“Crypto drainer” template facilitates theft
blog.confiant.com
blog.confiant.com
It's not clear exactly what's going on here. The word "connect" by itself implies two modes: (1) present public keys; or (2) present private keys. But the loss of property suggests it's (2). If so, then the people falling for this are hopelessly incompetent.
Of course, this has been a problem from the start of Bitcoin. Users "buy" something they have no clue how to secure. They don't understand at all how public key cryptography works, or worse, they bring truly bad mental models from their experience with their online bank or Facebook. Then they get burned. Nothing new here.
It's for this reason that central bank digital currencies are one the the worst ideas ever to come out of central banks. The average person is in no position to even think about managing cryptographic material let alone securing life-changing amounts of money with it. Idiot-proofing CBDC will mean that the central bank just becomes an actual, central, bank. No crypto required. A real one where people actually keep their money. So long to private banks.
This article is about phishing in the context of cryptos.
Silent signing doesn't happen (unless there is some kind of bug in metamask). the user is always presented with the contract address and call data (the args to the contract call)
If you have the Metamask browser extension (or another compatible web3 extension) and press its browser button to enable it while on a webpage, then the webpage can see your wallet address and suggest transactions for you to make. When that happens, the browser extension then shows a window under its own control explaining the transaction and allows you to choose to sign or reject the transaction.
The webpage never sees anything about your wallet if you don't activate the extension on the page specifically, it never sees your private keys, and it can never silently sign a transaction from you.
Does any of that fall under "user experience" for you?
The similarities are that in both use cases the user is presented with a request to approve or deny.
* Phished Apple Pay transactions can be reversed. Crypto transactions can't be reversed.
* Actors who phish Apple Pay transactions will be banned. Crypto bad actors generally can't be banned.
If somebody sets up a phishing website in the US with intent to steal funds, they are equally as liable whether their target is a crypto wallet or Apple Pay.
https://www.coindesk.com/markets/2019/06/24/two-israeli-brot...
https://www.cnbc.com/2020/07/31/twitter-bitcoin-scam-masterm...
https://krebsonsecurity.com/2020/09/two-russians-charged-in-...
https://nationalcybersecuritynews.today/greek-student-arrest...
Worse, I learned to decode what they refer to talking like that and I still dont see a point: to the gibberrish or to the whole concept.
Which is to say... don't assume jargon is pointless.
https://mashable.com/article/multiple-slurp-juices-single-ap...
>'Multiple slurp juices on a single ape' meme perfectly captures the stupidity of NFT culture
>If I know anything to be true is this mixed-up world, it's that ape holders can absolutely use multiple slurp juices on a single ape. Any fool knows that. It's as simple as two plus two equals four. An ape holder can use multiple juices on a single ape; this is fact.
The technical jargon does make sense like any kind of niche technical jargon.
Is that simple enough for a senior FAANG engineer?
Where fraud typically happens is when a user thinks they're signing an innocuous transaction, when in fact they're signing a malicious one. This is generally a hard problem, but it's very clear from the wallet the address of the smart contract your transaction interacts with.
Only on the second case does the browser extension handle primitives like private keys and in no scenario do they get exposed to a site.
The more common crypto-thefts are phishing (user gives away their recovery phrase) or malware (scanning for on-device keys and recovery phrases).
> In our design users interact with a central transaction processor using digital wallets storing cryptographic keys. Funds are addressed to public keys and wallets create cryptographic signatures to authorize payments. The transaction processor, run by a trusted operator (such as the central bank), stores cryptographic hashes representing unspent central bank funds. Each hash commits to a public key and value. Wallets issue signed transactions which destroy the funds being spent and create an equivalent amount of new funds owned by the receiver. The transaction processor validates transactions and atomically and durably applies changes to the set of unspent funds. In this version of our work, there are no intermediaries, fees, or identities outside of public keys.
That doesn't sound like Venmo to me.
[1]: https://www.bostonfed.org/news-and-events/press-releases/202...
> there are no intermediaries
Except the transaction processor.
Which part doesn't sound like Venmo?
