Live data from Hacker News

Bybit loses $1.5B in hack

tradingview.com

321–330 of 381 posts

Re: Bybit loses $1.5B in hack

#321

Earlier quoted context omitted.

It's easy to agree with this position if you deliberately ignore that the "service" crypto provides is a decentralized, censorship-resistent, self-contained, global system of finance that is designed specifically for the modern internet age and which does not need to be under the control of any particular nation-state or company in order to function. Otherwise, it is clear where the value comes from.

Do you think Buffett isn't aware of these things?

Probably. That guy is really old.

Re: Bybit loses $1.5B in hack

#322

Earlier quoted context omitted.

I saw a quote somewhere: >Crypto is speedrunning the entire evolution of finance to end up at the same place

I saw a quote somewhere: Those who don't learn from history are doomed to repeat it. The only thing new about crypto is paper has been replaced by electrons. Individuals/banks minting their own money has been tried before. It didn't go well.

[deleted]

Re: Bybit loses $1.5B in hack

#323

Earlier quoted context omitted.

You might be interested in reading Warren Buffett's reasoning for not investing in crypto. Basically he says crypto produces no goods, products or services, and it's only value comes from finding a "bigger fool" to pay a higher price than you did for it. It's value is from speculation assuming future speculation will assume more future speculation

It's easy to agree with this position if you deliberately ignore that the "service" crypto provides is a decentralized, censorship-resistent, self-contained, global system of finance that is designed specifically for the modern internet age and which does not need to be under the control of any particular nation-state or company in order to function. