Shashank’s Newsletter

Share this post

The CryptoBowl

0xshash.substack.com

The CryptoBowl

This is Shashank’s Newsletter, a newsletter with bite sized content on everything that happened in web3 over the past week.

Shashank Reddy
Feb 20, 2022
1
Share this post

The CryptoBowl

0xshash.substack.com

In today’s email,

🏈 Crypto ads raining during Superbowl

🥷 Most sophisticated social engineering hack

🐞 Coinbase's largest-ever bug bounty

🔒 Canada freezes bank accounts

🤑 Cryptopunk sells for 23M$

🐇 RabbitHole raises 18M$


Weekly gainers

source: tokenterminal

🏈 Crypto ads raining during Superbowl

Twitter avatar for @fintechfrank
Frank Chaparro @fintechfrank
Similarweb report on one day traffic gain across crypto platforms that ran ads during the Super Bowl
Image
11:06 AM ∙ Feb 18, 2022
92Likes8Retweets

Eye catching commercials with top celebrities like LeBron James and Larry David appeared in crypto ads highlighting a push to create more mainstream awareness for crypto. Coinbase tried something a bit different with a celeb-less QR code for their ad eventually crashing their site.

At ~$6.5M for 30sec commercial, a whopping $30M+ was spent putting crypto on the big stage. So, how did this budget translate to traffic? The numbers are out and Similarweb traffic insights suggest that FTX was the clear winner of the pack. Checkout this great thread on the rough math behind these huge marketing spends.

🥷 Most sophisticated social engineering hack

Twitter avatar for @thomasg_eth
thomasg.eth @thomasg_eth
For the past two weeks, I've been targeted in an extremely thorough social engineering scam that nearly cost me all of my ETH. I'm super lucky to have made it through unscathed. Here's the story 👇
12:53 AM ∙ Feb 13, 2022
27,883Likes8,198Retweets

As more money flows into crypto, scammers are flocking to really sophisticated techniques. So what happened here? A team of well funded hackers gained the trust of an early stage crypto founder by joining his discord and offering help for his project. They apparently even outsourced the work to a technical contractor to actually create 3D models for his project. 🤯 Once they gained his trust over several weeks, they started the attack by sending an NFT to his wallet and asking him to stake it on their web3 app. Luckily, the founder was highly technical and inspected the code to find out that they were actually taking the approval of aETH (Aave ETH) instead of the token it claimed to take approval of. It’s important to note here that the founder was able to mitigate this hack by actually inspecting public and open source code unlike traditional black box phishing attacks.

Takeaways: Token approvals can be dangerous and users need to be more conscious of giving approvals to smart contracts. Also, hackers have grown beyond the simple “please share your private key” scams.

Tip: Use Tornado cash to keep your transactions and token holdings private making it harder to be targeted. Stay safe out there!

🐞 Coinbase's largest-ever bug bounty

Twitter avatar for @Tree_of_Alpha
Tree of Alpha @Tree_of_Alpha
Coinbase's "largest-ever bug bounty" How a flaw in the new Advanced Trading feature would have allowed a malicious user to sell BTC or any other coin without owning them, and how Coinbase's reaction speed on a Super Bowl Friday averted a possible crisis. Bounty: $250,000
Image
12:38 PM ∙ Feb 19, 2022
3,322Likes720Retweets

Speaking about hacks, Coinbase had a white-hat hacker report a major bug in their Advanced trading API that would let users sell arbitrary tokens for BTC or any other token. The white hat hacker tested this by putting a 50 BTC limit sell order using 50 SHIB and saw it go through 😵

The reporter was able to get a direct line with Brian Armstrong and team within minutes and Coinbase stopped all advanced trading which was pretty impressive. This bug could have caused massive market moves if this attack vector was exploited on large market cap coins like BTC/ ETH. It would have had ripple effects across DeFi as several pricing oracles rely on Coinbase. All in all, I think the white hat hacker deserved much more than the 250k$ that he got 🥲

🔒 Canada freezes bank accounts

Twitter avatar for @greg_price11
Greg Price @greg_price11
This is literal madness. Canada's Deputy Prime Minister says, under the Emergencies Act, banks can immediately freeze or suspend bank accounts without a court order and be protected from civil liability. Is this still a free country?
10:04 PM ∙ Feb 14, 2022
21,090Likes6,523Retweets

There is a huge on-going protest by truckers against the Canadian Government’s Covid policies. In response to truckers blocking the roads, the government declared an Emergency Act ordering all financial institutions to FREEZE the bank accounts of any person directly or indirectly involved in the protests without any court orders. This is not happening in Vietnam or North Korea, this is happening in a free democracy in Canada, a G-7 country known for its extremely good nature.

People have always under estimated the risk of financial censorship and have always believed self-custody to be default suspicious. This needs to change and people should embrace and protect self-custody wallets where they can have true financial freedom as part of their constitutional rights. Highly recommend reading the entire thread by @punk6529 which is absolute gold.

🤑 Cryptopunk sells for 23M$

Twitter avatar for @nftsalesbot
Flip McBot @nftsalesbot
👀 0x7eb2..3f6b ↗️ flipped ↗️ CRYPTOPUNK #5822 🏆 status: Diamond Hands 🛒 in: 0.08 ETH 💰 out: 8,000 ETH 😬 hodl: 4 years 7 months 3 days Ξ profit: +7,999.92 ETH 🔥 💲paid: $19 (07/2017) 💲made: $23,431,981 (📈 +123,326,216%) opensea.io/assets/0xb47e3…
8:31 PM ∙ Feb 12, 2022
1,598Likes390Retweets

Deepak Thapliyal, CEO of cloud Blockchain firm Chain purchased CryptoPunk #5822 for 23M$ making it the fifth largest NFT sale till date. The seller made a whopping 123k% return 🤑 making it one of the most successful trades in history. CryptoPunk #5822 is one of the 9 punks in the collection of 10,000 to have a rare avatar type: alien.

🐇 RabbitHole raises 18M$

Twitter avatar for @Flynnjamm
Brian Flynn (🐇,🎩) - ETHDenver @Flynnjamm
gm! some news today we raised $18m led by @GreylockVC & @tcg_crypto to pave the way for users to become contributors in web3 and help DAOs find contributor talent
rabbithole-gg.notion.siteNotion – The all-in-one workspace for your notes, tasks, wikis, and databases.A new tool that blends your everyday work apps into one. It’s the all-in-one workspace for you and your team
4:01 PM ∙ Feb 15, 2022
757Likes66Retweets

So what is RabbitHole? RabbitHole is a web3 app where users can earn crypto by using the most popular Ethereum applications like Aave, Graph, Uniswap etc. and build reputation while doing it. The idea is that your wallet becomes your resume. For users, it gives them the opportunity to earn tokens and unlock all kinds of access based on their transaction history. For protocols, it is a way to identify and acquire quality contributors based on their capabilities that can be verified on-chain.

This is the future of work and education —a new digital economy built on reputation and merit based behavior. University degrees, resumes, credit scores are basically just reputation which can be represented and derived using on-chain behaviors.


How did you enjoy this week’s edition?

😍 Love it 😴 Meh 😠 Hate it

Share this post

The CryptoBowl

0xshash.substack.com
Comments
TopNewCommunity

No posts

Ready for more?

© 2023 Shashank Reddy
Privacy ∙ Terms ∙ Collection notice
Start WritingGet the app
Substack is the home for great writing