"Signed transactions" is essentially SSL/SPIF/I don't know the details but it's regular Internet security encryption and signatures.
The only difference from Venmo is that users get a proper PK instead of phone or email address id, and it's vertically integrated.
People rush to buy a new thing, and send their money to an unrelated thing that looks like the new thing.
1) When you "connect a wallet" what you are actually doing is signing a message from the site using your private key. They can verify it using your public key to prove you control that wallet (ie it is just a normal message signing process). This process involves your wallet (often via a browser extension) popping up a message giving you details of what you are signing and buttons to approve or reject.
Because lots of sites send a very unhelpful message that is just a big json token for people to sign, and because browser extensions are wonky leading to lots of requests to connect and reconnect and re-reconnect your wallet, people often get in the habit of not checking carefully what they are signing.
The fundamental UX problem arises because the flow for authorizing a transaction is exactly the same - you sign a transaction approval using your wallet.
Can you see the problem here? It's easy to accidentally approve a transaction which drains your assets when you think you're just approving a message to connect your wallet.
2) Secondly there is a classic phishing attack against the private key. If an attacker can pretend to be a legitimate site they can apparently sometimes persuade people to paste in their recovery phrase which is equivalent to their private key. If the attacker has the private key of course they don't need anyone else to approve the transactions which drain the wallet, they can do it themselves.
There's another attack vector I have heard about which I don't think is in the article but is more pernicious. I'm not 100% sure of all the details but it's sort of a variant of #1 with extra tabasco. It starts by sending someone a token with malicious code in some of its methods (say the 'transfer()' method which is used to send the token to another address). This code is set up to drain the wallet of the owner of the token.
So say the recipient of the token attempts to transfer the token to another wallet (or 'burn' it, which is just a transfer to a specific black hole address), they will be presented by their wallet with a normal-looking transfer approval method to authorize but unbeknownst to them (because they are approving untrusted code) they are actually authorizing the attacker to drain their wallet. The attacker can make it more likely a person will attempt to burn a token by either promising that burning will turn the token into something else (this is common in this world as a method of transforming things) or by making the content of the token really unpleasant so people want it out of their wallet (I think someone tried this with me - that is I got sent an unsolicited token with a pretty horrible animation that any sane person would want out of their wallet and it can't be burned because it is unverified code so there's no way of knowing whether the transfer method is trustworthy).
The same attack can be run using different methods and it will operate should the recipient try to list their new token on an exchange.
The remedy for this is that legitimate issuers can "verify" their code by publishing it and since the resulting bytecode checksum is the same as the checksum of the token people can be confident that they are seeing the real code. You would still need to actually check whether the code was doing anything bad to know whether it was safe to interact with such a token.
I assume the example from the author [of the blog post] must’ve been a deployment by someone without much experience with the javascript ecosystem or extremely lazy. Pretending this assumption is correct, what does it tell us? Is it a reflection of the environment’s lack of regulation (even industry/market led, like PCI) and a deluge of unsophisticated (ignorant) users/consumers?
We do see phishing pages like this increasingly popping up with obfuscation. I think at this time less than a third are obfuscated, but this is gradually increasing. The thing is, most of the folks running these sites are likely not very technical. They buy the template from a vendor and plug in the config settings and just focus on driving traffic to the site - this happens through Discord & Twitter spam.
The thing with fraudsters and threat actors that play in this space is that at the end of the day it's a business and they want maximum reward for minimal effort. I think right now there's not a very aggressive takedown feedback loop with these phishing sites, but we are working to accelerate this and as this happens the perpetrators WILL need to rely more on obfuscation to try and thwart on the fly static detection. My guess is that eventually most of the logic will be server-side and cloaked as has happened with many other categories of phishing and fraud (particularly malvertising campaigns). Sooner or later the more amateur scam operators in this space will likely get shaken out by this acceleration of the cat and mouse game and only highly technical operators will be left.
With regards to the sites that we see obfuscated today, we are still able to do accurate attribution, as we've been specializing in the detection and blocking malicious client-side code for some time now.
Thanks again for your comment.
