🧠 [Long Research] Topic: Fucking around with keys is a bad idea!
Migrate your seed to another hot wallet: no.
Migrate your keys from ledger to metamask: no.
Fuck around with seed generation: no!
💡 This news piece is not new-new. It's more of a wake-up call, based on recent recent information on how big the numbers were. Stop using unsafe systems if switching costs are so low! Changing a 2FA app or sending a few coins to the a address isn't hard at all…
Remember the GCR tweet from a couple of years ago? It says that even if you hold some of the good assets, a gazillion non-economic attack vectors can mess you up: your mobile phone security is weak, your keys will get lost, your seed phrase sheet will get seen by a random person, etc. There is no need to be a security junkie, but at least don't hold 7 figures in a phone app LoL 😰 like the atomic sers below.
It's not even about wrenches or sophisticated attacks, it's just common sense. For instance, a friend of mine almost lost their seed phrase from their Metamask when the laptop was broken... "I just never took the time to save the phrase after 6 months of daily trading". Another one had a similar situation, despite being knowledgeable about security. It's just negligence; it's not rocket science.
And just yesterday 👀 yet another Profanity thing came to light, unfortunately affecting KP3R, see the post-mortem. An attacker got hold of the governor of a whitelisted job in Keep3rNetwork v1. Tthe governor address was generated via Profanity, making it vulnerable.
Again: fuck around with cryptography, find out. Similar to fucking around with oracles in DeFi.
-> Back to the hack summary of Atomic Wallet
NEW 🔥 more losses were found, reaching $100M . See fresh Tay's thread.
The breach started on June 2, with reports of assets disappearing from users' wallets surfacing on June 3. The largest victim of the hack was on Tron, with 7.95 million USDT stolen, and the total losses amount to $35+ million. The stolen funds were converted into Bitcoin (BTC) and then laundered through a mixer called Sinbad, favored by the North Korean hacker cell Lazarus. Ahhh, it's all Lazarus isn't it…
The exact cause of the hack is still unknown, causing concern for the over a million users who may still be vulnerable. One theory suggests that a malicious update transferred users' private keys to the perpetrator when they opened the app. Atomic Wallet's security has been questioned before, and an audit conducted in 2021 raised concerns. Who says Trust Wallet or any other closed source wallet or extension doesn't suffer the same…
Software wallets, like Atomic Wallet, are considered fundamentally flawed, as they can be compromised easily. These recent incidents highlight the need for better security in the crypto community. To mitigate risks, it is recommended to trust open-source wallets, diversify holdings, and remember the importance of controlling your keys. And not by generating through weird apps! Stay safu, crabs 🦀
For more info:
- Thread by ZachXBT
- Visual & thread by Tay
PS: sumimasen, we were swamped with work for a few days, back to slow writing again.
Post #931
3.85K