create account

Bots and hot-wallets don't mix + privacy concerns. by edicted

View this thread on: hive.blogpeakd.comecency.com
· @edicted ·
$43.70
Bots and hot-wallets don't mix + privacy concerns.
<center>![bot.jpg](https://images.hive.blog/DQmdRAdodqmPQWkazHkgTTWnHVeMVo5QcPqX9toFGmpXebH/bot.jpg)</center>

Just now someone on Twitter was complaining that Hive withdrawals on Binance are locked up.  This can happen for various reasons, including maintenance, bugs, low RCs, frozen accounts, or whatever else. 

<center>![image.png](https://images.hive.blog/DQmQLcFL7UiMAFGXLVHsMyS9Di6ei8o7gWEmPLFXiuhcYCo/image.png)</center>

Sure enough the last transfer out happened over 9 hours ago. It's quite noteworthy to mention that this is the first time I've noticed that the Binance hot wallet only has 308 Hive Power. And of that 308 HP, 204 of those are delegated. 

### How crazy is that? 
Binance runs an entire @binance-hot wallet will less stake powered up than a minnow... that's pretty insane. Especially considering that transactions are free and they only charge 0.01 Hive to move money through a pseudo-anonymous hot-wallet.  Best deal ever. 

### So who's delegating to @binance-hot? 
Deep dive...

<center>![t1.png](https://images.hive.blog/DQmP4yUFrzokNeWdhkTaKAbW1nKx6KyY2rCuyRzYLss5WMp/t1.png)</center>

* @theycallmedan
* @gandalf

#### lol, there has to be a story there. 
Did @binance-hot really run out of RCs so the top brass delegated them some coins?  Yikes.  Hilarious. Power up more Hive, Binance: you cheapskates!

#### But then I saw something horrifying: 

<center>![t1.png](https://images.hive.blog/DQmVpSyR9ejLmvAfZitbc6JwfnTouhecsvjgyDiGESCPiaE/t1.png)</center>

# OH NO! 
Someone sent 1212.676 Hive to @token-converter (whatever that is) in order to get DEC coins, but the @token-coverter HiveEngine bot didn't have that much DEC and automatically sent the money back to the sender... which was the @binance-hot wallet.  Crap. 

As a reminder, the only account that is supposed to send funds to @binance-hot is @deepcrypto8.  We send our money to @deepcrypto8 with the correct memo that signifies our Binance account. The money then gets transferred to the hot wallet and credited to our account after the block becomes immutable (20 blocks; 1 minute). 

According to Binance corporate policy (and all exchanges really) money that gets sent to the wrong wallet or with the wrong memo is "lost forever".  They have to make an exception via support to reverse any of these botched transactions.  I'm not sure how often that happens but plenty of people on Coinbase have been burned by sending ERC-20 tokens to their ETH wallet.  Always make sure that an exchange actually supports the coin you're sending them. 

So yeah I would be very curious to know whether or not this person can get their 1212.676 Hive back or if the Binance arcade is going to eat the quarter. 

It should just go without saying: don't let this be you.  Don't interact with bots directly with a hot-wallet; that's just asking for trouble. Also, @token-coverter... fix your bot: you should never send funds to @binance-hot or any other exchange wallet for any reason.  Just a little taste of how early in the game we are for so many mistakes like this to be made at once. Perfect storm. 

<center>![heartlove.png](https://images.hive.blog/DQmbUzBVM3TarnPQnqchh7RvPcXJiDxNzp7rAsaVt2pVYF2/heart-love.png)</center>

This situations actually reminds me of my [Love Handles](https://peakd.com/hive-167922/@edicted/love-handles) dapp idea where users could buy and sell Hive accounts like NFTs. The only reason to use a hot-wallet like this is for the pseudo-anonymous privacy that hot-wallets provide (either that or just outright laziness).  

There is no way to know who sent money where because millions of users have access to the same hot-wallet.  The only way to know is to have direct access to Binance servers, and last I checked very few people in this world actually have those permissions. 

On top of that Binance has no KYC, so even if someone did have access to the database the only identifying information contained therein is going to be an email address and IP addresses.  It all depends on context.  That might be plenty of information for the CIA but completely worthless to the IRS.  The IRS is woefully underfunded by design, even if Biden is promising them more funding. 

[This is why using a hot-wallet is likely even more private than using a mixing service.](https://peakd.com/hive-167922/@edicted/bitcoin-mixing-and-tumbling-the-poor-man-s-exchange)  Millions of people use hot-wallets.  Very few people use mixing services and those services are constantly being cracked down on by regulators.  

Imagine going to a coffee shop, connecting to a vpn, logging into Binance with an email you just created.  You move Hive from Binance to Huobi, from Huobi to Ionomy, from Ionomy to a couple of random Hive accounts.  If someone was trying to track this money they'd need cooperation from Binance, Huobi, and Ionomy.  Hm yeah, probably not going to happen. 