For reference, this appears to be an example of that warning: https://github.com/MetaMask/metamask-extension/issues/11337
Transcript: "Signing this message can have dangerous side effects. Only sign messages from sites you fully trust with your entire account. This dangerous method will be removed in a future version."
Presumably part of the issue is that a legitimate "NFT mint" transaction might also carry the same warning.
There is a new method they have for signing strings that does not allow a transaction to be signed so its safer.
The crypto drainer seems to directly be sending the NFTs and assuming that the user cant understand the transaction and what its actually doing.
Hmm.. create a botnet to sell NFTs on Insta.
I see a lot of victim-blaming suggestions that it's the fault of the person who didn't set up a new crypto wallet for every interaction they might want to make and then transfer enough money into said wallet to cover unpredictable gas fees (while also paying gas fees to transfer the money) and then, presumably pay even more gas fees to transfer everything back out of the wallet if it turns out to not be a scam. It's incredible that crypto has reached a point where some people seem to think this is all totally reasonable and natural to expect the average user to know.
The app does not have the ability to sign transactions on your behalf without your explicit approval.
It's used by a lot of DeFi apps, often with an unlimited amount. It doesn't give control of the tokens to a website, but rather to a contract. It's fine if the contract is secure and immutable, but of course that's not always the case.
It is easy to create a site that asks you to provide your wallet private phrase. The DNS MyEtherWallet hack that I vaguely recall exploited this.
On the other hand, good crypto citizens will just use the web3 library that will request permissions on an ad-hoc basis from your wallet extension (such as MetaMask).
However even then you can scam someone using social engineering: Just tell them "how" to do XYZ. E.g. "To get your free mini-monkey NFT, just connect your wallet with your bored ape, and when the confirm box pops up from metamask just click OK".
The fiat equivalent of course is a site that asks you to log into paypal and send them $1000 - but that is way more obvious than the crypto equivalent, where you interact with a smart contract and it isn't necessary clear ahead of time what will happen. Especially as smart contracts might be used for, for example user registration. If the user registration endpoint asks for money then you could get scammed that way.
When a site initiates a transaction, you can see the address you're interacting with. You should then look up the address on etherscan to see if it has public code and a lot of transactions. Then you should search that address in google and see if the main site links to it. A lot of projects have a list of addresses in their github. You can also inspect the function code. Once you're comfortable, you should add it to your saved addresses on your wallet and next time you'll see the name of the address.
Also you can create a new throw away address, transfer just a little bit of coins to it and interact with the contract. If it does what you think it should do, then you can create a new account and do it again.
It's not perfect. It could be a proxy, so you're not guaranteed the contract you're interacting with.
There's no easy way to "see what a transaction does". You just need to do risk management.
Oh, that’s it? So simple.
How much money would you be spending on this scheme (in transaction fees)?
I wish wallets made it easier to create a burner throw away account or there were some trusted contracts that would create an account, do something and then transfer back to another account. I don't know if anything like that exists or even if the workflow is generalizable enough
https://www.savings.com.au/news/scamwatch-2021
Australians lost a record $323 million to scams in 2021
--
So glad they solved fraud prevention 'decades ago'.
But in the regular banking system we have decades of experience in how to mitigate the impacts of them e.g. account insurance, MFA for any new transfers or over a certain limit, auditing by independent regulators.
The tech community should be keenly aware of this because there are new apps, new languages, new libraries, new plugins, etc all the time, which solve a problem that was pretty much solved already.
You might counter that new things usually have to have some value proposition to gain a footing, like cheaper, faster, more reliable, etc. For one, that's not always true, but also crypto does have a value proposition like that. It's immutable, trustless, and can be anonymous. And it is even cheaper and faster than the regular banking system in some circumstances, depending on the sum being sent and where it goes.
(let's keep the discussions civil)
The only thing I can imagine you’re talking about is when some wannabe domestic terrorists rightfully had their funding declined.
Crypto seems like a convenient way to do this, and the more repressive governments get, the more of a use-case there'll be!
So it's safest to just avoid debit cards, unless you know that the issuer has their own legally-binding limits on cardholder liability.
