Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

121–130 of 381 posts

Re: Bybit loses $1.5B in hack

#121

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

> what exactly is left to keep anyone a “huge believer”?

Bias. I expect believers to have earned a profit or still hold significant quantities of crypto assets.

But in their favor, trust in any currency is the foundation of its value. States create it by collecting taxes and paying employees. Crypto currencies generally lack that heavy weight central authority, so they kind of have to believe to the point where they get burned.

Re: Bybit loses $1.5B in hack

#122

Earlier quoted context omitted.

Solutions have existed for years (eg Gnosis Safe), they just aren’t being used by that exchange.

Bybit was quite literally using Gnosis Safe for the compromised wallet.

I can't believe someone posted that without knowing they actually used Gnosis Safe

Re: Bybit loses $1.5B in hack

#123

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

https://x.com/tayvano_/status/1847877011462901915 This thread has some info about very similar past attacks, should give some insights into the level of sophistication that goes into something like that.

Re: Bybit loses $1.5B in hack

#124

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

> What would finally be enough to shake your faith?

Crypto scams run by top government officials? Oh, wait...

Re: Bybit loses $1.5B in hack

#125
post #119

There should be something like a "finalizing transaction", which both the sender and receiver need to sign after the first transaction has been mined, i.e. like an in-built escrow. If it's not signed by both, then funds are returned. This wouldn't protect against key leakage, but in this case, the tx was signed by accident. This would also protect against sending to wrong address.

This would also protect againts dusting attacks.

Illicit addresses sending to thousands of random recipients and making them all marked by automated KYC systems.

Re: Bybit loses $1.5B in hack

#126

Earlier quoted context omitted.

You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?

I'm not too sure but few things come to mind: 1. Upgrade protocol to include protections for well known cold wallets held by exchanges (ex: API call has to be made to the exchange's security endpoint to validate each transaction out of the wallet. Exchange staff would need to manually allowlist large transactions before they are transmitted). 2. Decentralized voting on reversal of transactions (90-95%+ vote needed to…

This is getting pretty close to the banking system, at which point one needs to ask - maybe just improve existing protocols?

Re: Bybit loses $1.5B in hack

#127

Society has devolved a bit when not long ago a heist like this would involve sieging Nakatomi Plaza, now it takes just finding a bug in someone's defective Python codes.

You don't even have to break into a wierd high-tech vault to get an unreasonably slow (or fast) billion-dollar progress bar with a snazzy custom UI toolkit these days. Not sure if technology or inflation is most to blame!

Re: Bybit loses $1.5B in hack

#128
Who says ByBit can cover the loss? The article title says that but the article quotes do not. The CEO only said that their other cold wallets are intact and that withdrawals remain normal.

Bybit claims to be regulated by the Virtual Assets Regulatory Authority of Dubai.[1] But the lookup page at VARA says they only have "In-principle approval", not a full license. "Applicants holding an IPA are strictly prohibited from initiating operations, conducting any virtual asset activities, or servicing clients until they have obtained their full VASP licence from VARA."

Uh oh.

[1] https://www.vara.ae/en/licenses-and-register/public-register...

Re: Bybit loses $1.5B in hack

#129
post #35

I wouldn't be surprised if Bybit cuts a deal with the hacker to return the funds. There's no way that $1.46 billion of marked ETH can be liquidated and off-ramped to fiat.

That’s well within the daily trading volume.

Well within real daily trading volume is less clear.

https://www.forbes.com/sites/javierpaz/2022/08/26/more-than-...

Post reply on HN