Hacker News new | ask | show | jobs
by UncleMeat 1550 days ago
It isn't like monitoring would have done anything. Once the transaction goes out it is gone. The core problem here is the massive private-key bounty being created by a ton of organizations that don't have world-class security teams.
3 comments

True, but you would think they’d notice $650,000,000 missing before a user reported an issue withdrawing $5,000 (edit - 5k ETH). It’s honestly so impossible to believe that I’d wager the real story is they knew and were actively trying to recover the funds.
just a poke: it was 5K Eth ($16,924,050), not 5K USD, but i agree with your wager.
God damn, 17 million stolen forever from 1 person and there is nothing they can do about it.
Even more shocking, is why someone would hand 17 million dollars worth of assets to a random company that has no security apparently.
Ah right you are. Misread the article.
But the attacker used 2 transactions. The first one should have been flagged immediately. Plus the servers themselves were compromised. Four of them. The attacker was able to take control of 4 different servers without even being noticed. This is just one massive secops fail.
Yeah, I'm just picturing a Graphana chart going from $625M to $0. And then admins sitting around like, OK, now what?