If entered, the transaction happens on the Maestro et. al. network and you can’t do chargebacks.
If no PIN was entered, the transaction happens on Visa/MC systems and you can chargeback.
Your bank irrespective of whether it's a savings account, credit card etc will almost always insure you against fraud provided you didn't do anything reckless e.g. write your PIN on the card.
This is a well known fact in secure system design. Most people just click through dialogs. If you must get their attention you have to make the dialog huge and scary but then people will usually just turn back instead of reading. Scary dialogs make it seem like you should never say OK.
“Undo” is powerful in any app, not just because it can roll a change back with a single click, but because scary dialog boxes (“Really, really REALLY delete this file? It can not be recovered once deleted, so check this box saying you know what you’re doing before clicking OK”) don’t work for regular apps, either.
Always someone getting burned, but in this case it's the "idiots" for lack of better word. Don't try to make cryptocurrencies work like fiat, that's exactly the kind of problems they're trying to solve.
And let's say someone implements your solution, years later you will read how a bad actor did a chargeback for all the coins in those contracts and you will claim it was a retarded feature from the start.
You didn't even explore any of the options for different types of "undo" operations that could be possible in contracts. You seemed to simply assume recreating the exact same situation that exists in traditional finance and responded based on that.
There are several other ways of doing it that I can think of, all with their own pros and cons. There are even a couple that have already been applied in crypto that I can think of and I'm sure many that I'm not aware of.
And why would you assume I even meant "reimplement traditional chargebacks as they are today"? My recommendation: Hold off on forming strong opinions too early in the process of learning about something.
The internet has kind of conditioned all of us to be OK with passing around complex payment instruments without paying too much attention. If you're a hardcore believer in cryptocurrency as a political project, you almost certainly understand the difference and see the "code is law" dark forest as a feature, not a bug. But if you started buying crypto and NFTs because Matt Damon and Larry David told you to, then you're in for a world of hurt.
"A religion cannot fail, it can only be failed"; I admire your optimism, but I expect that the true believers will not question whether the premise of cryptocurrencies is wrong, but rather will twist themselves in knots to find new scapegoats as to why it doesn't work the way they expected.
This criticism of cryptocurrency would be analogous to criticizing the concept of fiat currency by pointing to the inflation of the deutsche mark as an example. The cryptocurrencies being discussed here are real cryptocurrencies, they are bloated and useless shitcoins. Any credible project would not have all the bloated crap that enables the "exploits" mentioned in the article in the first place.
If it's harder and riskier then the user isn't going to care if it's their fault or not.
Do you want a world where crypto is common and useful, or do you want it where it's the web equivalent of casinos, with some sharks making money off suckers but most people not taking it seriously as a "real" or useful business?
I can and I will. People know not to give out their credit card numbers to fishy businesses or install untrustworthy software on their computer. Why does that personal responsibility suddenly disappear when we talk about cryptocurrency?
>Do you want a world where crypto is common and useful, or do you want it where it's the web equivalent of casinos, with some sharks making money off suckers but most people not taking it seriously as a "real" or useful business?
The path to the world where crypto is a common and useful tool starts with these speculators and gamblers losing all their monopoly money and leaving. It's no surprise to me that the "scams" and "exploits" mentioned in the article are enabled by bloated "smart contract" cryptocurrencies like etherium that serve little real purpose.
I don't believe victims should be punished. I just don't think victims should be rewarded either. I do think that the perpetrators should be punished.
>Wouldn't it be more compassionate to recover their losses
It would be "compassionate", but it would also encourage people to make risky and stupid decisions. Tough love I suppose.
>Trust shouldn't be seen as a weakness. Trust powers all the best things humans can do. Trust should be rewarded, not punished.
There is a difference between knowledge, trust, and blind faith. Your inability to discriminate between the three is what allows you to mix these unrelated platitudes.
What you call tough love, I call inflicting trauma that makes everyone worse off. No one should ever risk being destitute. There's no societal benefit to risks with a downside of total loss.
