The FBI has tied the recent Axie Infinity Ronin sidechain hack to North Korea
thismorningonchain.com
thismorningonchain.com
I wonder if US lawmakers would step in to try to shut down these systems. It may be politically very difficult since there is so much money riding on crypto now, and many US lawmakers reflexively support crypto in order to appear pro innovation.
If sanctions cannot be effectively enforced without repressing decentralized platforms, then the US should look to other tools of statecraft to combat problematic states like North Korea.
That seems rather idealistic, let alone any likelihood of it leading to democratic values taking root there.
I'm saying that censorship resistant finance reduces the impact of repressive laws around the world. It helps individuals circumvent laws like those instituted in places like Venezuela and China, that give the state enormous power over private citizens by controlling how they move money.
Stopping North Korea from using cryptocurrency would require very repressive laws to shut down entire global cryptocurrency networks, which in and of itself would make for a less free world because of the extremely heavy-handed enforcement actions that such a campaign would require. On top of this, the end result of such a campaign were it to succeed - of these censorship resistant networks not existing - would further undermine the goal of creating more free societies, for reasons mentioned above.
What do you suggest? North Korea is effectively a rogue state, only having relations with China and sort of Iran. What other statecraft tools do you think the US has its disposal?
https://risk.lexisnexis.com/insights-resources/research/2019...
The impact on the developing world is profound:
https://finance.yahoo.com/news/money-reimagined-starve-ugly-...
Other ways to counter the threat posed by the North Korean state include aiding and encouraging South Korea and Japan in building up their armed forces, as a deterrent to any North Korean attack, and expanding deployments of missile defense systems while increasing funding for the development of more advanced missile defense systems.
Yet another approach could be to apply pressure on North Korea's allies, like Iran and China, to reduce military cooperation with the state, as long as it remains outside of the Non-Proliferation Treaty.
That ability continues until you can convince most nations to abandon their currencies and turn all of that economic self-determination and political power over to independent crypto systems they have no control over. It ain't gonna happen.
It's unecessary to shut down because fiat off-ramps are the Achilles heal. Already there are wallet address banlist [1]; and woe to any instituion who processes transactions which originate from those addresses.
[1] https://home.treasury.gov/policy-issues/financial-sanctions/...
It also supplies a opposing fact to some forms of internal propaganda, especially when tied to a discrete event in the country's foreign policy.
With Russia sanctions are doing some damage right now, even if it hasn’t stopped the war. With North Korea we’ve blown our load and the main casualty is just a destitute population over there.
Actually no, much more could be done against North Korea. A total naval blockade, for example.
Isn't virtually all their trade land trade via China? Short of a land invasion to cut off that border, I don't see how any kind of a blockade makes much of a difference.
Besides, sanctions enforcement turns pretty active when you start prosecuting violators.
It discourages war because of the threat of being cut off.
If you don't actually carry the threat out, it stops being an effective threat.
Don't turn a scam into some political commentary
So a question remains of how the attacker got access to Sky Mavis systems?
> A security audit likely would have identified an inherent problem in the majority of the multisig keys being stored on a single server.
There was no security aduit? Can anyone more familiar with this project add context?
So, not only did they call an effectively centralized server a "blockchain", they also acted deceptively about the number of centralized custodians on that multisig, by pretending there were 9 entities when there was only one.
Most likely, the underlying code was audited as being secure when used by a larger group of independent validators. If there were 20, it would be very hard to compromise them all. The code that was broken was probably some other dumb utility on the server that got hit by a regular privilege escalation vulnerability or something.
They did say that they are expanding the amount of individual entities holding multisig keys, so they seem to realize this was a bad idea.