Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

201–210 of 381 posts

Re: Bybit loses $1.5B in hack

#201

Earlier quoted context omitted.

What action can be taken? There's no law against getting hacked or being a moron.

There is a law against gross negligence. Holding client money comes with other obligations too.

It’s not money though. It’s property at best. It doesn’t get held to the same standards.

CryptoBros are all about “no laws, do whatever” right up until the, inevitable, point at which /they/ are getting swindled and then they want to cry foul and run to the authorities.

It’s just like the whole DAO situation which showed “Crypto is immutable and we want to live and die by the code unless of course someone finds a flaw in the code and steals our money, then we will roll back the immutable chain to recover it” what a farce.

Re: Bybit loses $1.5B in hack

#202

Who says ByBit can cover the loss? The article title says that but the article quotes do not. The CEO only said that their other cold wallets are intact and that withdrawals remain normal. Bybit claims to be regulated by the Virtual Assets Regulatory Authority of Dubai.[1] But the lookup page at VARA says they only have "In-principle approval", not a full license. "Applicants holding an IPA are strictly prohibited fr…

> Who says ByBit can cover the loss? CEO on X

When has the CEO of a cryptocurrency exchange ever lied before?

What possible motivation would he have to not tell the truth, the whole truth, and nothing but the truth?

Harumph!!!

Gentleman, please, rest your sphincters!

https://www.youtube.com/watch?v=g2Bp8SqYrnE

Re: Bybit loses $1.5B in hack

#203
post #189
post #140

Earlier quoted context omitted.

There are cryptocurrencies in which transactions must be signed by both sender and receiver, such as those implementing the pure Mimblewimble protocol. > Both the sender and receiver need to sign after the first transaction has been mined That makes no sense; miners don't mine transactions unless they're guaranteed to be valid. All signing must be done before transactions are even published. Otherwise one could DoD-a…

What does DoD stand for, in this context?

I think they meant DoS.

Re: Bybit loses $1.5B in hack

#204

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

My faith would shake when scams, rugs, fraud, and ponzis completely stop outside of crypto.

Re: Bybit loses $1.5B in hack

#205

Earlier quoted context omitted.

For what it’s worth, I’m a “crypto believer” and I have never considered ease of use to be one of its selling points. What you are describing are the systems of power which create a stable financial system. That is, one where you can put a nickel into a bank account and expect it to be there in a year or a hundred years. That indeed requires a complex web of power structures, because its top line goal is to be stable…

> Crypto provides the exact opposite value: it cannot be controlled, no matter how robust your power structure is. It can be insured, at a significant cost, but not controlled. This is such a naive claim parroted by crypto enthusiasts. Lots of criminal things can't be 'controlled' (e.g. stopping people murdering, stealing, etc.), but there are consequences if you do them. Crypto could easily be controlled by laws or…

You wouldn't be the first person to pump and dump their own turds.

Some people even brand their own turds with their own name, and drop a $TRUMP and dump.

Re: Bybit loses $1.5B in hack

#206

Earlier quoted context omitted.

In the face of the never-ending list of these kinds of events, the laughably impossible task of average nontechnical individuals protecting their own assets (and the consequence of total financial ruin when they fail to do so), the overwhelming number of and size of scams, rug pulls, fraud, outright Ponzi schemes, and on and on and on… what exactly is left to keep anyone a “huge believer”? Put differently, it’s been…

> what exactly is left to keep anyone a “huge believer”? I don't really engage in the ponzibucks part and don't touch exchanges except to on and off-ramp, and use crypto to pay for things like hosting, seedboxes, or other services I might not necessarily want my debit card directly attached to. I like sending vendors $100 and spending $0.00005 in transaction fees and knowing that they'll get $100 (or $99 with some 3r…

Your transfer fees are a bit off.

Coinbase is 10,200x more than you stated ($0.51 to send $100) BUT that’s only if I send directly on Coinbase. Coinbase Commerce takes 1% so it would actually be 20,000x more than you listed.

Stripe is 64% of what you stated ($3.20), and that’s with no processing fee discounts like you can get with higher volume.

Now, obviously, $3.20 > $1 but it’s not apples to apples. You can claw back your money with a card for one. there are many cases where I would prefer to pay the extra $2.20.

Re: Bybit loses $1.5B in hack

#207
post #148

How on earth is it possible they can cover a 1.5B loss? Are they really sitting on that much profit, or is the goal to ponzi it out from here, MtGox style?

Bybit trading volume is in tens billions of dollars daily. Their comission rate for the retail traders is up to 10bp (0.1%). Even considering a huge part of that volume is coming from institutional players who enjoy significantly reduced commission rates, I think they're surely making few million dollars daily on comissions alone, maybe tens of millions in a good day. And besides comissions, they also have other sour…

I'm nowhere near expert on any of the things below, but: My gut tells me if an exchange makes as much money as you suggest, people involved in that exchange are making even more profit from the said exchange, otherwise they wouldn't engage. The whole thing being literally money out of thin air, it feels like a huge bubble that should inevitably burst bringing down _ a lot _ of collaterals with it.

Re: Bybit loses $1.5B in hack

#208
post #18
post #4

[flagged]

^Yep When you decentralize finance like this what becomes okay to do according to system rules is exactly what is possible to do according to system rules. We don't have humans in that loop anymore to enforce moral judgments about what constitutes unlawful theft (except for 1 or 2 rare "hard-forks" of various blockchains to reverse devastating transactions). I feel bad for people who lose large volumes of cryptocurre…

Being doomed to spending millions of real dollars litigating to buy a trash dump full of used diapers and toxic waste, just to dig around in it looking for a hard disk drive for the rest of your life, seems to be a particularly satisfying Sisyphean form of justice.

https://en.wikipedia.org/wiki/Bitcoin_buried_in_Newport_land...

Re: Bybit loses $1.5B in hack

#209
post #189
post #140

Earlier quoted context omitted.

There are cryptocurrencies in which transactions must be signed by both sender and receiver, such as those implementing the pure Mimblewimble protocol. > Both the sender and receiver need to sign after the first transaction has been mined That makes no sense; miners don't mine transactions unless they're guaranteed to be valid. All signing must be done before transactions are even published. Otherwise one could DoD-a…

What does DoD stand for, in this context?

Department of Defense; after the research funding cuts, the bureaucrats had to get creative about money sources.

Re: Bybit loses $1.5B in hack

#210

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

https://x.com/tayvano_/status/1847877011462901915 This thread has some info about very similar past attacks, should give some insights into the level of sophistication that goes into something like that.

This was interesting, thanks!
Post reply on HN