TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dusting “Attack” via Tornado Cash to Public Wallets

183 pointsby martialgalmost 3 years ago

21 comments

ArtTimeInvestoralmost 3 years ago
Ethereum is very different in this regard than Bitcoin.<p>Ethereum has accounts. So when Ana sends coins to Berta, Berta has no way to leave those coins untouched. As they just raise the amount of coins she owns. So next time Berta sends coins to Charles, it is unclear <i>which</i> coins she sent and if those include Ana&#x27;s coins.<p>Bitcoin on the other hand has no accounts. When Ana sends coins to Berta, she just marks those coins as &quot;Can be spent by Berta in the future&quot;. Berta can decide to never touch them. When Berta sends coins to Charles, she decides <i>which</i> of her coins she sends.<p>It is even more complex, as the conditions how the Bitcoins can be spent are defined by little scripts. Even though those scripts are (for now) more restricted than on Ethereum.<p>So it is not really true that Bitcoins are &quot;on address 17f8..&quot;. In reality that means the Bitcoins are locked by a script that demands any transactions must be signed by the secret key that matches public key 17f8...<p>So in a sense, Bitcoin does not have addresses. It has scripts.<p>I wonder how Blockchain explorers deal with more complex scripts. For example on blockchain.com one can look up coins by putting an &quot;address&quot; into the search bar. But how would one look up coins that are not locked by a script that puts the coins under control of a certain key? Or a script that puts them under control of multiple keys?
评论 #32407516 未加载
评论 #32400140 未加载
评论 #32405319 未加载
评论 #32400321 未加载
评论 #32400111 未加载
评论 #32400044 未加载
评论 #32401518 未加载
评论 #32400341 未加载
评论 #32401306 未加载
评论 #32399976 未加载
mmastracalmost 3 years ago
Judges don&#x27;t run code, so a dusting attack isn&#x27;t going to magically obfuscate anything. The blockchain record is public and it&#x27;s clear &quot;to a reasonable person&quot; that this is just a smokescreen.<p>That&#x27;s really what&#x27;s missing from web3: the concept of what a reasonable person [1] would believe - not a code-based contract.<p>[1] <a href="https:&#x2F;&#x2F;www.courthouselibrary.ca&#x2F;how-we-can-help&#x2F;our-legal-knowledge-base&#x2F;reasonable-person-reasonable-man" rel="nofollow">https:&#x2F;&#x2F;www.courthouselibrary.ca&#x2F;how-we-can-help&#x2F;our-legal-k...</a>
评论 #32400228 未加载
评论 #32400028 未加载
评论 #32399972 未加载
评论 #32406645 未加载
评论 #32411019 未加载
评论 #32400006 未加载
评论 #32409288 未加载
评论 #32401160 未加载
abxytgalmost 3 years ago
One of the most interesting implications of this is that it is a slight vindication of the bitcoin maximalist &quot;bitcoin fixes this&quot; mantra. If a government can&#x27;t exercise control over your unit of account, it doesn&#x27;t matter what they sanction.<p>Of course the &quot;bitcoin&quot; that &quot;fixes this&quot; isn&#x27;t the one we have in reality -- you can&#x27;t use it widely and cheaply to transact and it&#x27;s so volatile as to be useless as the unit of account for anyone with more than a few thousand $ nw.
评论 #32401713 未加载
评论 #32400064 未加载
评论 #32400306 未加载
woahalmost 3 years ago
Anti money laundering laws are similar to attempts to ban encryption because &quot;criminals might use it to plan crimes&quot;. Instead of focusing on catching criminals doing illegal things using time honored criminal investigation techniques, the government has chosen to curtail everyone&#x27;s right to privacy and free speech.<p>An analogous situation would be if the US government published a list of IP addresses which were known to have sent encrypted traffic, and declared that anyone receiving packets from these addresses (regardless of whether they wanted to or not), might be prosecuted.
mgraczykalmost 3 years ago
This has always been my idea for how I would try to extract a large amount of money if I ever managed to hack a big Defi protocol. Distract exchanges and regulators by splitting the stolen proceeds into tons of tiny amounts, send most of it to random famous accounts in small chunks, and have some of it go to my accounts which have been set up ahead of time to look like innocuous whales.
评论 #32403440 未加载
评论 #32403080 未加载
评论 #32406431 未加载
game-of-throwsalmost 3 years ago
0.1 ETH per address? That&#x27;s $168 at current prices. Someone is spending a lot of money to prove a point. Where do I sign up to get some of this &quot;dust&quot;?
评论 #32400257 未加载
评论 #32400358 未加载
评论 #32401874 未加载
评论 #32399980 未加载
jcpham2almost 3 years ago
