• Web3 developer Brian Guan lost $40,000 after accidentally posting his wallet’s secret keys publicly on GitHub, with the funds being drained in just two minutes.
  • The crypto community’s reactions were mixed, with some offering support and others mocking Guan’s previous comments about developers using AI tools like ChatGPT for coding.
  • This incident highlights ongoing debates about security practices and the role of AI in software development within the crypto community.
  • darklamer@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 months ago

    The developer said he forgot that his secret keys were in the repository.

    If you have your secret keys in your repository you’ve already fucked up, long before you accidentally make that repository public.

    • BrianTheeBiscuiteer@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      One of the first things you should do in a repo is add a .gitignore file and make sure there are rules to ignore things like *secret* or *private* etc. Also, I pretty much never use git add . because I don’t like the laziness of it and EVERY TIME one of my coworkers checked in secrets they were using that command.

  • Johanno@feddit.de
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    They made 2 errors.

    1. Use crypto

    2. Storing the key anywhere close to the repo.

  • k_rol@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    I’m sad I didn’t see any comments saying he shouldn’t be using a $40k wallet key to test his software in the first place. Anything could happen with simple code mistakes…just get an empty wallet or one with a few bucks in it.

  • dhork@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    I have no sympathy for him, if he is a crypto developer he knows how important those private keys are. And he also knows people scrape public areas all the time looking for keys just like that. The whole point of crypto is to be immutable, so that money is simply lost to him now.

    He seems to know how much of a dumb mistake that was, although his description of himself was a bit more colorful.

    • FiniteBanjo@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      5 months ago

      Some speculate that AI assisting him in programming could have made the error, in which case I hope he gets fucked by it again in the future.