And that's why I think your comment of blind faith was a non-sequitor. I'm not advocating for blind faith, I'm advocating for informed faith. I think we should have an informed assumption that the risk in a scam is on the part of the scammer. When something blows up, the scammer pays. Let's go ahead and reward people for blowing up scams from the inside.
In the case of crypto/investment fraud, you have to take into account that all investments and transactions bear a certain amount of risk and reward. It's not fair to expect the public to bail you out for risks that you knowingly accepted when they wouldn't get a slice of the reward. In the conventional financial system, the public sees a slice of that reward through taxation. The same is not true of cryptocurrency, so why use everyone else's tax dollars to regulate it?
The only reason authorities like the SEC exist is to reduce risk, thus increasing the amount that ordinary people can safely invest. It's not a matter of ethics, it's a matter of economics.
You should maybe run that past a tax attorney just to make sure. I'm in the US, where capital gains from cryptocurrency are taxed just like capital gains from stocks, but of course this may not be true in your jurisdiction.
> The only reason authorities like the SEC exist is to reduce risk, thus increasing the amount that ordinary people can safely invest. It's not a matter of ethics, it's a matter of economics.
I don't think that's correct, but if it is, yeesh! What a bleak hellscape we live in, where the only reason to add safety to anything is to prevent the plebs from getting too scared to spend money.
I take it from your responses that you're one of the "hardcore believers in the 'code is law' dark forest" mentioned in an earlier comment, so I guess we'll just have to agree to disagree.
Of course cryptocurrencies do not have such regulations. the purpose of cryptocurrency is to facilitate exchange with untrusted parties.
I mean, really. The security of the banking/credit system is not even based on public/private key cryptography. There is no notion of a separate spend address vs a sending address. Anyone with access to your (usually open source or easily findable) information can make a transaction on your behalf. Identity theft is a massive problem which is enabled by the current state of the industry.
I think it’s the nature of crypto that part of the benefit comes from the cost of it being up to the individual to maintain. Selling a product/service that consumes crypto or holds it easily might be the answer (like a bank is to usd), now the individual is giving up the keys though.
There’s a trade-off there that is very cool because it only exists because bitcoin adds the option of more reliably securing the money “all by yourself” rather than needing a bank due to physical limitations.
In that sense there are many crypto holders out there that may wish they had just kept it on Coinbase…
TLDR the cost of having it be serious to use crypto is well worth it for the power and value of crypto itself, it’s like the cost otherwise paid to run a bank, put into a different form, the average economy of carelessness
Is it worse than browsers+OSes allowing you to download and run a program? Or Github or npm or browser extensions? All 4 of those could steal all your crypto too if you install them.
The fact that gas fees even exist just boggles the mind.
Bank fees at least on paper pay for overhead of running the wire transfer system. Gas fees (to my uninitiated understanding) literally just pay for the excess waste that is Ethereum, by design.
Basically the fraud described is a twist on the classic "Musk giving away BTC" scam that's all over Youtube because Google is apparently unable to prevent it. You have to be fairly naive to fall for it in the first place. But ok, no victim-blaming. The way you can prevent it on smart contract platforms is simply holding the funds in a smart contract that allows users to set restrictions so that they couldn't take that expensive NFT even if the user mindlessly clicks on a fishing link, connects the wallet and approves the transaction without checking what it is. Same as having a withdrawal limit on your bank card. And you can also whitelist wallets, the contract then automatically blocks any transfers to untrusted wallets. If the user manually overrides this by getting his guardians to agree, there's no stopping them of course.
Ultimately you won't be able to protect everyone. A determined enough fool can also go to Western Union and mail money to the scammer. In the US they have those prepaid card scammers. Or they come to your home, telling you they're police and need to inspect your valuables. Yes, that's a real actual scam that exists in Europe.
You're making a great example of the victim-blaming I mentioned in my comment: That anyone who is surprised by their money disappearing clearly just didn't do all of the right research and use the right wallets and set all the right options to set the right limits and so on and so on.
