Show HN: Zenta – Mindfulness for Terminal Users (github.com)
142 points by ihiep 10h ago 29 comments
Show HN: Kokonut UI – open-source UI Library (kokonutui.com)
2 points by kokonutt_ 1h ago 0 comments
Wrench Attacks: Physical attacks targeting cryptocurrency users (2024) [pdf]
120 pulisse 117 5/25/2025, 11:56:16 AM drops.dagstuhl.de ↗
This will only go worse and harder to protect from. Most of the instances I heard about were carried by "amateurs", which makes all this quite unpredictable.
What’s a crypto based legal system look like? I’m thinking maybe your sentence fluctuates depending on how many people have been released recently.
Maybe clever kids can fork their own legal systems?
Also, cryptocurrency transactions are reversible, it just takes a hard fork or a 51% attack in order to do so. See the etherium DAO hack and resulting fork. I would argue this is a bad thing, as it goes against the principles of cryptocurrency.
https://en.wikipedia.org/wiki/Ethereum#Founding_(2013%E2%80%...
Buterin chose the name Ethereum after browsing a list of elements from science fiction on Wikipedia.
https://en.wikipedia.org/wiki/List_of_fictional_elements,_ma...
Also, “Ethereum” looks like a misspelling to me; even though we’ve got “petroleum” and “linoleum” my instinct is to replace it with the more common “-ium” ending from the Periodic Table.
However, I have never been inclined to pronounce or spell “Dubai” with a diaresis, because it’s an Arabic word with a diphthong.
I am a native speaker of American English, second language Spanish; polyglot including proficiency in Latin, Italian, Greek, Sanskrit, and Semitic family.
I am an english native, I probably picked up the -ium suffix because that's how elements are usually written.
In general, don't make yourself a target by self-custodying.
This has not been stopped, but mitigated a lot by hiring a sufficient amount of bodyguards.
... or consider an important reason in the very restrictive gun laws in France.
There was however another case with the french familly of a Dubaï expatriated influencer, with a happier ending this time.
https://www.nytimes.com/2025/05/24/nyregion/crypto-investor-...
Crypto investor charged with kidnapping and torturing - https://news.ycombinator.com/item?id=44085188 - May 2025 (67 comments)
Sure you can pressure people to transfer money from banks to you. But that will be easier to trace and the transactions could just be reversed. If moving all your wealth the bank is likely to ask some questions, maybe want to see you in person.
With crypto the philosophy is “be your own bank”. It’s like keeping your money under the mattress. So you are a much more promising target.
e.g. you have not had a wonderful windfall of someone mistypes an account number and send you a $1 million. You are in fact obligated to report the issue and not simply go "great!" and start spending the money, tonthe point that you can be held legally liable.
It's not 100% but as people are fond of saying: we do live in a society, it's hardly onerous.
Me kidnapping you probably isn't going to yield me much money from a bank. And robbing a bank is a death sentence.
No comments yet
In my country, transfers of very large sums often require upping the transaction limit by visiting the bank branch, filling out a form and then submitting it at which point it’ll be accepted in a few days.
While obviously inconvenient when trying to transfer funds for investments, etc. it’s easy to see why the system prevents fraud of this sort.
2) Privacy focused currencies like Monero make it exceedingly difficult to attribute transactions to specific individuals.
“Be your own bank” makes a cool bumper sticker but it’s like saying “be your own pilot” or “do your own surgery” in terms of complexity and risk. There’s a reason why these things traditionally involve teams of people with various safety precautions baked in to make attacks riskier.
In all seriousness I think most people relate to kidnapping and mutilation and not wanting it to happen to them.
I mean it’s not like the traditionally rich receive much love.
Keep. Your. Mouth. Shut.
Pseudo-anonymity, with the emphasis on the pseudo part, is only as good as you. If you truly believe in Bitcoin and all that implies, it really is in your best interest to be quiet and keep it to yourself, and this knife cuts in more ways than you might expect. You don’t have layers of security like at a traditional bank. You are the weakest link wrt private keys and storage.
