Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

311–320 of 381 posts

Re: Bybit loses $1.5B in hack

#311
post #260

Earlier quoted context omitted.

Note that Coinbase (like most exchanges) charges retail clients outrageously high fees (orders of magnitude more than you would pay at a competitive FX or equity broker), but institutional and whales that trade a lot very small fees. Yet another way crypto moves money from poor suckers to insiders.

You just described volume-based discounts. What’s so wrong with that? It’s the same reason why buying a single soda at a convenience store cost more (per unit) than buying a large pack at Costco.

Try to become an insider at one of these exchanges even with a couple million dollars. See how it goes.

This is like Coke ONLY giving discounts to Costco instead of anywhere else so that Costco can reap the rewards. Walmart, Target, they can all pay full price.

The convenience store spends more money to package individual items. A crypto transaction is the difference of a keystroke. They are not comparable on many fronts.

Re: Bybit loses $1.5B in hack

#312

Earlier quoted context omitted.

Here is what the CEO wrote on X: "Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold…

One of the links says the following: > According to crypto security firm Groom Lake, a Safe multisig wallet was deployed on Ethereum in 2019 and on the Base layer-2 in 2024 with identical transaction hashes. Ethereum’s alphanumeric transaction hashes are 64 characters long, so deploying the same smart contract transaction hash twice should be mathematically impossible. > The same transaction hash appearing on both Et…

The quote is incorrect. If I deploy the same smart contract to two different EVM chains, from the same wallet, with the same nonce (pretend it's the first transactions I'm doing with this wallet on each chain, so nonce 0), then the transaction hash will be the same on both chains. That's not odd.

Re: Bybit loses $1.5B in hack

#313

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

Here is what the CEO wrote on X: "Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold…

They could have used a hardware wallet like the Lattice1 from GridPlus, which actually shows the function parameters on a big screen instead of blind signing.

Re: Bybit loses $1.5B in hack

#314

There's some info and speculation in these two (distinct) articles, but I'd love to know technical details of where the gaffs were. eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines / hardware devices? https://archive.ph/YMZrq https://blockworks.co/news/bybit-hack-raises-security-questi...

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

[deleted]

Re: Bybit loses $1.5B in hack

#315

Earlier quoted context omitted.

I saw a quote somewhere: Those who don't learn from history are doomed to repeat it. The only thing new about crypto is paper has been replaced by electrons. Individuals/banks minting their own money has been tried before. It didn't go well.

However, this quote is usually intended to be a warning, not an opportunity to run all the old scams again. These people hear it and think "You mean we get to repeat history?!"

It’s not an uncommon joke about how easy it would be to be a serial killer or bank robber in “the olden days” - just need to move 1 town over and you can do it all again which has a strong similarity to being able to commit crypto crimes with hardly a consequence by virtue of doing it across jurisdictions..

Re: Bybit loses $1.5B in hack

#316

Earlier quoted context omitted.

You might be interested in reading Warren Buffett's reasoning for not investing in crypto. Basically he says crypto produces no goods, products or services, and it's only value comes from finding a "bigger fool" to pay a higher price than you did for it. It's value is from speculation assuming future speculation will assume more future speculation

It's easy to agree with this position if you deliberately ignore that the "service" crypto provides is a decentralized, censorship-resistent, self-contained, global system of finance that is designed specifically for the modern internet age and which does not need to be under the control of any particular nation-state or company in order to function. Otherwise, it is clear where the value comes from.

Do you think Buffett isn't aware of these things?

Re: Bybit loses $1.5B in hack

#317
post #215
post #207

Earlier quoted context omitted.

I'm nowhere near expert on any of the things below, but: My gut tells me if an exchange makes as much money as you suggest, people involved in that exchange are making even more profit from the said exchange, otherwise they wouldn't engage. The whole thing being literally money out of thin air, it feels like a huge bubble that should inevitably burst bringing down _ a lot _ of collaterals with it.

Yeah, as a layman this MSTR explainer was an "aha" moment for me: No, what is likely happening with all the convertible bond issues is that MicroStrategy prices the bonds in a manner to attract market neutral hedge fonds, meaning arbitrageurs. Saylor has briefly mentioned these firms, as opposed to firms seeking actual Bitcoin exposure. For issue after issue, they can be spotted as the largest bond holders by anyone…

https://www.oneweirdkerneltrick.com/polytope.pdf

Re: Bybit loses $1.5B in hack

#318

Earlier quoted context omitted.

I saw a quote somewhere: >Crypto is speedrunning the entire evolution of finance to end up at the same place

I sure hope we don't end up in the same place where the monetary system is only being held up by the fact that there is more debt than money creating an endless competition for the limited quantity of money that exists in order to pay off ever-increasing debts and expenses with a currency that is continually debased throughout the process.

We crossed that point years ago. It's the stablecoins that hold all the debt and use it to back their "dollars."

Re: Bybit loses $1.5B in hack

#319

I'm a huge crypto believer but I can admit that we don't have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.

You like decentralized money without laws and accountability, but would like to have a central thing (TBD) that is accountable and respect laws? How would that work?

I think the move is less having a central thing and more advancing wallet and multisig technology. ByBit was pretty reckless by using a simple majority multisig to hold $1.5b. At that level you should probably have a few speed bumps. Like, maybe a majority of signatures allows you to make a proposal, but you can only accept the proposal after a couple hours, which would give you the chance to see the malicious transaction and bail on it.

Something like that would probably be overkill for individuals, but most people would definitely benefit from some added on chain bureaucracy regarding how their accounts are managed. And yes, for many this would lead to a system that isn't notably less centralized than the traditional banking system. But people would at least have a choice as to where their wallets gets to sit on the bureaucracy complete freedom spectrum. And even if they end up closer to the bureaucracy end, they'd have a lot more flexibility and lower administrative fees than what they currently have.

Re: Bybit loses $1.5B in hack

#320

Earlier quoted context omitted.

There is a law against gross negligence. Holding client money comes with other obligations too.

It’s not money though. It’s property at best. It doesn’t get held to the same standards. CryptoBros are all about “no laws, do whatever” right up until the, inevitable, point at which /they/ are getting swindled and then they want to cry foul and run to the authorities. It’s just like the whole DAO situation which showed “Crypto is immutable and we want to live and die by the code unless of course someone finds a fla…

From the beginning, they also feared contact with the underworld. People so familiar with the asymmetry between attackers and defenders online fail to imagine how that looks in real life. Considering the upfront cost of a rubber hose, a year's supply of heroin, Ensure (prevents bedsores) and maybe sodium pentothal: when $1.5 B hits the news, you need to be able to prove: it's gone; North Korea is protecting the proceeds; and you're back to being indistinguishable from an innocent tax payer.

This explains strategically erratic behavior in communities like loot crate gambling. The low end and high end can rely on state protection. The center of the curve needs to look like a problematic target, and maybe draw attention to their competitors.

Post reply on HN