Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

111–120 of 381 posts

Re: Bybit loses $1.5B in hack

#111
post #94

Earlier quoted context omitted.

It's definitely embarrassing that people losing their shirts in crypto didn't see it coming. It's bad that people think a zero sum game is worth playing against incumbents. The marks aren't the worst part, though. Everyone promoting memecoins and utility-free cryptocurrency in general is either ignorant or just a bad person with a warped idea of success. Personal money accumulation is a sad goal compared to actual we…

Yeah on memecoins isn’t that just a loophole for running naked pyramid schemes? I.e. a pyramid where everyone knows it’s a pyramid. Like the weird part about a pyramid is that depending on your risk tolerance it may actually make sense to participate in a pyramid even if everyone involved knows it’s a pyramid. So are that many people being scammed as in tricked (seems hard to believe), or is it just a risky form of g…

I've never purchased crypto or had any involvement but acquaintances I know have used that exact argument. They know it's a pyramid but believe they can get ahead because they were in early enough.

They are usually a lot more vague when I ask about their realized gains.

Re: Bybit loses $1.5B in hack

#112

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

Thanks for spelling this out, the explanation makes a lot of sense.

You'd think they could at least show a blockie representing the contract, or reputational party who cryptographically vouched for it.

Re: Bybit loses $1.5B in hack

#113
post #72
post #11

From the article: > The wallet in question appears to have sent 401,346 ETH ($1.1 billion) as well as several other iterations of staked ether (stETH) to a fresh wallet, which is now liquidating mETH and stETH on decentralized exchanges, etherscan shows. The wallet has sold around $200 million worth of stETH so far. If you showed me a paragraph like this a decade ago and told me it was from 2025, I would have a diffi…

[flagged]

And only a few weeks ago the lawsuit started payout the 'early lump sum' repayment option for creditors.

Re: Bybit loses $1.5B in hack

#115

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?

Re: Bybit loses $1.5B in hack

#117

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

Solutions have existed for years (eg Gnosis Safe), they just aren’t being used by that exchange.

Re: Bybit loses $1.5B in hack

#118

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

Solutions have existed for years (eg Gnosis Safe), they just aren’t being used by that exchange.

Bybit was quite literally using Gnosis Safe for the compromised wallet.

Re: Bybit loses $1.5B in hack

#119
There should be something like a "finalizing transaction", which both the sender and receiver need to sign after the first transaction has been mined, i.e. like an in-built escrow. If it's not signed by both, then funds are returned. This wouldn't protect against key leakage, but in this case, the tx was signed by accident. This would also protect against sending to wrong address.

Re: Bybit loses $1.5B in hack

#120

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?

I'm not too sure but few things come to mind:

1. Upgrade protocol to include protections for well known cold wallets held by exchanges (ex: API call has to be made to the exchange's security endpoint to validate each transaction out of the wallet. Exchange staff would need to manually allowlist large transactions before they are transmitted).

2. Decentralized voting on reversal of transactions (90-95%+ vote needed to reverse to avoid 51% attacks)

Post reply on HN