There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...
Here is what the CEO wrote on X: "Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold…
Bybit loses $1.5B in hack
231–240 of 381 posts
Re: Bybit loses $1.5B in hack
#232Earlier quoted context omitted.
How it it different from what banks do? (Except for a central regulator.)
FEDS can print money while Binance does not
Re: Bybit loses $1.5B in hack
#233[flagged]
I see this quote repeated here often, but working in the industry I've never heard it said unironically by any of my peers or thought leaders in the space. Best I can tell it is a sort of lazy straw man repeated by skeptics. Does it have an origin?
The industry cannot appeal to the protections of law enforcement, civil tort, and other features of the regulated banking system, without simultaneously undermining the "crypto" part. If you're going to summon authorities when hackers hack, you're no better off than if you just acted like any other bank and stored the client's balance in an excel sheet.
Re: Bybit loses $1.5B in hack
#234Earlier quoted context omitted.
Most of the trading is not done by retail traders but at much lower fees than that, if not being paid (market makers). I just can't make it add up.
I know! As I stated, > Even considering a huge part of that volume is coming from institutional players who enjoy significantly reduced commission rates... But the volume is huge. Even if we take the best publicly shared MM rates from Bybit (which is 1.5bp taker commission, 0.5bp maker rebate), and assume the whole volume is traded with these rates, it is still 1bp from 40B dollars, which is 4M dollars daily.
Re: Bybit loses $1.5B in hack
#235Earlier quoted context omitted.
A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…
> with turing-complete arbitrary computations in EVM this becomes very difficult. I have very limited knowledge about EVM, but those computations are bounded by gas, right? Evaluating them is a finite process.
Re: Bybit loses $1.5B in hack
#236How on earth is it possible they can cover a 1.5B loss? Are they really sitting on that much profit, or is the goal to ponzi it out from here, MtGox style?
Re: Bybit loses $1.5B in hack
#237Earlier quoted context omitted.
bybit makes $100 million a month and has substantial excess reserves
A lot more money than the majority of AI startups and it is creating jobs rather than purposefully destroying them.
Re: Bybit loses $1.5B in hack
#238Re: Bybit loses $1.5B in hack
#239Society has devolved a bit when not long ago a heist like this would involve sieging Nakatomi Plaza, now it takes just finding a bug in someone's defective Python codes.
You don't even have to break into a wierd high-tech vault to get an unreasonably slow (or fast) billion-dollar progress bar with a snazzy custom UI toolkit these days. Not sure if technology or inflation is most to blame!
Re: Bybit loses $1.5B in hack
#240Earlier quoted context omitted.
What? It's my personal opinion which I explicitly pre-qualified. Why do you care what I think? Move on and live your life.
Just curious, how think.