Misunderstanding by end users of MEMO and MNEMONICS, resulting in $1.3 million in losses
// New users can add only 2 links, so make some personal edits for full story, will edit when will get higher rating! UPD : I got approval from a team that is well versed in this issue, so after a long wait and numerous allegations of fraud, we finally posted it here to prevent any other claims about our (dishonest, as some think) work in the future. 1. $1.3M Loss with MEMO and MNEMONICS To understand the problem, you should check two articles - #1 on the loss of Amphibious Validator and #2 - on MightyFrog CTO’s report. #1 : Heart-Stopping Experience of Breaking a Validator in Cosmos-Based Chain in Prod: How, Why, What to Do and More… | by Lordfrog | Mighty Frog Ecosystem | Medium #2 : How we found exposed wallets in Cosmos-based blockchains | by Techno Freak | Mighty Frog Ecosystem | Medium 2. IBC - Potential Losses Leveraged IBC is an incredible feature that allows the user to interact between different chains = keep all the assets of the all possible cosmos-based chains in one chain wallet (user side view is mostly based on our predictions). Since we published our articles and provided a minimum viable solution (wasmywalletleaked. com) - will be detailed in…
Excerpt (1198 of 4693 characters). Read the whole post on the forum ↗
In addition to the above, cryptocurrency market for a long time needed some solutions to prevent users ‘shoot themselves in leg’, so the topic is the right way to develop any ecosystem safe for users first of all.
Just an interesting sing that Ripple solve such kind if problems renaming MEMO to an Destination Tag and making it numeric only (memos are alphabetical), which is just an workaround (IMHO).
Exactly, but still there are 100s of blockchains using this MEMO standard and MNEMO (jargon for mnemonics = private keys)
Main issue in all such problems as @Mighty_Frog mentioned is literally just miscommunication in naming conventions, I as former UX designer can say that this issue is wrong ‘memory recall’, so it’s slightly different from technical field.
@Stanley, yes XRP changed naming which should help, but coins losses in dosens of other transactions giving bad experience to users and even large investors.
Exactly, as we said no wallets or exchange fault, just user
Same problem was before websites started to force people to create strong passwords
Respect Apple for their strong pass recommendations on web and some apps, might take this into consideration don’t know how
Heard about problems of fund losses due to typos in adresses, as one guy from reddit who send 3K BTC in a 2k15 to a somehow existing adress (probability 1 no 4 billions) so no one believed him, but the MEMO’s problem looks more wide spread.
Just a small reminder that Ripple had never an MEMO attribute, that was Destination Tag from the beginnig BUT users anyway submit there accounts password LMAO
@M_Everett God bless 2FA on my accounts, that actually helped me hold my funds from being stoled when YoBit where hacked at 2018
Actually concept described above looks promising, I would not surprised if that could became an actual standart for new ecosystems in a 2-3 years. Anyway seems like cosmos is opensorced so that could happen even faster.
Thought such stuff should regulated by default, but unlike any new tech it all go througt ‘way of try and failures’
Are you saying people are/have sent their seed phrase in the memo field of a transaction? If this is the case wallet apps should definitely take steps to prevent this if possible.