did was raid your fridge, and not even say so much as a "hi".
Do you trust your neighbour with your spare key?
Do you trust your doctor with your medical history?
Do you trust your pizza delivery guy to deliver you pizza's that aren't poisoned?
Being skeptical is sometimes a good idea, like when it comes to "online research" or "alternative medicine". But having zero trust in even the most basic human interactions sounds like hell.
I don’t trust most Doctors either, and you probably can’t trust any medicinal organization with keeping records confidential, plenty of examples of breach of that trust.
I think you are not skeptical enough.
Social engineering is so much easier when you engage in faceless, voiceless communication. This could've been shut down so much more easily if they put a real human being to match the messages. When things actually matter, I need more than just a Discord avatar and a handle to identify someone.
If I'm John Doe and I made some merge requests to your open source project for a couple of weeks, is that alone really enough to potentially meet me in some city far from yours? That's essentially what the author was prepared to do.
OTOH it'll probably be harder for non-native English speakers to pull off a phone/video call considering that a lot of amateur scammers have telltale bad grammar even over text
This kind of scam just wouldn't work on BTC. You're passing tokens around. At fanciest you're time-locking wallets or using M of N signatures. You're not like, installing arbitrary code in your bank account.
I find ETH very technically interesting but it feels like it's full of sentient foot-guns.
Cant keep your assets? Someone else who can code can!
Looking forward to the technocrat plutocracy
I’m being facetious as I think there will continue to be a balance and cat / mouse game.
If I had to read the source code of all my wire transfers, I'd probably just barter my services for some milk and bread, it definitely seems smarter.
That's probably more secure than crypto, where click of a button can siphon it all away. At least with physical money you have to be able to carry it, and physically present to steal.
I'm sure there are strategies like using multiple wallets etc, but overall it will never be mainstream if you put the onus of security on the individual. Literally just typo-ing an address can disappear all of your money.
Second scam is the wrong word. A confidence scam originally mean the mark had to bring a suitcase of cash to give confidence to the scammers that he had the means to join their get-rich scheme - and of course he would walk away with a suitcase of old newspapers.
But this is almost a new kind of crime - he did not present or move his money, he did not give away any keys. it is the very mechanism of money transmission that is the issue.
SWIFT is rarely seen as part of crimes - but crypto is pointing towards a new world. Imagine "permissioned blockchains" ie Bank Of England coins, this would still be a real viable scam. Proving you did not mean for people to take your 100M and rapidly move it would be a slow process. Stop orders would be a common place activity, potentially holding up long chains of transactions.
Even without permission-less crypto the move to a digital native currency is a long process
By virtue of converting the ETH to AAVE wrapped ETH, they're earning interest by loaning out the underlying ETH. Who is taking out loans and paying interest for ETH I have no idea.
Plus, even without the AAVE wETH, they expect ETHs value to accrue faster than any other asset, so there's no cost to letting the money just sit, as opposed to your USD in savings depreciating over time.
Just two lines... Is the idea that tokenToBeApproved.allowance() can do bad things?
Code: https://twitter.com/thomasg_eth/status/1492663290715152384/p...
Tokentobeapproved is a variable declared in the contract. It will be pointing at the aWETH contract, which is the claim token for ETH on aave, a money market.
I'd have diversified. Some cash, some ETF, some property. A lot of tax, now or in the future. I wouldn't complain about the tax, even after there's enough for a lifetime. (And yes I know both property and ETF can decline in value, but here's the thing: when you see their book value it's a damn sight more real)
Remember, unless I am very mistaken he didn't put $80m of real money in, to secure an amazing 20% ROI which out in your real world would be normally exciting. So the net effect of fees, gas, AML, tax even taking 50% makes him as rich as croesus compared to most people for very low initial input.
Do we know what real world $ went in to bootstrap?
(I know this story is mostly about the social engineering, which is of course the real problem)
God I hate twitter threads, especially 32 tweets long!
Tbh I would feel safer having 10k in cash (at home at least) than in crypto. At least the attack vectors (fire, burglary) are known and tangible.
Imagine founding a startup, working your ass off living off ramen for a few years, every day worrying that it all might be for naught, and then through a combination of skill, determination and luck you do make it and your startup is worth a few millions... and then suddenly you make a small mistake and lose all your shares!
This is how crypto feels to me.
Maybe I am just not made for crypto.
Since NFT's are subject to heavy criticism of their existence, a lot of people are developing extra things you actually can do with them. The market is interested in that being done right, so its interesting to be a part of projects that are trying. This extra thing required Thomas sending the NFT to another service they developed. Smart contracts in Ethereum Virtual Machine environments (EVMs) have to be primed to recognize asset. So there is something called an Approval. When Thomas interacted with this contract it did the approval for the NFT, and also an approval for aWETH a token associated with that project.
aWETH is the ticker symbol for a token that project created called Armstrong ETH. The namespace for ticker symbols has many collisions as there are many tokens. So people aren't too worried about that, a token's ID is its contract address which does not have collisions.
In this case, this was the actual phishing attempt.
Their project did indeed use a token called Armstrong ETH, but their approval was for aWETH which is Aave Eth, an asset collateralized by liquid valuable actual Ether. It is also redeemable for actual Ether.
So if Thomas approved the use of their project from his main account, the hacker would have been able to use another function written in their smart contract that leveraged the approval of aWETH (the Aave Eth) to take it all away from Thomas. He has $100m of that.
Very close one for him.
To be clear, the “thing” in this instance is NFT staking: a ponzi upon a ponzi where you buy a NFT and then lend it to a platform, which pays you fees. Platforms can advertise ridiculous yields (200% APY) because deposits go right out the door again as fees to people higher up in the pyramid.
Someone comes to you and says "I'll give you X Euro if you let me hold onto your Y Dollars until you give me X Euro back."
You think, well Euro are useful, maybe you need Euro specifically to invest in an European business. So you agree.
But when you review the contract presented it just says you give Y Dollars, so you go "wtf?" and refuse to sign.
Apparently, some people are dumb enough to hand over their cash without reading the contract, and an entire industry exists to fool people into doing so.
If he approved their contract to be allowed to control his aWETH they'd take it all.
Imagine if every person you interact with could "be their own bank", and define the logic between your transactions. It's fully transparent, so you can audit it as much as you want to - but still, that's the amount of headache you'd have to deal with, to fully trust the other part.
There are lots of upsides to this, but there's no shame in saying: No, I'd rather not. I'll keep trusting the trust-based system I've been using since forever.
Also it seems strange to hold most of it in aETH, wouldn't you want to diversify a bit?
I don't understand why a startup working on aircraft design is linked to crypto at all. If you have $100M in ETH, the first thing to do is to convert it to USD and put it in a bank, preferably a large one. Then use the money to run your startup. Why would you keep your money in a crypto wallet? Why would you model your startup as a DAO?
Not really, it seems like the usual being extra flattering to earn favours (or worse). The first two messages would have raised several red flags with me.
> He's currently working at Ubisoft and offers to help with 3D design and animation
Like if I worked for Ubisoft I'd have time to do 3D design for free for some other company.
Why is that so hard to believe? It's like suggesting that no professional software engineer would ever contribute code for free into an open source project in their free time. My basic assumption if somebody send a patch to an open source project is not that I'm being social engineered -- it is that they're either using the software or interested in the domain.
No doubt this is often genuine goodwill, but it's also an effective technique for recruitment (it's longstanding practice for evangelical religions and MLMs), and it creates a situation where a lot of self-interested people looking to get rich quick are mingling in an environment where it's perfectly common to make generous offers with no expectation of return.
It's like going to a tech meetup where there are a lot of people working on startups, and who might buy a few rounds at the bar afterwards in exchange for maybe attracting an interested investor or cofounder, but where there's a chance that drinking a seemingly normal beer might give them access to your bank account.
I love that he wasted 2 weeks of these scumbags and exposed them. I hope they can trace their email address and nab the real people.
This part wasn't a guess, it's publicly available information known from the outset
-invite Thomas to a private Airbus VTOL demo day in another city
-buy him first class ticket
-offer to send a limo to the airport
-send a limo with a big guy holding a wrench
-instant $100mil profit
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it. Note this one:
"Avoid [...] generic tangents."
Yes, Coinbase, Binance and other big exchanges offer OTC trading where you can trade pretty large amounts without impacting the market at large.
At $100M you would want to split trade across exchanges and probably some defi too, but yeah, you could. Eth has about $10M/-2% on major exchanges.
Not that you would need to convert to fiat. If you ran your own island, just pay for goods and labor in Bitcoin or Ether directly.
the world is not anymore the way it used to be, mm mm NO NO No! Bitconeeeeeeeeeeeeeeeect wooo bitconnect! We are coming and we are coming in waves. We are starting and to actually go all over the world. We all built the entire world.
Me? Im just out there fiat mining, stacking sats…
I'm calling them out for that -- perhaps in a way that's too terse, but at least I'm not completely derailing the conversation like they're doing. But thank you for prompting a longer response from me.
At least there are uses for ETH
In case it helps: the first two comments you posted with this account (a couple weeks ago) were much more substantive and much more along the lines of what we're looking for.