If they try to trace the IP address directly they need to get the VPN server to cooperate, only to figure out that you did all your business at a coffee shop.  Are they then going to go to the coffee shop and ask for video footage?  These are things that FBI, NSA, or CIA agents could do if they were committed enough... but the IRS?  C'mon.  Get real. White collar victimless crime is the easiest kind of crime to get away with for a reason.  Just sayin. Rules are for suckers.  Everyone at the top knows that.  [This is the Wild West.](https://peakd.com/blockchain/@edicted/the-blockchain-wild-west-gold-rush) 

<center>![privacyprivatekeylock.jpg](https://images.hive.blog/DQmf3Sh5MSCQ9Wa1ZibJ4tWdqWYc9PcTvG9zCDWMNLC2PmN/privacy-private-key-lock.jpg)</center>

### Privacy matters 
But even more importantly, privacy is a pretty big deal even though the vast majority of people would prefer to remain completely legit.  The whole "I have nothing to hide" argument has been debunked a thousand times over.  Especially in crypto where the laws (some a century old) make zero sense and the development/expansion will explosively outpace regulations.  The friction is real.  Prepare for explosions. 

This is exactly why Hive needs more privacy.  When someone changes their owner key there has to be some kind of expectation that the owner of that account could have legitimately changed. This is exactly why the ability to buy and sell accounts like NFTs is so essential to the network. Anyone should be able to change their owner key and have the slate wiped clean, so to speak. 

Another thing that could help Hive privacy is multi-sig (which we are actually working on).  When multiple parties control the money in question it becomes much harder to track.  For example, ~~my~~ our @hextech witness account is controlled by the entire team.  When money moves around it's impossible to know which one of us signed the transaction.  I think it's pretty crazy and cool that this is even possible on Hive.  It sure as hell isn't on most networks. 

So how many users have access to @edicted's owner / active / posting / memo keys?  Non of ya business; that's a private matter.  Respect my privacy.  Thanks. 

### Conclusion
* Don't use hot-wallets to play around with bot services. 
* Privacy matters. 
* We are still very early in the game. 

Posted Using [LeoFinance <sup>Beta</sup>](https://leofinance.io/@edicted/bots-and-hot-wallets-don-t-mix-privacy-concerns)
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 225 others
properties (23)
authoredicted
permlinkbots-and-hot-wallets-don-t-mix-privacy-concerns
categoryhive-167922
json_metadata{"app":"leofinance/0.2","format":"markdown","tags":["bots","binance","palnet","proofofbrain","leofinance","privacy"],"canonical_url":"https://leofinance.io/@edicted/bots-and-hot-wallets-don-t-mix-privacy-concerns","links":["https://peakd.com/hive-167922/@edicted/love-handles","https://peakd.com/hive-167922/@edicted/bitcoin-mixing-and-tumbling-the-poor-man-s-exchange","https://peakd.com/blockchain/@edicted/the-blockchain-wild-west-gold-rush"],"image":["https://images.hive.blog/DQmdRAdodqmPQWkazHkgTTWnHVeMVo5QcPqX9toFGmpXebH/bot.jpg","https://images.hive.blog/DQmQLcFL7UiMAFGXLVHsMyS9Di6ei8o7gWEmPLFXiuhcYCo/image.png","https://images.hive.blog/DQmP4yUFrzokNeWdhkTaKAbW1nKx6KyY2rCuyRzYLss5WMp/t1.png","https://images.hive.blog/DQmVpSyR9ejLmvAfZitbc6JwfnTouhecsvjgyDiGESCPiaE/t1.png","https://images.hive.blog/DQmbUzBVM3TarnPQnqchh7RvPcXJiDxNzp7rAsaVt2pVYF2/heart-love.png","https://images.hive.blog/DQmf3Sh5MSCQ9Wa1ZibJ4tWdqWYc9PcTvG9zCDWMNLC2PmN/privacy-private-key-lock.jpg"]}
created2021-06-04 19:27:21
last_update2021-06-04 19:27:21
depth0
children5
last_payout2021-06-11 19:27:21
cashout_time1969-12-31 23:59:59
total_payout_value24.260 HBD
curator_payout_value19.444 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length7,344
author_reputation2,887,606,064,196,067
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,132,565
net_rshares71,219,451,891,535
author_curate_reward""
vote details (289)
@hivebuzz ·
Congratulations @edicted! You have completed the following achievement on the Hive blockchain and have been rewarded with new badge(s) :

<table><tr><td><img src="https://images.hive.blog/60x70/http://hivebuzz.me/@edicted/payout.png?202106042253"></td><td>You received more than 49000 HP as payout for your posts and comments.<br>Your next payout target is 50000 HP.<br><sub>The unit is Hive Power equivalent because your rewards can be split into HP and HBD</sub></td></tr>
</table>

