Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Elysiume posted:

this sounds like hell

ah yes it's micro loans again but this time with blockchain! and venture capitalists, those famous drivers of economic benefits for the world's poor!

Adbot
ADBOT LOVES YOU

Qwertycoatl
Dec 31, 2008

a loan which by its nature is impossible to use for anything other than some dumb poo poo

Zamujasa
Oct 27, 2010



Bread Liar

ymgve posted:

actually looking at the change proposal they camouflaged it as a donation to Ukraine (which they actually did, not sure if it was part of the attack or some more obfuscation)

the code is short and I don't see any obvious flaws so theres probably just some gotcha in how change proposals are added to the bean system, but I guess it explains why the proposal didn't raise any alarm bells

i'd be interested in seeing a detailed explanation. i'm not enough of a shitcoin expert to figure it out, though it's interesting that the tx you linked calls .mint, and somewhere deep in the bowels of that shitcoin contract there is a mint() function that says something akin to "low level function that should be called after security checks".

it can't be that stupid, i must be understanding it wrong.

Hammerite
Mar 9, 2007

And you don't remember what I said here, either, but it was pompous and stupid.
Jade Ear Joe
hosed up that Johnny from the Zybourne Clock is alive, and trolling yospos superstars to death.

Qwertycoatl
Dec 31, 2008

Zamujasa posted:

i'd be interested in seeing a detailed explanation. i'm not enough of a shitcoin expert to figure it out, though it's interesting that the tx you linked calls .mint, and somewhere deep in the bowels of that shitcoin contract there is a mint() function that says something akin to "low level function that should be called after security checks".

it can't be that stupid, i must be understanding it wrong.

it's stupider than that, you're understanding it wrong.

a proposal had to exist for 24 hours before it could be voted on and enacted. however, it's possible to change the proposal during this time. so the attacker submitted a completely empty proposal 18, and the ukraine thing was proposal 19 but called "proposal 18" to throw people off. then once the 24 hours were up the attacker replaced the empty proposal with the attack code and voted it through.

the actual attack code doesn't come with source code, maybe someone will reverse engineer the ethereum bytecode but it's not going to be me

gschmidl
Sep 3, 2011

watch with knife hands

Qwertycoatl posted:

the actual attack code doesn't come with source code, maybe someone will reverse engineer the ethereum bytecode but it's not going to be me

Shame Boy
Mar 2, 2010

Kazinsal posted:

the lore goes that jonny (pbuh) sent stymie into such a frothing rage by repeatedly calling him a millionaire that he went on a flameout comparing being told to ignore jonny trolling him to being told to not dress provocatively to avoid being raped (stymie's words, not mine)

jean de deux-cent-quatre-vingt-dix is the master of casually trolling horrible people into loving off forever

it was in the tech bubel thread and it was fun to watch yes

ultrafilter
Aug 23, 2007

It's okay if you have any questions.


Shot:
https://twitter.com/revive_dom/status/1514752274471473152

Chaser:
https://twitter.com/revive_dom/status/1516047190044590080

Eeyo
Aug 29, 2004

hindsight is 20/20 and all, but i feel like "only allow governance tokens that haven't been transferred since proposal was made" and "proposals cannot be changed or amended after they're made" would have been fairly obvious additions to my decentralized contract.

Shame Boy
Mar 2, 2010

Eeyo posted:

hindsight is 20/20 and all, but i feel like "only allow governance tokens that haven't been transferred since proposal was made" and "proposals cannot be changed or amended after they're made" would have been fairly obvious additions to my decentralized contract.

from what i understand of how etherium works, that second one is harder than it sounds because everything is function pointers to other smart contracts

distortion park
Apr 25, 2011


Eeyo posted:

hindsight is 20/20 and all, but i feel like "only allow governance tokens that haven't been transferred since proposal was made" and "proposals cannot be changed or amended after they're made" would have been fairly obvious additions to my decentralized contract.

Even if the proposal had been static I think the attack would still work? As long as 50% of the assets are available to borrow it's free game.

The idea is that possession of the money confers voting rights, and whoever has 50% of the money can vote to do whatever they want with 100% of the assets. That's exactly what happened here so I don't think they can go crying to anyone about it. If they wanted minority shareholder protections they could have started a normal company.

Blotto_Otter
Aug 16, 2013


Eeyo posted:

hindsight is 20/20 and all, but i feel like "only allow governance tokens that haven't been transferred since proposal was made" and "proposals cannot be changed or amended after they're made" would have been fairly obvious additions to my decentralized contract.

come on now, if you start using things like "common sense" and "just a little dash of knowledge about the history of finance and contracts across centuries", we might wind up coming to the conclusion that all of this cryptocurrency stuff is terrible and useless for anything but scams, and we can't have that now can we

e:

Qwertycoatl posted:

a loan which by its nature is impossible to use for anything other than some dumb poo poo

screaming at the loan officer at my local credit union that it is an infringement of my free speech HIPPO rights to ask me what I plan to do with a loan that only lasts 0.13 seconds

Blotto_Otter fucked around with this message at 15:12 on Apr 19, 2022

distortion park
Apr 25, 2011


No one's doing it because there are easier fish to catch, but if you had enough money then any of these DAOs which control a pot of outside assets and trade at near par are vulnerable to someone slowly buying up 51% of the tokens then cashing out the whole thing. Flash loans make it easier and cheaper but they aren't the only issue.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/gvanrossum/status/1508959260905918465