Obviously there are right ways to navigate the crypto space and not get burned, but the issue is that the crypto community seems to think it's okay that everything is complicated and prone to new users making mistakes that people are routinely losing huge amounts of money due to not being 100% up to date on the right way to do everything.
> The way you can prevent it on smart contract platforms is simply holding the funds in a smart contract that allows users to set restrictions so that they couldn't take that expensive NFT even if the user mindlessly clicks on a fishing link, connects the wallet and approves the transaction without checking what it is.
Yep, sounds easy. To avoid losing everything you just have to set up a smart contract and then...
I can't believe this stuff passes for reasonable suggestions in the crypto world.
With Crypto, payments are irreversible, all transactions are transfers, all payees are equal (no merchants for payments and P2P for transfers) and it all combines together to be the perfect scammer heaven - you can scam people without any repercussions anonymously.
Of course people can use other wallets if they like to. These are open networks just like the internet itself. No one can stop folks from doing dumb stuff online, input their credit card information where they shouldn't, wire thousands of dollars to a "girl" overseas who "loves" them, visit shady sites with their outdated Internet Explorer on a WindowsXP machine... Why didn't Microsoft prevent this!?
Yes, so simple! Just put your coins into this website’s smart contract and you’ll be much more secure.
Btw yes, from a user perspective it actually is very simple and easy to use. It's a good wallet for beginners. Most who're more active and understand the tech have hardware wallets. You could combine the two solutions as well.
The regular non-tech savvy user doesn't necessarily have to understand the details. That's why people are working on such solutions in the first place. Someone experienced with blockchains would never connect their wallet to a random stranger's and approve draining their funds. However the massive hype around them has brought in a lot of new users.
Wallets have come a long way from people writing their private key on a piece of paper back in the early days. The above complaint is bizarre in this context, because what they described is the exact opposite of what's actually happened. Every reputable wallet team has worked hard on improving security over the past years using strategies like social recovery, multi sig, cold storage of keys, etc.
If they got someone to execute a malicious transaction, couldn’t the scammer just `curl etherscan.io/VICTIM`, get the restriction amount and go just under that? With normal banking, everything is closed so you can’t access that kind of information that easily, but since crypto is so open, isn’t this possible?
People think of history like it was wonderful, but it was full of cons and scams. Reputation matters, and people with reputations charge a premium for it.
Some of the best aspects of regulations is exactly to remove the reputation tax by mandating everyone follow the same practices as the trusted institution.
The real sad aspect is that the crypto-libertarians of today are repeating some of the exact same clear scams from the wildcatting era, and when it's brought up, it's just mocked because, honestly, who is going to read a book about 19th century finance when you can just watch the new star wars show instead.
Which usually points back to the companies/industries being regulated.
These corporations control us if we don't control them.
The idea that anti-intellectualism even exists is testament to this.
e.g. China/CCP (which isn't really communism, but definitely not democratic).
But you are right, a benevolent, enlightened dictatorship is probably the best form of government. Only two problems:
- finding a benevolent enlightened dictator
- keeping them benevolent and enlightened
For example, what's stopping a company in China lobbying a minister for regulations that harm their competitors? The Minister may not have been elected through democratic means, but regulatory capture can still occur.
What recommendations do you have?
https://www.investopedia.com/terms/w/wildcat-banking.asp
here's a whitepaper from the Atlanta Fed,
caution PDF:
https://maysweb.tamu.edu/sage/wp-content/uploads/sites/16/20...
Modern-day anti-intellectualism FTW! I know, I know, commenters will argue that this is mainly a laziness problem… But when has it ever been “cool” to read (in the sense of being socially incentivized broadly speaking)? To quote a modern day (retired) twitter poet: “Sad!”
With most blockchains, this is entirely not feasible. The irony is that many of the brokers will likely be swamped by regulation going forward exactly because people will be unhappy with the lack of these types of disclosures.
A wallet is not like a bank. It's like.. well, a wallet. If you hand a wallet full of cash to a thief, no banking regulation will protect you. The tradition digital equivalent is a Visa gift card or Western Union.