Also, even talking about it amongst folks you think are your friends, like fellow Bitcoin users, isn’t wise either. Hypothetically, if you became exceedingly wealthy on paper, it would be in the interest of others to take you out of the equation so you can’t cash out. If that means a five dollar (or whatever they cost these days) wrench to the head so you stop moving… now that value is locked up in the blockchain! Could this happen to any given bitcoin users with just a few satoshi or whatnot? Very unlikely, but don’t forget that a decade and a half ago, a handful of bitcoins could cost you very little money. Now it has gone up exponentially in value and would make you a big fat target.
There are those on /r/bitcoin that think a wrench won’t ever break their wills and spirits. That math is invincible. Don’t think they’ve ever been on the wrong side of one before. Math might be bulletproof, but wetware is very fragile.
One of them was defrauded of their entire savings, and only discovered at the point where they needed it as a deposit on a house. The person had spent over a year worming their way into their confidence (not just online), and was regarded as a good friend. They managed to convince them over a long period of time that it was safer for them (as a financial advisor) to manage their funds for them. Once the wallet was out of her control, the 'friend' disappeared entirely.
The interesting thing to me about this is watching how we've changed over the past 40 years. As a kid, it was impressed up on kids to not talk to strangers. You don't tell people where you live. You don't tell people anything more than necessary. Now, people share the most intimate details of their daily lives. People share/invite random strangers to their accounts without any concerns about who they are or what they might do. People just do not think about how the most benign of posts can be used for nefarious purposes by someone else. So we've gone from share nothing to over sharing everything.
During covid some SWEs had pretty sweet gigs due to lowered expectations and a rush on talent. And what do a small fraction of SWEs do? Make “life in the day of” videos that glamorize how cushy and easy-going it is, painting the whole group of SWEs as spoiled and entitled who make too much money. Point is they could’ve just realized they had it good and kept quiet.
But, no, they had to hustle for internet points, even risking their job inadvertently. It’s unbelievable to me how fast we flipped from the internet being an accessory to life to it being a surrogate for actual social interaction.
Pretending you're rich has been happening for a long time. Conversely, pretending you're poor though might make you a bit of a miser as you wouldn't use what you have to help anyone else. It seems wise to be discrete about your wealth if you have it, or you're just inviting trouble for little real gain.
Sure it'd take longer than pulling up directions on your phone does now but if you're planning a cross-country trip to kidnap someone and beat their passphrases out of them or demand a ransom from their family or whatever then you've probably got some other plans to make. If it's a total impulse then you just grab your duct tape, chainsaw, masks, and continental-scale road atlas and hit the road; when you get to your target's state you can pick up maps that'll get you to their place at the first gas station you hit. Don't make jokes about why you're on a road trip when you stop at the whimsical roadside attraction shaped like a dinosaur, someone will come forwards when your case makes the news.
If I needed a direction addresses for another city I'd just go there (had a full highway map of the country) and buy the local map - they were typically for sale near the front of basically every store (gas station, pharmacy, etc.).
And I think it all boils down to the fact that some humans need to make noise about their successes so they feel validated. Much like the cryptocurrency evangelists, they probably can’t help themselves because they want to ensure they defend “the mission” even if it comes at great personal cost in the long run.
It's worth worrying about in the general case, too. There are subtler and much more noxious failure modes here than merely getting beaned with a Swedish nut rounder.
This leads to the outcome that it is hard to find good security advice. I'm from New Zealand and too many in the crypto community here are far too trusting (unsafely so - so why would I wish to learn from them).
I was (past tense) interested in investing in crypto however I wanted to learn how to manage security before I invested more than I could afford to lose (say more than a month's salary). I have never felt I could trust my own security so I have never invested much in crypto (one exception has been a little money in crypto correlated stocks).
I was in South America and I thought that might be a good place to learn crypto security since the people there need to be a lot more careful about their security. I couldn't find anybody I trusted to teach me, even if offering a good professional hourly rate. Easy to find people with opinions on security: however they were somewhat ignorant because they lacked real risk (because their amounts at risk were small enough that they would never be spear targeted).
When basic security is silence, then it is difficult to find anyone clueful who would teach.
Edit: an interesting adventure in trying to understand trust. Smart people won't share the details of their own security because it puts their security at risk (how can they trust me?) And why would I trust anybody who isn't at risk?
It’s truly exhausting in the long run, which is why I prefer old fashioned, tried and true financial vehicles instead.
Because they are very knowledgeable.
Matt Levine had a recent article about this. Another part of the problem is that some BTC repositories* got hacked and the hackers got people's names and addresses and maybe quantity of BTC
So, even if you keep your mouth shut, if people can get your address, you're a potential target.
*(I can't recall the details and I don't know enough about crypto to know if I'm using the proper terminology)
* edit: here's the article. skip down to "$5 wrench attack"
https://archive.is/lUNox
Everything you do to keep keys safe from some risks weakens your posture against other risks. Making sure most people don't know about your holdings is nice and all, but ultimately key management is a really hard problem. It's hard enough for companies, but I'd argue it's even worse for individuals.
If the person who kidnaps you believes you have the necessary keys on you, or remember them or whatever, they aren't going to let you go because you genuinely do not have the ability to provide them.
A critical aspect of crypto-currencies is sales. They have to sell a story so that investors keep pouring money into the system. Otherwise the whole thing would collapse very quickly.
With events like the recent Coinbase breach, is this even enough?
Of course it would be easy to say one's never touched crypto, and not so easy to prove, as with any negative. I don't care. If I ever get bounced with a King Dick, it'll far more likely be because I said something someone didn't like - which seems to happen about as often as I open my mouth, these days. Or because I said something someone failed to comprehend and so took insult at. Brains are severely out of fashion this decade, and I can't seem to help having some, so presumably someone will seek to scatter them sooner or later. Why not? I hear it's the last argument of kings, and their time too seems coming 'round again.
In any case they better not let me hear them coming. Wiser to spin the block in a car, really. I've never been hit with a wrench before, but it did once take more than a hammer to get me off my feet.
No, all those trying to normalize the wild-west and those who try to prosper from the wild west- they have to go. Now. Wherever they came from. Take your low-thrust, non-working societies with you. The enablers too, if you want to co-exist with this, you are wrong here. You need to go. Now.
The Jordan Belforts and P.T. Barnums (and many more) have been a part of US society since the beginning.
You’re just able to see the snake oil salesman parting the rubes from their coin remotely, instead of only being able to see it if you’re standing right next to the rube.
Even with that happening, there are still plenty of rubes - and just like before, people who are trying to run the snake oil salesman out of town (but generally being ineffective at it).
Side joke: with inflation the XKCD $5 wrench attack (https://xkcd.com/538/) is no longer possible.
Seriously though, most B&E’s will use tools stolen from some prior victim. Why spend money you don’t need to, or something.
$7.99
They also have an 8-inch wrench on sale for $3 but I'd spend the extra for the pipe wrench.
Better whackin' with an 18-incher.
This way, you don't even have to torture them. You just have to kidnap them and keep them from transmitting closing transactions.
If you open a channel with them beforehand, you don't even need to extract the keys from their hardware. You get to can steal the funds in their channel unless they use another mechanism like a DMS to transmit a revocation transaction.
Kids these days.... Always inventing new words for old ideas, amirite?
More seriously: I'm still a little unclear how stealing crypto is feasible. There's a ledger, right? Tumblers are really that effective at hiding the chain of custody?
At some point(s) the cyberspace "durable digital asset" (h/t a15z) has to emerge in meatspace, right? Even if it pops up in Russia, NK, or Golden Triangle, there's always some heads to bash, fingers to break. Right?
There is tech for private transactions, but the cryptography is more complex. It's used in cryptocurrencies like zcash or monero. You can also trade between different cryptocurrencies without trusting an intermediary, using "atomic swaps". So if you seize cryptocurrency you think will be tainted, you have a small window to swap it for private (and thus fungible) currency.
https://cointelegraph.com/news/zachxbt-330m-btc-heist-xmr-su...
This business is booming!