<sub>_You can view your badges on [your board](https://hivebuzz.me/@edicted) and compare yourself to others in the [Ranking](https://hivebuzz.me/ranking)_</sub>
<sub>_If you no longer want to receive notifications, reply to this comment with the word_ `STOP`</sub>



**Check out the last post from @hivebuzz:**
<table><tr><td><a href="/hivebuzz/@hivebuzz/pud-202106-feedback"><img src="https://images.hive.blog/64x128/https://i.imgur.com/zHjYI1k.jpg"></a></td><td><a href="/hivebuzz/@hivebuzz/pud-202106-feedback">Feedback from the June 1st Hive Power Up Day</a></td></tr></table>

###### Support the HiveBuzz project. [Vote](https://hivesigner.com/sign/update_proposal_votes?proposal_ids=%5B%22109%22%5D&approve=true) for [our proposal](https://peakd.com/me/proposals/147)!
properties (22)
authorhivebuzz
permlinkhivebuzz-notify-edicted-20210604t232311000z
categoryhive-167922
json_metadata{"image":["http://hivebuzz.me/notify.t6.png"]}
created2021-06-04 23:23:12
last_update2021-06-04 23:23:12
depth1
children0
last_payout2021-06-11 23:23:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,260
author_reputation367,875,206,484,874
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,135,933
net_rshares0
@jfang003 ·
$0.03
I also wonder if that person will get back their HIVE. I am guessing they could talk to Binance and eventually they might get things fixed but that will be depend on what whether they want to address the issues.

Posted Using [LeoFinance <sup>Beta</sup>](https://leofinance.io/@jfang003/re-edicted-odga7)
👍  ,
properties (23)
authorjfang003
permlinkre-edicted-odga7
categoryhive-167922
json_metadata{"app":"leofinance/0.2","format":"markdown","tags":["hive-167922","leofinance"],"canonical_url":"https://leofinance.io/@jfang003/re-edicted-odga7"}
created2021-06-05 00:10:39
last_update2021-06-05 00:10:39
depth1
children0
last_payout2021-06-12 00:10:39
cashout_time1969-12-31 23:59:59
total_payout_value0.014 HBD
curator_payout_value0.014 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length304
author_reputation431,646,912,600,339
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,136,526
net_rshares84,237,776,036
author_curate_reward""
vote details (2)
@rishi556 ·
$0.10
binance's hot wallet ran out of RC at one point and thats why they have those delegations.
👍  ,
properties (23)
authorrishi556
permlinkre-edicted-qu6zj4
categoryhive-167922
json_metadata{"tags":["hive-167922"],"app":"peakd/2021.05.5"}
created2021-06-04 19:30:42
last_update2021-06-04 19:30:42
depth1
children0
last_payout2021-06-11 19:30:42
cashout_time1969-12-31 23:59:59
total_payout_value0.050 HBD
curator_payout_value0.045 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length90
author_reputation111,982,053,527,065
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,132,606
net_rshares275,774,867,792
author_curate_reward""
vote details (2)
@shortsegments ·
I was hoping that that person would get their Hive back, so I am happy to read yabamatts comment. This stuff is complicated, and Hive is less complicated then other crypto.
Thanks for the info.
properties (22)
authorshortsegments
permlinkqu9qb0
categoryhive-167922
json_metadata{"app":"hiveblog/0.1"}
created2021-06-06 07:04:12
last_update2021-06-06 07:04:12
depth1
children0
last_payout2021-06-13 07:04:12
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length193
author_reputation587,980,080,574,576
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,160,950
net_rshares0
@yabapmatt ·
$0.03
token-converter is a Splinterlands-related service and we'll get that fixed, and I've already made sure the user behind that transaction got their DEC tokens so we will eat the loss. We've chained a bunch of services together to allow people to buy DEC tokens with a bunch of other cryptos and it's hard to always stay on top of all of the issues that can arise ahead of time.

Basically players can choose a crypto they want to use to buy DEC and it gives them a deposit address which is through the SimpleSwap.io service. SimpleSwap will use Binance to trade their token for HIVE which is sent to @token-converter which then deposits the HIVE to Hive Engine, trades it for DEC in the diesel pool, and sends the DEC to the player's Splinterlands account.
👍  
properties (23)
authoryabapmatt
permlinkre-edicted-qu7jey
categoryhive-167922
json_metadata{"tags":["hive-167922"],"app":"peakd/2021.05.5"}
created2021-06-05 02:40:09
last_update2021-06-05 02:40:09
depth1
children0
last_payout2021-06-12 02:40:09
cashout_time1969-12-31 23:59:59
total_payout_value0.012 HBD
curator_payout_value0.013 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length755
author_reputation151,480,345,982,709
root_title"Bots and hot-wallets don't mix + privacy concerns. "
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id104,138,428
net_rshares73,713,807,282
author_curate_reward""
vote details (1)