Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

71–80 of 381 posts

Re: Bybit loses $1.5B in hack

#71

Earlier quoted context omitted.

What is the gullibility here?

Thinking you can store your crypto with some 3rd party that _definitely_ won't get hacked (or """hacked"""), also thinking your crypto won't become worthless from a singular unusual event. Actually the most gullible are the people who think of cryptocurrency as an "investment" XD

I don't know. I always store my crypto offline. I bought $1000 worth of bitcoin when it was less than $100 per bitcoin because it seemed like something that could get big at some point, and I was willing to risk $1000 on that thought.

My thought was it will some day either be worth a lot or be worth 0 and I'm OK with both of those possibilities. I don't really think I was gullible about anything and yes I thought about it as a risky investment that turned out to pay off quite well.

Re: Bybit loses $1.5B in hack

#72
post #11

From the article: > The wallet in question appears to have sent 401,346 ETH ($1.1 billion) as well as several other iterations of staked ether (stETH) to a fresh wallet, which is now liquidating mETH and stETH on decentralized exchanges, etherscan shows. The wallet has sold around $200 million worth of stETH so far. If you showed me a paragraph like this a decade ago and told me it was from 2025, I would have a diffi…

[flagged]

Re: Bybit loses $1.5B in hack

#73

Society has devolved a bit when not long ago a heist like this would involve sieging Nakatomi Plaza, now it takes just finding a bug in someone's defective Python codes.

You just gotta trust the wrong people.

Don’t forget FTX willingly hired the Ultimate Bet “god mode” guy.

Re: Bybit loses $1.5B in hack

#74

Earlier quoted context omitted.

What are you talking about in 2010?

https://en.bitcoin.it/wiki/Value_overflow_incident Other transactions besides the one that created 184 billion BTC in that block was effectively “rolled back” on the working chain.

Thank you.

Re: Bybit loses $1.5B in hack

#75

Earlier quoted context omitted.

What is the purpose of this comment?

It describes the legal status of stolen cryptocurrency changing after the first sale. This HN story is about stolen cryptocurrency. In particular: > The wallet has sold around $200 million worth of stETH so far If some of those sales took place within jurisdiction of a U.S. state that has ratified UCC Article 12, then the buyer of the stolen cryptocurrency is now the new legal owner.

The hacked coins are not "free of conflicting property claims."

Re: Bybit loses $1.5B in hack

#77
There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were.

eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices?

https://archive.ph/YMZrq

https://blockworks.co/news/bybit-hack-raises-security-questi...

Re: Bybit loses $1.5B in hack

#78

Earlier quoted context omitted.

It describes the legal status of stolen cryptocurrency changing after the first sale. This HN story is about stolen cryptocurrency. In particular: > The wallet has sold around $200 million worth of stETH so far If some of those sales took place within jurisdiction of a U.S. state that has ratified UCC Article 12, then the buyer of the stolen cryptocurrency is now the new legal owner.

The hacked coins are not "free of conflicting property claims."

> The hacked coins are not "free of conflicting property claims."

2023, American Bar Association, https://www.americanbar.org/groups/business_law/resources/bu...

  .. “take free” regime introduced by the 2022 UCC Amendments for these assets.  Under these rules, a person who acquires a CER for value, in good faith and without notice of any conflicting property claims, is deemed a “qualifying purchaser” and, as such, takes it free from any preexisting property claims.  

  The 2022 UCC Amendments draw heavily from the UCC Article 3 provisions for negotiable instruments, and these provisions have the effect of making CERs negotiable.  It follows that if a secured creditor obtained a security interest in CER inventory and only perfected by filing, that creditor would be at risk of the debtor disposing of the collateral and transferring control to a qualifying purchaser that would take it free from any competing claim.

Re: Bybit loses $1.5B in hack

#79
post #4

[flagged]

I see this quote repeated here often, but working in the industry I've never heard it said unironically by any of my peers or thought leaders in the space. Best I can tell it is a sort of lazy straw man repeated by skeptics. Does it have an origin?

Re: Bybit loses $1.5B in hack

#80
post #41

What are the chances that a Bybit insider is behind this?

Or former insider. I spent several years pointing out to my last employer that every former employee could have walked off with secrets that allowed them access to our backends. The were already slowly working on hardening write access but read access was still being worked on a couple months before I left, when I got to write about half of the last mile code for the user facing bits. This is not a unique experience…

Are these business-owned exchanges and managed wallets not fundamentally incompatible with making guarantees of security? Is anyone doing it the "right" way and what does the right way even look like?
Post reply on HN