Atomic Wallet exploited, users report loss of entire portfolios
cointelegraph.com
cointelegraph.com
When this happens to crypto, you got nobody to blame but yourself.
Great. So not only I lost my money but now I'm getting an assignment as well. Which will last many years and at best will result in recovering a fraction of what I lost and the most likely outcome us not getting anything back and possibly paying more.
Which ones?
I still haven't gotten my money back.
Thankfully we can be reasonably sure that some compilers at least predate cryptocurrency.
Are there actually any keyloggers for iOS and Android? Unlike on desktop OSes, there isn’t even an API for that, so you’d need an actual OS exploit.
> fresh linux system with fresh wallet software
And how do you make sure that that doesn’t come with a keylogger (in a world where a significant number of people were to actually do that)?
Not necessarily, for instance 3rd party keyboards like Grammarly are keyloggers by their very nature. They grab your input, process it, and give output in terms of grammar corrections. And a rogue app update can absolutely do the same.
> And how do you make sure that that doesn’t come with a keylogger
The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.
> The same way you verify anything is what you want and stays that way, MD5/SHA256 hashes and airgaps.
How do you determine a given hash to be trustworthy? And how do you know you can trust your `sha256sum` implementation?
You're always trusting someone. Any security analysis pretending otherwise is worthless.
wow, what a practical way to be able to store and use money!
If you want “practical” and unsafe, then store all your crypto in hot wallets like Atomic, that sure ended up well.
This is not at all to say that there is no point in hardened/secure execution environments like smartcards, Yubikeys, hardware wallets etc., but the important point is that the statement "hardware is more secure than software" by itself is dangerously misleading.
And there is no such thing as (fully) "FOSS hardware". Somebody needs to build a physical thing in the end, and you can't verify every single step of that process. Openness/transparency has its advantages and reduces the chance of nefarious things happening in your supply chain, but this is lightyears away from "trustlessness".
https://www.cnn.com/2023/06/02/investing/payment-apps-safety...
Still, personally, I distribute over all kinds of banks (where I get E100k per bank when they fall, so I make sure I'm under that amount per bank) and assets so the fallout is minimal if something falls. Well, unless it's a 1929 event of course; then it remains to be seen what is left after. But then crypto is wiped out too; people gotta live, so they will mass sell off.
All I ever hear is how we need more regulation with crypto. Why aren't we demanding that with something as pervasive as Paypal/Venmo?
I wouldn’t even trust Metamask in the long run. If the wallet doesn’t get exploited, something that interacts with the wallet will.
If crypto ever becomes a bigger market, you’ll eventually have state actors trying to exploit protocols and wallets, and they’ll be more sophisticated than the North Korean hackers.
This strikes me as funny because software engineers are regularly told not to roll their own crypto.
surely they would have some idea
To me this seems the most obvious. Use open source wallets, reproducible builds, hashes and, of course, cold wallets. Also, divide; don’t put your money in one place; I would say that goes for banks too.
If not, I don’t see how an app on a phone is worse than on a desktop.
I don't get your response, though. It was an app where the keys were "yours". The "not your keys" is about custodial services, which this is not.
If the keys were stolen using a cryptographic trick, how was it done at scale?
It sounds to me like at some moment the keys were exfiltrated.
So "not your keys, not your coins" stands. If you don't have strict control over the keys you don't have strict control over the coins.