3/23/2026 at 11:18:24 PM
Missing from the article - the hacker first compromised Resolv Lab's AWS account, took a private key from KMS that was used to control minting, then managed to extract $25 million into ETH before all protocol functions were suspended.by primitivesuave
3/24/2026 at 4:44:00 AM
> took a private key from KMSThey used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.
by WatchDog
3/24/2026 at 5:43:23 AM
^ this is a common security misconception in crypto. "We're using an HSM, they can't steal our private key." OK genius now you still have to secure the HSM.There's no shortcut to MPC/multisig with 3+ keyholders.
by pants2
3/24/2026 at 5:59:47 AM
It's still significantly better, since access can be revoked, vs a leaked key where you're permanently fuckedby Ferret7446
3/24/2026 at 6:09:14 AM
> you still have to secure the HSMObviously.
> There's no shortcut to MPC/multisig with 3+ keyholders.
The whole concept of a stablecoin seems to be based on centralised trust. Ultimately there is some org that has the fiat bank account, that mints and redeems the coins.
by WatchDog
3/24/2026 at 10:06:50 AM
Nope, that is the foundation of bad stablecoin. Trustless decentralized stablecoin like DAI exist. People just largely don't do their homework and prefer scams that lure them in with promises of 'yield'by idiotsecant
3/24/2026 at 11:01:05 AM
DAI and SKY are backed in large part by USDC, so they are not truly decentralized. It is possible in theory, but nobody has successfully done it so far.by Hendrikto
3/23/2026 at 11:27:25 PM
Do you have a source for that information? I'd like to read more on it.by thebiblelover7
3/24/2026 at 1:20:27 AM
https://www.chainalysis.com/blog/lessons-from-the-resolv-hac...by layer8
3/24/2026 at 3:32:17 AM
It's explicitly mentioned in the article:A step by step breakdown of the attack Step 1. Gaining Access to Resolv’s AWS KMS Environment
by abrookewood
3/24/2026 at 3:58:10 AM
The link was changed, the old one did not mention it (apparently): https://news.ycombinator.com/item?id=47498220by leonidasv
3/24/2026 at 11:19:58 AM
Thank you! I was scratching my head at this, having seen 'Step 1'by rithdmc