• 0 Posts
  • 12 Comments
Joined 2 months ago
cake
Cake day: June 8th, 2026

help-circle

  • No, the cold wallets were using a predictable algorithm to generate key phrases. When you set up the wallet, you use the generated key phrase to pair it with your coins. So this wallet is supposed to live offline, keeping your coins safe because the key is kept offline. No way to hack it if it’s entirely offline. But a flaw caused the generated keys to be predictable, meaning hackers were able to brute force the keys and initiate coin transfers without even messing with the cold wallet.

    Imagine you lock a million dollars behind a super secure vault door. This vault is impervious to all kinds of physical and digital attacks. The only way to open it is with the key. The vault is in a public area, but (again) there is no way to open it without the key. This vault only has one key, which you keep safely stored in a separate secure facility. Additionally, this key has like a thousand pins and tumblers, so it should be nearly impossible for a hacker to guess the correct key. The hackers essentially realized that due to a flaw in the lock’s design, there were only like three dozen potential key combinations. The thousand pins didn’t actually matter, because they were predictably arranged at the factory that built the lock. So the thieves just made like two dozen fake keys (until they got the correct one,) then took the money. All without touching (or even seeing) your key.



  • The issue is doing one at scale, with proper access controls. Also, let’s not skip past the whole “network isn’t air gapped anymore” side of things. Now you’re having to maintain firewalls, patch firmwares, manage users, enforce good password hygiene, etc… All without any additional IT support or hardware, because management is doing this as a cost cutting measure.

    I can pretty much guarantee that the systems that get hacked aren’t the ones that do everything right. They’re the ones who have a single shared VPN password, haven’t updated their firewall since it was installed 8 years ago, and they haven’t even changed the default passwords for their control systems. Because they got tired of answering phone calls about what the password was, so they just made every username and password something stupid like admin/admin.




  • In a statement, Murphy cited the recovery amount, personal payments by former executives, a commitment for $7 million to go to nonprofits and the absence of a confidentiality provision in a system where “wrongdoers too often hide their misdeeds by dangling compensation in front of those they victimized and trading that compensation for confidentiality or an NDA.”

    Glad they stuck to their guns. I’ve been following this case for a few years now. This all began as an attempt by eBay’s C-level executives to bully a few reporters into silence. It makes perfect sense that those reporters would refuse to accept an NDA as part of the settlement, because reporting on things like this is exactly what landed them on eBay’s radar in the first place.