If that whole "Amazing Pandaverse" theme template appeals to your aesthetic sensibilities and primal urge to get rich quick and screw everyone else and the environment while wearing kewl sunglasses and dollar sign bitcoin logo bling jewelry, you're probably a huge narcissistic douchebag who actually deserves to get the fuck scammed out of you, not a poor innocent senior citizen living on a pension.
It kind of makes me nostalgic for the good old fashioned robot insurance scams targeting seniors, when you could actually feel sorry for the victims.
At any rate, they'll probably reskin these templates to feature Hummel figurines, then I can feel sorry for the victims again.
What an earth does that even mean? It's no wonder people keep messing this up. You need to spend half your life keeping up with the tech just to not get scammed.
This is the equivalent of being mad at banks because you don't understand what a bank routing number is.
>It's no wonder people keep messing this up.
The type of user that doesn't understand this should not even be using cryptocurrency in the first place.
Then why did all those cryptocurrency exchanges buy ads during the super bowl?
Who wants to replace your TV and have to fix the window they broke to steal it
NFTs of art images are such an absurdity.
NFTs are an absurdity, but millions are spend on advertising them to an unprotected public. That are the real culprits.
Scammers do not deserve to get any money, that's for sure.
Most people buying stocks don't understand the company as well as someone who works in the sector.
Most casual art appreciators don't know how to tell if a painting they're buying is a forgery.
Most people buying a house don't know how to assess the foundation, and even if they get a professional assessment, they don't have the same knowledge of the housing market as professionals. Maybe that neighbourhood is slated for rezoning in 5 years that would devalue the property.
Heck, even people buying gold/diamonds get ripped off on fakes/synthetics.
Outside of investments, most people here have probably bought a car. Do people who buy a car deserve to get ripped off if they don't understand how every component works well enough to inspect it themselves?
If something happens, then we should try to help, but I'm not showing up for the candle lit vigil and pretending it's crazy that 1+1=2.
even couples with dual six figure salaries.
It's more likely they think that the victims here had every available opportunity to exercise basic diligence. I'm not sure I actually agree with that (I think a lot of the people getting scammed here are being predated on by a market that thrives on misinformation), but that's a far cry from how you've interpreted the comment.
My point is if you read that comment it takes a second of introspection to come to an answer.
I'll tell you this: the scummy thieves who drain these deserve it even less.
People must learn to avoid crypto. We can teach them why.
PS: Read your HN profile: Submitting stories is by far the best way to earn karma. Comments are small potatoes.
If the law doesn't take environmental action seriously then individuals have to take control. Destroying the entire crypto market, even criminally, would be a benefit to the world.
I'm just surprised there isn't a privacy.com equivalent for this, like a limited-view wallet that lets you create sub-wallets for interaction with various services. Or if there is, perhaps it's not famous yet. Worthwhile product, I think, but hard to build because you'll be the target of everything. I think it would be easy for me to make a mistake somewhere while building it.
Edit: and if you wanted to routinely transfer small funds to a hot wallet, gas fees will put a stop to the idea.
They go to the website, click "mint NFT", then their wallet pops up and says, "Sending [your expensive NFT] to [address], confirm?"
And then the user says, yeah, I want to send them my NFT.
There are more subtle ways to scam though. But the people losing them here are the type of users that confirm everything without reading.
Not to say it's the user's fault entirely. What they're taking advantage of, is that generally people are less familiar with what to look for in a crypto transaction vs say an online credit card form (and/or wallet UI is worse than a typical stripe checkout)
Sure.
Keep in mind though that crypto is battling the status quo where some arbitrary user could initiate an arbitrary chargeback through the use of a third party. Good luck building a smart contract around that!
With crypto there's no confusion or anxiety-- your coins are provably gone in the example you're citing.
In a way it's like the old error-prone analog computers vs. the new binary-logic-based digital ones. Yeah, rampant theft is bad, but it is discrete theft. And that is the point-- we can measure it in ones and zeros to build upon and compose the digital infrastructure that will become web4.
It's mostly zeros but you get the idea.
Just like you could pay your phone bill with a prepaid Visa each month just in case they overcharged you.