Discussion about this post

User's avatar
awbvious's avatar

Going out of order to comment on this, as it's timely advice for anyone (not just DZM, but definitely applies to DZM right now).

Do not engage scammers. Do not assume that you know all their tricks and can avoid them. Or that you know what specifically they are going for. It's possible that funds in a hot wallet is an end goal, but maybe not /your/ hot wallet.

https://krebsonsecurity.com/2023/05/discord-admins-hacked-by-malicious-bookmarks/

DZM has a Discord, they might want his Discord admin credentials. Would he know not to use the same browser with cached credentials (if he has them) to have the meeting. Further clickjacking is probably not something DZM has heard of, nor I prior to this article.

The above, I'm pretty sure happened to Fetch, and the admin that got compromised got /me/ compromised, because I felt like I "knew" the person, and didn't realize it was an impersonation. Further, the messages were old and I couldn't believe such a compromise could last that long. Further, I thought I knew what to look out for. Namely, authorizing spending of a token. That's a huge red flag, but the new drainers, like PinkDrainer which I think has "retired" actually use Permit, which doesn't have anything helpful in the transaction details to prior to clicking confirm. (Note: You can sometimes undo Permit via revoke.cash and they have some good articles on it https://revoke.cash/learn/approvals/what-are-eip2612-permit-signatures and https://revoke.cash/learn/approvals/what-is-permit2 .)

Fetch never did reimburse me or anyone else for their hack https://fetch.ai/blog/new-discord-server . The main reason I feel them responsible to compensate is it took them far too long to do something. And regardless they did very little to engage the community and show they were taking it seriously.

Then when I tried to get users to join forces with me to maybe shame them into action, they blocked me from the Discord. What's worse is the reason I would go to their Discord and talk repeatedly with the admin I thought I "knew" was they owe me from their Ethereum chain staking days. They kept claiming a reconciliation that never happened, even after signing up for it. Said they were waiting for a network upgrade. Well, pretty sure the ASI superalliance should count for that (it was a BS excuse anyway). Now I got no way of contacting via Discord and they don't respond to emails. Bad org all around.

I don't want to go off track too much, just to say in crypto you're on your own. And I'd prefer that over BS regulation that, say, benefited giant centralized exchanges and recreated Big Tech monopolies in crypto because they are the only ones who can afford regulation management. A nuanced approach that benefited smaller players would be great, but that's not typically how things go in congress these last few decades, is it?

Reverse image and checking your network and other research is great, and naturally in DZM's wheelhouse. But engaging and seeing what happens really should only be done by an sec ops expert. At the point where the meeting was going to happen, someone like SamCZSun, Gupta Mudit, or ZachXBT should get involved. I mean, if DZM's got that kind of cachet to get their time, otherwise stay away.

Oh, and:

"

If you want to be more energized, face your palms to the sky. If you need calm, turn your palms to the ground.

"

Pretty sure that psuedoscience. Yoga has a lot of dubious stuff regarding hand postures (see mudras). The rotation of the hands will have a subtle effect on your shoulders and postures, but you can do whatever feels most comfortable. The rest seems right. There's some nuance in trying to think of nothing vs detaching and turning off thinking of something (see Citta, though I consider it more out of control mental time travel), but that could just be semantics.

Expand full comment
1 more comment...

No posts