Back in the merged mining days of bitcoin&#x2F;namecoin, there was a lot of worthless namecoin around and you didn&#x27;t exactly know what to do with it:<p>So I had the bright idea to go around collecting publicly listed namecoin addresses - bitcointalk signatures, github donation addresses, developers, you name it I think I gathered about 100 addresses<p>I wrote a bash script and put looped namedcoind to read my text file and send the minimum tx amount to a random address every second....<p>So that was running in a (detached) screen and I got busy and forgot about... for a few days...<p>Some folks didn&#x27;t think that was very funny and called it an &quot;attack&quot;
评论 #32403448 未加载
seibeljalmost 3 years ago
Why this will cause chaos is that Chainalysis and similar tools for sanctions screening are all &#x2F; nothing - if the rule was that &quot;anyone who has touched Tornado assets should be banned&quot;, then sending small amounts to everyone means that the industry has to ban everyone.<p>The point is to show the difficulty of using such a blunt tool. By the letter of the law, everyone based in the US is a criminal if they receive Tornado funds, and legally must contact the OFAC office.
评论 #32401314 未加载
评论 #32399853 未加载
spaceman_2020almost 3 years ago
Whatever else you might say about it, crypto is never boring.
mathieuborderealmost 3 years ago
Can someone explain this in English please?
评论 #32399959 未加载
评论 #32400654 未加载
评论 #32400112 未加载
评论 #32399987 未加载
yuan43almost 3 years ago
It looks like this only checks <i>one</i> of the blacklisted addresses. For the full set, see:<p><a href="https:&#x2F;&#x2F;home.treasury.gov&#x2F;policy-issues&#x2F;financial-sanctions&#x2F;recent-actions&#x2F;20220808" rel="nofollow">https:&#x2F;&#x2F;home.treasury.gov&#x2F;policy-issues&#x2F;financial-sanctions&#x2F;...</a><p>Blacklists have been a topic in Bitcoin for ages. The problem with a blacklist is that in principle, identity creation is easy. Tornado team gets just one new address, and it&#x27;s whack-a-mole time for Treasury.<p>I doubt this will work out the way Treasury thinks it will.
评论 #32408374 未加载
Hnusalmost 3 years ago
Can somebody more knowledgeable confirm if all your coins will become forever tainted if you are &quot;dusted&quot; like this? As there is no way how to break ever break the paper trail using just bitcoin is only way how to make your coins clean going to monero and back again or something like that? Are techniques determining if your coins are tainted or not on exchanges where they could be refused or confiscated sophisticated enough to not flag you in cases like these? Even if its possible I imagine its computationally expensive.
评论 #32400036 未加载
评论 #32401162 未加载
评论 #32400070 未加载
nicboualmost 3 years ago
A bit of context: <a href="https:&#x2F;&#x2F;web3isgoinggreat.com&#x2F;?id=tornado-cash-added-to-us-sanctions-list" rel="nofollow">https:&#x2F;&#x2F;web3isgoinggreat.com&#x2F;?id=tornado-cash-added-to-us-sa...</a>
dudeman6969almost 3 years ago
So what? If North Koreans stand outside of the mall and make it rain dolla bills and you pick one up doesn’t mean you are now a criminal. This is dumb as hell
geriksonalmost 3 years ago
What&#x27;s the context? &quot;Poisoning the well&quot; by associating these addresses with Tornado.cash?
rufusroflpunchalmost 3 years ago
This will be a great test of how decentralized the ethereum ecosystem actually is.
评论 #32400474 未加载
zionicalmost 3 years ago
This outcome was as obvious as it was inevitable.<p>There is no mechanism in crypto to reject incoming funds, and all the top addresses are public.<p>Anyone could easily send the top 100,000 wallets “tainted” crypto.
评论 #32399822 未加载
评论 #32402292 未加载
评论 #32402865 未加载
评论 #32399769 未加载
sva_almost 3 years ago
So this just solidifies&#x2F;removes any doubt the US&#x27;s opinion that Tornado is merely used by criminals?
Tepixalmost 3 years ago
Related: How many tornado cash forks have been deployed and how long will it take to blacklist them?
评论 #32403195 未加载
评论 #32401729 未加载
评论 #32400127 未加载
paulpauperalmost 3 years ago
It&#x27;s easy to handle dust transactions. There are many ways of going about it, such as disregarding transactions that have certain parameters. Binance&#x27;s wallets are not threatened by this.
londons_explorealmost 3 years ago
I believe this hyperlink might have a sanctioned address in it, and therefore puts HN and readers at risk of violating US sanctions, or creating reporting requirements, if distributed...<p>Sanctions list excerpt: <a href="https:&#x2F;&#x2F;home.treasury.gov&#x2F;policy-issues&#x2F;financial-sanctions&#x2F;recent-actions&#x2F;20220808" rel="nofollow">https:&#x2F;&#x2F;home.treasury.gov&#x2F;policy-issues&#x2F;financial-sanctions&#x2F;...</a>
评论 #32399814 未加载