Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

141–150 of 381 posts

Re: Bybit loses $1.5B in hack

#141
post #132
post #94

Earlier quoted context omitted.

It's definitely embarrassing that people losing their shirts in crypto didn't see it coming. It's bad that people think a zero sum game is worth playing against incumbents. The marks aren't the worst part, though. Everyone promoting memecoins and utility-free cryptocurrency in general is either ignorant or just a bad person with a warped idea of success. Personal money accumulation is a sad goal compared to actual we…

> memecoins and utility-free cryptocurrency As opposed to what?

Bitcoin, ETH, and Monero all have utility in one way or another. Bitcoin is accepted by most black markets (and Monero is even better for privacy). And software is built on top of the ETH chain. No one is buying stuff using DOGE or Trump coin. There's a clear difference between memecoins and legitimate cryptocurrencies whether you like them or not.

Re: Bybit loses $1.5B in hack

#142

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

> with turing-complete arbitrary computations in EVM this becomes very difficult.

I have very limited knowledge about EVM, but those computations are bounded by gas, right? Evaluating them is a finite process.

Re: Bybit loses $1.5B in hack

#144

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

They've seen other people make loads of money (or maybe made a load themselves) and are still in the game hoping to make loads more.

Re: Bybit loses $1.5B in hack

#145

Earlier quoted context omitted.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

> What would finally be enough to shake your faith? Crypto scams run by top government officials? Oh, wait...

and the existence of financial scams isn't the same for fiat because...?

Re: Bybit loses $1.5B in hack

#146

Who says ByBit can cover the loss? The article title says that but the article quotes do not. The CEO only said that their other cold wallets are intact and that withdrawals remain normal. Bybit claims to be regulated by the Virtual Assets Regulatory Authority of Dubai.[1] But the lookup page at VARA says they only have "In-principle approval", not a full license. "Applicants holding an IPA are strictly prohibited fr…

They're probably just saying that to avoid a run.

Re: Bybit loses $1.5B in hack

#147
These are not hacks, just like Mtgox, Celsius, FTX etc etc etc were not hacks. These are crypto insiders supporting the stablecoin so they can print and set a floor on prices before/during potential mass sell off events.

Re: Bybit loses $1.5B in hack

#148

How on earth is it possible they can cover a 1.5B loss? Are they really sitting on that much profit, or is the goal to ponzi it out from here, MtGox style?

Bybit trading volume is in tens billions of dollars daily. Their comission rate for the retail traders is up to 10bp (0.1%). Even considering a huge part of that volume is coming from institutional players who enjoy significantly reduced commission rates, I think they're surely making few million dollars daily on comissions alone, maybe tens of millions in a good day. And besides comissions, they also have other sources of profit, like staking, crediting customers, and forced liquidations.

Being a crypto exchange in current market is very profitable. If the crypto itself does not collapse, I think it's totally possible for them to repay that sum in a year or less.

Re: Bybit loses $1.5B in hack

#149

Earlier quoted context omitted.

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

> with turing-complete arbitrary computations in EVM this becomes very difficult. I have very limited knowledge about EVM, but those computations are bounded by gas, right? Evaluating them is a finite process.

But the space of their effects on the Blockchain state is vast. You need software to translate those effects to a form human can interpret as "what I want"/"not what I want".

Ie. engineering work needs to happen in the UI they used to confirm the tx

Re: Bybit loses $1.5B in hack

#150
post #16

The entirety of the cryptocurrency world is so obviously a "Chesterton's Fence" situation. Every pseudo-intellectual thinks that the fiscal world is "too complicated" and they're going to "simplify" it by making some token, only for people to realize that the monetary world is just complicated , and they have to reinvent everything that already existed in the traditional banking system. I had to do some work on an AC…

For what it’s worth, I’m a “crypto believer” and I have never considered ease of use to be one of its selling points. What you are describing are the systems of power which create a stable financial system. That is, one where you can put a nickel into a bank account and expect it to be there in a year or a hundred years. That indeed requires a complex web of power structures, because its top line goal is to be stable…

> Crypto provides the exact opposite value: it cannot be controlled, no matter how robust your power structure is. It can be insured, at a significant cost, but not controlled.

This is such a naive claim parroted by crypto enthusiasts. Lots of criminal things can't be 'controlled' (e.g. stopping people murdering, stealing, etc.), but there are consequences if you do them.

Crypto could easily be controlled by laws or punitive taxes. KYC is a step in that direction. But still this claim keeps coming out. All they need to do is control the off-ramps.

It's like the one "but, but, there will only ever be a fixed amount of BTC, so it's valuable!". There will only ever be a fixed amount of my turds, but I don't see them up for auction. It also doesn't explain why BTC is the valuable one but not all the clones (spoiler: it's the brand name).

It's easier to just parrot some grifter's justifications than actually thinking for yourself I guess.

Post reply on HN