Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It isn't like monitoring would have done anything. Once the transaction goes out it is gone. The core problem here is the massive private-key bounty being created by a ton of organizations that don't have world-class security teams.


True, but you would think they’d notice $650,000,000 missing before a user reported an issue withdrawing $5,000 (edit - 5k ETH). It’s honestly so impossible to believe that I’d wager the real story is they knew and were actively trying to recover the funds.


just a poke: it was 5K Eth ($16,924,050), not 5K USD, but i agree with your wager.


God damn, 17 million stolen forever from 1 person and there is nothing they can do about it.


Even more shocking, is why someone would hand 17 million dollars worth of assets to a random company that has no security apparently.


Ah right you are. Misread the article.


But the attacker used 2 transactions. The first one should have been flagged immediately. Plus the servers themselves were compromised. Four of them. The attacker was able to take control of 4 different servers without even being noticed. This is just one massive secops fail.


Yeah, I'm just picturing a Graphana chart going from $625M to $0. And then admins sitting around like, OK, now what?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: