Daily Mail PH

Thursday, October 12, 2023

[New post] Alameda Trader Phished for $100 Million After Clicking Malicious Google Link, Says Ex-Engineer

Site logo image Crypto Breaking News posted: "In yet another lengthy thread on X (formerly known as Twitter), former Alameda Research software engineer Aditya Baradwaj revealed how FTX's sister fund grappled with multiple security incidents, ultimately losing at least $190 million in trading funds.On" Crypto Breaking News

Alameda Trader Phished for $100 Million After Clicking Malicious Google Link, Says Ex-Engineer

Crypto Breaking News

Oct 12

In yet another lengthy thread on X (formerly known as Twitter), former Alameda Research software engineer Aditya Baradwaj revealed how FTX's sister fund grappled with multiple security incidents, ultimately losing at least $190 million in trading funds.

One of the most significant exploits detailed by Baradwaj reportedly involved a trader at Alameda losing more than $100 million of the firm's funds.

The incident unfolded when the trader clicked on a malicious link for a DeFi app that had been promoted to the top of Google Search results.

Decrypt reached out to Baradwaj for additional comments and will update the article should we hear back.

Another example cited by Baradwaj revolved around Alameda's involvement in yield farming on a blockchain of "questionable legitimacy." This venture resulted in losses exceeding $40 million, as "the creator ended up holding our funds hostage, and we had months of prolonged negotiations."

Incident #1:

An Alameda trader got phished while trying to complete a DeFi transaction by accidentally clicking a fake link that had been promoted to the top of Google Search results

Cost: $100M+

Postmortem: Implemented extra checks on our internal wallet software

— Adi (e/acc) (@aditya_baradwaj) October 11, 2023

Yet another incident reportedly saw an old version of Alameda's plaintext keys file leaked, supposedly by a former employee, according to Baradwaj. It resulted in the attacker transferring funds out of some exchanges and placing bad orders, with Alameda losing another $50 million.

"These are just a few incidents—there's many more, including from before my time at the company," said Baradwaj.

Responding to the above incidents, the firm simply implemented extra checks on its internal wallet software, decided to be more careful about which protocols it was trading on, or migrated secret keys to a more secure storage system.

"Was the tradeoff worth it?" asked Baradwaj. "Sam certainly seemed to think so. Even after all these incidents, no serious attempt was made to change the way we operated. It's the kind of risk-taking that seems to work... until it doesn't."

Alamada pushes speed over security

According to the former Alameda employee, the trading firm put substantial focus on prioritizing speed, a belief held by FTX founder Sam Bankman-Fried.

This approach often led the company to overlook industry-standard engineering and accounting practices.

This meant virtually no code testing and incomplete balance accounting

Safety checks for trading would only be added on an as-needed basis

Blockchain private keys and exchange API keys were stored in plaintext in a file that several employees could access

— Adi (e/acc) (@aditya_baradwaj) October 11, 2023

Code testing, according to Baradwaj, was virtually nonexistent, and safety checks for trading were implemented only when deemed necessary.

"These decisions allowed us to move at breathtaking speed. Developer velocity that would make any Silicon Valley software engineer shed tears of joy," wrote Baradwaj. "However the flip side of this tradeoff was that we'd have a major security incident once every few months."

Baradwaj's remarks come as former Alameda CEO Caroline Ellison took the stand to provide testimony against Bankman-Fried on the sixth day of his fraud trial in New York.

She shed more light on the firm's relations with FTX, including former co-CEO of Alameda tapping Thai sex workers in a bid to reclaim $1 billion worth of funds frozen by the Chinese government.

Stay on top of crypto news, get daily updates in your inbox.

Source: Decrypt.co


Unsubscribe to no longer receive posts from Crypto Breaking News.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://www.cryptobreaking.com/alameda-trader-phished-for-100-million-after-clicking-malicious-google-link-says-ex-engineer/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at October 12, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Learn to spot & report corruption: Join Rappler’s workshops, forum in Dumaguete!

The most interesting news selected specially for you!       Hello!   Did you know that you can actually do something to make your commun...

  • [New post] Achieve Data Sovereignty through Omnisphere
    Crypto Breaking News posted: "Web 3.0 is one of the biggest buzzwords flying around the world of social media this year. An...
  • [New post] Tuesday’s politics thread is trying to stay positive.
    SheleetaHam posted: " Even though I just finished the latest Opening Arguments podcast about how Roe v. Wade is toast, and ...
  • [New post] Is XRP going to take the Crypto market by storm
    admin posted: "Is XRP going to take the Crypto market by storm While the SEC has been going after Ripple in court the XRP b...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • January 2026 (6)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.