Shumagorath
Jun 6, 2001
I like how he posits it as if Python needs a future in web3 and not the reverse.

killhamster
Apr 15, 2004

SCAMMER
Hero Member

this one's excellent because he's absolutely convinced someone from apple called him and all the other nft dorks in the replies think the same and apple themselves shows up to post "nah it wasn't us, you got scammed"

https://twitter.com/AppleSupport/status/1514986406489346050

Chalks
Sep 30, 2009

distortion park posted:

No one's doing it because there are easier fish to catch, but if you had enough money then any of these DAOs which control a pot of outside assets and trade at near par are vulnerable to someone slowly buying up 51% of the tokens then cashing out the whole thing. Flash loans make it easier and cheaper but they aren't the only issue.

the fundamental flaw with a system where 51% can do anything they want is that 51% can steal everyone's stuff. DAOs are specifically designed to bypass all the regulation and some of that regulation is what prevents this so.... working as intended?

Main Paineframe
Oct 27, 2010

the response makes this

https://twitter.com/tech_update0/status/1516262537737605122

running straight to elon musk to invite him to a Twitter fight with someone who badmouthed crypto

gschmidl
Sep 3, 2011

watch with knife hands

Main Paineframe posted:

running straight to elon musk to invite him to a Twitter fight with someone who badmouthed crypto

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.




Truman Peyote
Oct 11, 2006





unfortunately it is a tell-all by the widow of that crypto ceo guy who disappeared, not a steamy crypto-themed smut novel

Neito
Feb 18, 2009

😌Finally, an avatar the describes my love of tech❤️‍💻, my love of anime💖🎎, and why I'll never see a real girl 🙆‍♀️naked😭.

nft bros falling for sub-Kitboga-video level scams is just what I'd expect.

SubG
Aug 19, 2004

It's a hard world for little things.
by definition nft owners have already fallen for a sub-Kitboga-video level scam

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

Elysiume posted:

holy poo poo, since 2019?

i was confused about why the leper colony wasn't showing his more recent ban because there's no way it's been three years right?

graph
Nov 22, 2006

aaag peanuts

Truman Peyote posted:

a steamy crypto-themed smut novel

someone call mr tingle

Endless Mike
Aug 13, 2003



graph posted:

someone call mr tingle

way ahead of you

Vincent Van Goatse
Nov 8, 2006

Enjoy every sandwich.

Smellrose

four seconds

Boxturret
Oct 3, 2013

Don't ask me about Sonic the Hedgehog diaper fetish
i watched the whole thing because im dead, it doesn't even end, just abruptly cuts off right when a new ape is starting their part of the ""song""

ultrafilter
Aug 23, 2007

It's okay if you have any questions.


They probably didn't think anyone would get that far.

Shumagorath
Jun 6, 2001

Boxturret posted:

i watched the whole thing because im dead
the sixth sense, but we're all the kid and bitcoin can only end when boxturret's spirit moves on

Boxturret
Oct 3, 2013

Don't ask me about Sonic the Hedgehog diaper fetish
just get one million bitcoins and I will rest in peace

Pigbuster
Sep 12, 2010

Fun Shoe


I think he actually did?? I'm pretty sure he had a BAYC av before. If so lol

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
to be fair, maybe he got sick of wearing the loss

Pigbuster
Sep 12, 2010

Fun Shoe
https://twitter.com/revive_dom/status/1515667785099231232

What possesses a person to do this. "Oh, someone's trying to hack my phone. Ah and now the scammer is calling me. But wait, the supposed scammer is telling me to call the number back, something which is definitely how Apple support operates. Oh the number to call back says "Apple", guess that means he's legit!".

It also looks like they phished his Apple account and got the encrypted MetaMask vault that was stored on iCloud (which Metamask apparently does by default lol). They still needed this guy's password for it though so I think there's yet another fuckup somewhere.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
to be clear, he called the number that appeared on his phone, that the scammer had just called from. rather than say, looking up the number on the apple dot com website, and calling that.

he is very smart, you see

Zamujasa
Oct 27, 2010



Bread Liar

Qwertycoatl posted:

it's stupider than that, you're understanding it wrong.

a proposal had to exist for 24 hours before it could be voted on and enacted. however, it's possible to change the proposal during this time. so the attacker submitted a completely empty proposal 18, and the ukraine thing was proposal 19 but called "proposal 18" to throw people off. then once the 24 hours were up the attacker replaced the empty proposal with the attack code and voted it through.

the actual attack code doesn't come with source code, maybe someone will reverse engineer the ethereum bytecode but it's not going to be me

so much for 'immutable'

Pigbuster
Sep 12, 2010

Fun Shoe

infernal machines posted:

to be clear, he called the number that appeared on his phone, that the scammer had just called from. rather than say, looking up the number on the apple dot com website, and calling that.

he is very smart, you see

Yeah but then why did it say it was Apple. Can't explain that!

RPATDO_LAMD
Mar 22, 2013

🐘🪠🍆
i asked the nice man inside the telephone if he was scamming me and he said no

Boxturret
Oct 3, 2013

Don't ask me about Sonic the Hedgehog diaper fetish
are you a scammer? you have to tell me if you're a scammer

Adbot
ADBOT LOVES YOU

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Pigbuster posted:



I think he actually did?? I'm pretty sure he had a BAYC av before. If so lol

p sure their twit av was one of those extra gross + grotesque zombie apes or whatever when i saw it, so :golfclap:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply