Skip to content
TORNLIFE More

sieger: forum

sieger [1760232] Level 98

Forum posts (Torn's count)
30 observed
Archived posts
12
Threads started (archived)
3

Boards

From the 12 newest archived posts.

Threads started

Most-liked posts

Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.

ArmaLite - Macana high quality. Armors gone · · 1 like

More information and C/O prices will be on the 2nd post.

[image: i.imgur.com]
Dune Boots:


[image: i.imgur.com]
Riot Body:


[image: i.imgur.com]
Assault Glove
[image: i.imgur.com]
Riot Helm

[image: i.imgur.com]
ArmaLite

[image: i.imgur.com]
Macana

Bullrun Crypto Security Guide · · 1 like

All types of wallet/token/NFT hacks fall into two categories:

  1. Abuse of previously owned token approval.
  2. Private key/seed compromise.

 

[image: cdn.mos.cms.futurecdn.net]

Token Approvals:

Token approvals are essentially a permission for smart contract to access and move specific type or amount of a token from your wallet. Like giving permission to OpenSea or Uniswap to move your NFTs so you can see them.

In detail, on Ethereum network, everything except ETH is ERC-20 token. NFTs are are mostly ERC-721 and 1155 tokens respectively. Their approval mechanics work similar to ERC-20s but for NFT marketplaces.

If you are not careful about that, you might just give grant tokens permission to a malicious smart contract to get your assets stolen.

Many DeFi apps will prompt for unlimited approval of ETC20 token by default. This is to improve user experience, and it is more convenient as it does not require potential future approvals thus saving on time and gas fees.

So limiting this for max amount of tokens will fix the problem.

NFT Approvals:

NFT marketplaces will ask for that kind of approval, thus when you sell and NFT to a buyer, that marketplace’s smart contract can move the NFT automatically to the buyer. This sounds cool, but can also be used by malicious websites/contracts to steal your NFTs.

Example: When you are about to mint an NFT, from a website which looks totally legitimate, in the background their contract searches for your wallet and chooses the highest value NFT and asks for permission to take it, and when you think you are minting, you are giving away your NFT.

Limit your risk to approvals:

  • Use multiple wallets, do not sign approvals from your high value wallet.
  • Ideally reduce or completely avoid granting unlimited apprivals for ERC-20s.
  • Check and revoke approvals periodically via Etherscan or Revoke.

Hardware Wallets:

Hot wallets are connected to the internet thtough your computer or phone so the keys stored online.

Cold wallets are hardware devices where the key is generated and stored offline.

So it is a lot safer to use hardware wallet, I would suggest Coldcard mk4 for #btc, and trezor for #eth

There are some stuff to look for:

  • Buy hardware wallet only from official manufacturer website. No ebay/ no amazon…
  • Make sure the packaging is sealed.
  • First time you set it up, it will generate a seed phrase.
  • ONLY write that seed on physical paper or a steel plate so it will be fire and waterproof.
  • Never digitilize it meaning never take picture of it, never write it on any kind of keyboard.
  • This seed phrase you got when you set up is EVERYTHING. Do not forget that, and not spesific to your device, you can use that with any device.
  • If you loose it, you will loose everything.
  • Ledger / Trezor and Coldcard has the ability to add 25th word. Which sets a different address which cannot be access via the 24-word recovery phase alone, so you will be the only one who can know the word.

How People Got Hacked?

  • Tricked into downloading malware via PDFs, beta testing games, running some macros via google sheets or phishing websites.
  • Interacting with malicious contracts: FOMO minting from a mimic website, as explained above.
  • Insering or giving away the seed to customer support or something similar.

Takeaways:

  • Don’t trust, always verify. Make sure the contract address and website you are interacting with is legitimate.
  • Periodically check and revoke your token approvals via revoke and etherscan.
  • You can take advantage of Pocket Universe and Wallet Guard as the last line of defense.
  • Choose custom approval limits over the default unlimited approval option.
  • Hedge your risk by utilizing multiple wallets.
  • Utilize cold wallet and hot wallets for their purpose.

Misc Stuff:

  • Always use 2FA. Authy is great app, you can use Yubikey for the next level. Never use SMS as 2FA tho.
  • Use password manager. Then you can use all different 20 mixed characters passwords for all websites. Most people use Bitwarden, but I would suggest pass or KeepassXC.
  • You can check have I been pwned for data breaches.
  • Assume everyone online is liar or compromised.
  • Instead of using Gmail, Hotmail etc.. Use better ones like Tuta or the best, you can host your mail.
  • Never use public Wi-Fi, there can always be fake hotspot, or MIM attack.
  • If you need to use a Wi-Fi, use VPN, because any network can be hacked. For VPN I would suggest Mullvad, or even better host your own VPN.

 

The point is assume that everything you have in a how wallet is already compromised or can be at any point, so act accordingly.

What would you do? · · 0 likes

I’ve been having a lot of deep thoughts recently, I go through stages of reflection more and more often now as I get older.

 

In fighting we always used to do this exercise.

 

When a new guy had a fight coming up we’d ask them

 

“Imagine you’re fighting for the UFC title, how would you train?”

 

What would your diet be?

 

What would you do outside training?

 

Who would you spend time with?

 

What time would you wake up?

 

How hard would you train?

 

What would you spend your money on?

 

How often would you go out and get drunk at the weekend?

 

What would you do with every minute of every day?

 

They would always say the same thing… “I’d train harder than I have ever before, I’d eat perfectly, I’d be 100% focused on becoming UFC champion”

 

Then you would simply say…

 

“Great… so let’s pretend your next amateur fight is for the UFC title and you have to do everything you just described”

 

Those that followed through with it never lost.

 

Everyone thinks external things are going to help us become better versions of ourselves…

 

The reality is we become the best version of ourselves by BEING the best version of ourselves everyday.

 

Treat today like you are already better than your villain that guy who has everything he could ever dream of…

 

How does that guy walk, talk, enter a room, treat people, work, how does he live daily?

 

Then just start doing that soon you’ll realize you were that man all along.

Recent archived posts

Bullrun Crypto Security Guide ·

I think it is just commonsense, if you do not install random exe files, there wont be any problem.

Sometimes they hijack major software (like ccleaner) but soon after it will be fixed. So as a user who has half of a brain, no need to worry about that.

Bullrun Crypto Security Guide · · 1 like

All types of wallet/token/NFT hacks fall into two categories:

  1. Abuse of previously owned token approval.
  2. Private key/seed compromise.

 

[image: cdn.mos.cms.futurecdn.net]

Token Approvals:

Token approvals are essentially a permission for smart contract to access and move specific type or amount of a token from your wallet. Like giving permission to OpenSea or Uniswap to move your NFTs so you can see them.

In detail, on Ethereum network, everything except ETH is ERC-20 token. NFTs are are mostly ERC-721 and 1155 tokens respectively. Their approval mechanics work similar to ERC-20s but for NFT marketplaces.

If you are not careful about that, you might just give grant tokens permission to a malicious smart contract to get your assets stolen.

Many DeFi apps will prompt for unlimited approval of ETC20 token by default. This is to improve user experience, and it is more convenient as it does not require potential future approvals thus saving on time and gas fees.

So limiting this for max amount of tokens will fix the problem.

NFT Approvals:

NFT marketplaces will ask for that kind of approval, thus when you sell and NFT to a buyer, that marketplace’s smart contract can move the NFT automatically to the buyer. This sounds cool, but can also be used by malicious websites/contracts to steal your NFTs.

Example: When you are about to mint an NFT, from a website which looks totally legitimate, in the background their contract searches for your wallet and chooses the highest value NFT and asks for permission to take it, and when you think you are minting, you are giving away your NFT.

Limit your risk to approvals:

  • Use multiple wallets, do not sign approvals from your high value wallet.
  • Ideally reduce or completely avoid granting unlimited apprivals for ERC-20s.
  • Check and revoke approvals periodically via Etherscan or Revoke.

Hardware Wallets:

Hot wallets are connected to the internet thtough your computer or phone so the keys stored online.

Cold wallets are hardware devices where the key is generated and stored offline.

So it is a lot safer to use hardware wallet, I would suggest Coldcard mk4 for #btc, and trezor for #eth

There are some stuff to look for:

  • Buy hardware wallet only from official manufacturer website. No ebay/ no amazon…
  • Make sure the packaging is sealed.
  • First time you set it up, it will generate a seed phrase.
  • ONLY write that seed on physical paper or a steel plate so it will be fire and waterproof.
  • Never digitilize it meaning never take picture of it, never write it on any kind of keyboard.
  • This seed phrase you got when you set up is EVERYTHING. Do not forget that, and not spesific to your device, you can use that with any device.
  • If you loose it, you will loose everything.
  • Ledger / Trezor and Coldcard has the ability to add 25th word. Which sets a different address which cannot be access via the 24-word recovery phase alone, so you will be the only one who can know the word.

How People Got Hacked?

  • Tricked into downloading malware via PDFs, beta testing games, running some macros via google sheets or phishing websites.
  • Interacting with malicious contracts: FOMO minting from a mimic website, as explained above.
  • Insering or giving away the seed to customer support or something similar.

Takeaways:

  • Don’t trust, always verify. Make sure the contract address and website you are interacting with is legitimate.
  • Periodically check and revoke your token approvals via revoke and etherscan.
  • You can take advantage of Pocket Universe and Wallet Guard as the last line of defense.
  • Choose custom approval limits over the default unlimited approval option.
  • Hedge your risk by utilizing multiple wallets.
  • Utilize cold wallet and hot wallets for their purpose.

Misc Stuff:

  • Always use 2FA. Authy is great app, you can use Yubikey for the next level. Never use SMS as 2FA tho.
  • Use password manager. Then you can use all different 20 mixed characters passwords for all websites. Most people use Bitwarden, but I would suggest pass or KeepassXC.
  • You can check have I been pwned for data breaches.
  • Assume everyone online is liar or compromised.
  • Instead of using Gmail, Hotmail etc.. Use better ones like Tuta or the best, you can host your mail.
  • Never use public Wi-Fi, there can always be fake hotspot, or MIM attack.
  • If you need to use a Wi-Fi, use VPN, because any network can be hacked. For VPN I would suggest Mullvad, or even better host your own VPN.

 

The point is assume that everything you have in a how wallet is already compromised or can be at any point, so act accordingly.

What would you do? ·

I’ve been having a lot of deep thoughts recently, I go through stages of reflection more and more often now as I get older.

 

In fighting we always used to do this exercise.

 

When a new guy had a fight coming up we’d ask them

 

“Imagine you’re fighting for the UFC title, how would you train?”

 

What would your diet be?

 

What would you do outside training?

 

Who would you spend time with?

 

What time would you wake up?

 

How hard would you train?

 

What would you spend your money on?

 

How often would you go out and get drunk at the weekend?

 

What would you do with every minute of every day?

 

They would always say the same thing… “I’d train harder than I have ever before, I’d eat perfectly, I’d be 100% focused on becoming UFC champion”

 

Then you would simply say…

 

“Great… so let’s pretend your next amateur fight is for the UFC title and you have to do everything you just described”

 

Those that followed through with it never lost.

 

Everyone thinks external things are going to help us become better versions of ourselves…

 

The reality is we become the best version of ourselves by BEING the best version of ourselves everyday.

 

Treat today like you are already better than your villain that guy who has everything he could ever dream of…

 

How does that guy walk, talk, enter a room, treat people, work, how does he live daily?

 

Then just start doing that soon you’ll realize you were that man all along.

ArmaLite - Macana high quality. Armors gone ·

Done, thanks

& Slaterz Trading Inc is Buying & Selling · · 1 like

fast, easy. A+

ArmaLite - Macana high quality. Armors gone ·

B wouldnt need any c/o.

ArmaLite - Macana high quality. Armors gone ·

C/O Prices:
Dune Boots:
Riot Body:

Assault Gloves: Sold
Riot Helm:Sold
Armalite:
Macana:


Deadline: Not sure yet, but it wont be long.

ArmaLite - Macana high quality. Armors gone · · 1 like

More information and C/O prices will be on the 2nd post.

[image: i.imgur.com]
Dune Boots:


[image: i.imgur.com]
Riot Body:


[image: i.imgur.com]
Assault Glove
[image: i.imgur.com]
Riot Helm

[image: i.imgur.com]
ArmaLite

[image: i.imgur.com]
Macana

Yellow 4% Rage Macana - 35 MINUTES LEFT TO BID ·

1.62b

Yellow 4% Rage Macana - 35 MINUTES LEFT TO BID ·

1.6b

Yellow 4% Rage Macana - 35 MINUTES LEFT TO BID · · 1 like

1.44b

Are you Offended ? · · 1 like

Honestly, people are free to think whatever tf they want. Lets say someone thinks all people are insects, so what! IF someone gets offended so what?
I think getting offended is the most stupid, and meaningless thing that someone can do. Which is also only my own and my idea. So if anyone gets offended, your welcome.
But really a person should not be that weak to read something on the net, and get a complete breakdown. We should have stronger personalities, if we dont have, we have to work hard to make it stronger.

At the end of the day, who cares.