Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

101–110 of 381 posts

Re: Bybit loses $1.5B in hack

#101
post #11

From the article: > The wallet in question appears to have sent 401,346 ETH ($1.1 billion) as well as several other iterations of staked ether (stETH) to a fresh wallet, which is now liquidating mETH and stETH on decentralized exchanges, etherscan shows. The wallet has sold around $200 million worth of stETH so far. If you showed me a paragraph like this a decade ago and told me it was from 2025, I would have a diffi…

Crypto shenanigans were happening in 2015, even as far back as 2010, so I would have to absolutely believed you to hear that it continues happening, as crypto is a fundamentally unstable platform.

Re: Bybit loses $1.5B in hack

#103
I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

Re: Bybit loses $1.5B in hack

#104

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this type of problem contributed to the exploit. BTC TXs are simple enough that all HW wallets can basically display what's happening, but with turing-complete arbitrary computations in EVM this becomes very difficult.

Re: Bybit loses $1.5B in hack

#105
post #37
post #16

The entirety of the cryptocurrency world is so obviously a "Chesterton's Fence" situation. Every pseudo-intellectual thinks that the fiscal world is "too complicated" and they're going to "simplify" it by making some token, only for people to realize that the monetary world is just complicated , and they have to reinvent everything that already existed in the traditional banking system. I had to do some work on an AC…

The crypto community continues to speed run the history of traditional finance. [1] https://news.ycombinator.com/item?id=31777761

It's only a matter of time until we get a railroad track laying network secured by proof of railroad track (PoRT) and recreate the panic of 1873.

Re: Bybit loses $1.5B in hack

#106

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”?

Put differently, it’s been seventeen years of constant and escalating mayhem. What would finally be enough to shake your faith?

Re: Bybit loses $1.5B in hack

#107
post #98

Earlier quoted context omitted.

It was an offline multi-sig wallet. Hackers seem to have musked the transaction when the owners signed it as it looked good to them.

Wow it must have been really musked then, huh?

A “musked” transaction consists of payload obfuscation and spoofing, more often than not malicious actors create a genuine looking UI with legit transaction details, while being malicious underneath.

It’s basically phishing at a transaction signing level.

I only found the term a few weeks ago and thought I was the one left out, sorry for not defining it earlier.

It’s got an eerie ring to it though, right?

Re: Bybit loses $1.5B in hack

#108
Can someone even explain what Bybit is actually about? I searched around when the hack was announced, but I'm very confused. Mostly what I saw said "scam" on it.

This isn't your run-of-the-mill Coinbase style exchange, right?

Re: Bybit loses $1.5B in hack

#109

Can someone even explain what Bybit is actually about? I searched around when the hack was announced, but I'm very confused. Mostly what I saw said "scam" on it. This isn't your run-of-the-mill Coinbase style exchange, right?

It's the second largest crypto exchange by volume globally, behind Binance. Specialized in derivatives but they have lots of regular retail products that you might find at Coinbase. Basically like a bigger version of Coinbase from Asia.

Re: Bybit loses $1.5B in hack

#110

Bybit CEO Ben Zhou wrote on X that a hacker "took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address." "Control" has a specific meaning under UCC Article 12, which was ratified in 2022 and is slowly being adopted by U.S. states. It links some rights to control/possession of keys, even if a blockchain asset may have been stolen before being sold, https:/…

[dead]
Post reply on HN