Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

291–300 of 381 posts

Re: Bybit loses $1.5B in hack

#291
post #273

Earlier quoted context omitted.

You pay 1% on Coinbase because they are a quasi monopoly due to regulation. Offshore exchanges take less than 0.1% usually. The neutral rate for perps is 10%, which is lower than the credit card borrowing rate in the USA. And nothing prevents retail investors to earn it by shorting while holding spot. Last, Tether is crypto's most profitable business, and likely the world's most profitable if you account on $ of prof…

Tether is an absolutely remarkable business, indeed. Basically an unregulated bank that pays no interest and follows no KYC/AML/ABC/CTF rules (because they just deal with wholesale, and then the Tethers are transacted on some permissionless "who, me?" blockchain). Remarkable dereliction of responsibility. I don't understand why we let them get away with it.

Presumably for the same reason the US let offshore banks get away with creating Eurodollars in the past: It's useful to maintain the status of the US dollar as the currency of global trade.

This utility has always been at odds with the (relatively recent in comparison to Eurodollars, as far as I understand) desire to and ability of the US government to use USD financial rails as a political tool via sanctions.

Re: Bybit loses $1.5B in hack

#292

Earlier quoted context omitted.

That's because they're mistaken. In traditional banking only the central authority can print money, not the individual banks. If someone stole a trillion dollars from JP Morgan, JP Morgan can't make themselves whole by creating a new trillion dollars. The central authority might guarantee the customers of JP Morgan that their money is protected, but they won't print money to make the bank whole.

False. Banks create money. https://en.wikipedia.org/wiki/Money_creation

Banks create money by issuing loans; but they can't create money out of thin air if $1.5B was stolen from them.

Re: Bybit loses $1.5B in hack

#293

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

In almost all cases EVM smart contract interaction looks like a function call which can be easily decoded into JSON if you know ABI.

HW wallet doesn't need to understand the contract logic, it just needs ABI, which is generally a simpler task. Also it can show the name of function you're calling as selector is a hash of a name.

Safe is a bit more complex as it also wraps it in EIP-712 message, but that can also be decoded in a systematic way.

Re: Bybit loses $1.5B in hack

#294

Earlier quoted context omitted.

It's possible to make stable-coins using just price oracle and collateral. Most attempts at "algorithmic" stable coins have failed. See TerraDollar, Luna and Titan.

Over-collateralized stables are different from "algorithmic": the algorithmic ones are not fully backed by reserves.

They are very capital inefficient and still can fail during black swan events.

Re: Bybit loses $1.5B in hack

#295

Earlier quoted context omitted.

You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?

I'm not too sure but few things come to mind: 1. Upgrade protocol to include protections for well known cold wallets held by exchanges (ex: API call has to be made to the exchange's security endpoint to validate each transaction out of the wallet. Exchange staff would need to manually allowlist large transactions before they are transmitted). 2. Decentralized voting on reversal of transactions (90-95%+ vote needed to…

Ethereum is programmable, such a protocol can be implemented as a smart contract.

Re: Bybit loses $1.5B in hack

#296
post #16

The entirety of the cryptocurrency world is so obviously a "Chesterton's Fence" situation. Every pseudo-intellectual thinks that the fiscal world is "too complicated" and they're going to "simplify" it by making some token, only for people to realize that the monetary world is just complicated , and they have to reinvent everything that already existed in the traditional banking system. I had to do some work on an AC…

I don’t know anyone working in crypto who complains about the physical world being too complex. Imaginary dragons are easily slayed.

If you read the original bitcoin paper, it complains about bank centralization and “issues” with traditional finance for a not-insignificant amount of it, and presents cryptocurrency as a solution.

I will admit I used a bit of shorthand, but the paper is providing a “simple” solution to a “complex” problem.

Re: Bybit loses $1.5B in hack

#297

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

Here is what the CEO wrote on X: "Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold…

One of the links says the following:

> According to crypto security firm Groom Lake, a Safe multisig wallet was deployed on Ethereum in 2019 and on the Base layer-2 in 2024 with identical transaction hashes. Ethereum’s alphanumeric transaction hashes are 64 characters long, so deploying the same smart contract transaction hash twice should be mathematically impossible.

> The same transaction hash appearing on both Ethereum and Base indicates an attacker could have found a way to make a single transaction valid on more than one network or could be reusing crypto wallet signatures or transaction data across networks, pseudonymous Groom Lake researcher Apollo said.

Re: Bybit loses $1.5B in hack

#298

Earlier quoted context omitted.

[flagged]

Yes we definitely should have left all the sector unregulated or else how would we make a profit?

They didn't regulate the crypto industry. They told everyone to stop and then refused to provide regulations or guidance on acceptable behavior despite continual begging by coinbase et al. to be allowed to cooperate.

Re: Bybit loses $1.5B in hack

#299

Earlier quoted context omitted.

How it it different from what banks do? (Except for a central regulator.) Your exception is the answer. Only the central regulator can "mint" money and doing so has real world consequences. The central regulator has financial incentives to limit this sort of activity. The bizarro world of crypto has no such regulation and as a result, it is inherently unstable. The proof of this is right in front of you --- it is the…

I saw a quote somewhere: >Crypto is speedrunning the entire evolution of finance to end up at the same place

I sure hope we don't end up in the same place where the monetary system is only being held up by the fact that there is more debt than money creating an endless competition for the limited quantity of money that exists in order to pay off ever-increasing debts and expenses with a currency that is continually debased throughout the process.

Re: Bybit loses $1.5B in hack

#300

Earlier quoted context omitted.

How it it different from what banks do? (Except for a central regulator.)

How it it different from what banks do? (Except for a central regulator.) Your exception is the answer. Only the central regulator can "mint" money and doing so has real world consequences. The central regulator has financial incentives to limit this sort of activity. The bizarro world of crypto has no such regulation and as a result, it is inherently unstable. The proof of this is right in front of you --- it is the…

They are being loaned ETH to cover withdrawals and prevent what would amount to a bank run, not stablecoins. This entire comment chain is stupid and pointless.
Post reply on HN