Vitalik Buterin pfp
Vitalik Buterin
@vitalik.eth
People who work in large corporate settings where things like this are a risk, do you have any existing rules or standardized best practices for how to minimize the risk? https://twitter.com/RichardHanania/status/1754257428198416393
46 replies
31 recasts
419 reactions

christopher pfp
christopher
@christopher
yes, it’s called approval levels. e.g. you need your manager, whom has a $500,000 approval limit, to approve anything. any more than that you need their manager to approve until you get to the board
1 reply
0 recast
3 reactions

Gilly pfp
Gilly
@gilly
@vitalik.eth - we (Coinbase) follow strict procedures. No one, not even Brian can ask for a wire payment to be made without it following a predefined process.
0 reply
0 recast
1 reaction

Nelson pfp
Nelson
@nelsonmckey
Sure. Make everybody click through a mindless training video every 90 days. I’m sure somebody is already hard at work making a new course on deepfakes.
0 reply
0 recast
0 reaction

Chad🎩 pfp
Chad🎩
@chad
nothing that is full-proof im sure crypto fixes this
0 reply
0 recast
0 reaction

Grindr.eth🎩(formerly Http) pfp
Grindr.eth🎩(formerly Http)
@zuccschini
Hi Vitalik! I love you btw (hope this doesn’t come off as weird) You are inspirational 🥺
0 reply
0 recast
2 reactions

BK 🎩 pfp
BK 🎩
@basedken
Segregation of duties and multiple approval levels. A transaction of this amount would go through multiple management levels within multiple departments
0 reply
0 recast
1 reaction

Whitetail pfp
Whitetail
@whitetail
Strict cash control processes would usually involve the CFO. Always need have maker and checker
1 reply
0 recast
1 reaction

Penelope 🎩 pfp
Penelope 🎩
@aitoolsdegen.eth
Geesh, if gonna send that much, might as well go meet them actually in person on flight and/or have someone vet them for realz. Didn't think it would have reached so quickly to this point.
0 reply
0 recast
0 reaction

Alex Blagirev pfp
Alex Blagirev
@dvorkin01
looks weird. 😏 simple treasury control procedure with multisig with CEO / CFO and Head of Legal or third party custody service should be a regular plain/vanilla risk practice. But I can offer some advisory on this for sure. paid in #eth #agix or #degens ofc.
0 reply
0 recast
0 reaction

Fitz pfp
Fitz
@fits
Multiple approvers and approval thresholds per level (<50k, 250k 1m+ etc). Encoded in enterprise accounting software so enforced by software rules. This particularly scam was strange for cos the value should require multiple (at least 3 levels of approval. More potent scam is 1000’s of low value invoices submitted.
0 reply
0 recast
0 reaction

Matt TFG pfp
Matt TFG
@matttfg
People is the weakest part of the chain
0 reply
0 recast
0 reaction

Shanyé pfp
Shanyé
@shanye
I am under the impression that Bitcoin solves this
0 reply
0 recast
0 reaction

Lux_V 🔵 🎩 pfp
Lux_V 🔵 🎩
@lux-v
Human interaction is irreplaceable. For sums of that amount, most corps require dual signatories. Trust, but verify, just like on chain.
0 reply
0 recast
0 reaction

Calc.eth pfp
Calc.eth
@calc
They for sure just missing standard practices, shouldnt happen ever even with AI. - Gap duration for payments from Authorisation > Approval. - Larger multi M payments need multiple higher level authorisation. - Approved addresses for payments authorised by separate parties. Trilllion other ways
0 reply
0 recast
0 reaction

gary pfp
gary
@gensler
proof of identity
0 reply
0 recast
0 reaction

Andrew pfp
Andrew
@andrewgoldsky
The best solution they've come up with is a four hour long cybersecurity training course that you can skip over using a browser plugin
0 reply
0 recast
0 reaction

Andrei O. pfp
Andrei O.
@andrei0x309
On what was the call? It's better to use MS Teams, Slack, or even Discord with roles. Anything with enclosed spaces that are harder to penetrate. Using software that does not have designated spaces(and is meant for any kind of communication) will obviously increase the risk.
0 reply
0 recast
0 reaction

the pfp
the
@worden
This isn't really a risk for those who have up to date systems. New ERPs (like Workday) have built in signatory policies. E.g. An employee logs in and submits the payment request, their manager needs to log in and approve it, then their VP... SVP, CFO, and then probably CEO for $25 million.
0 reply
0 recast
0 reaction

Rich Widmann pfp
Rich Widmann
@richwidmann
As a former white collar corruption lawyer who helped companies investigate and thwart this activity a few things included a separation of duties, aggressive training and awareness about social engineering threats, process deceleration (adding checks/multi factor approvals to slow velocity of transactions)
0 reply
0 recast
0 reaction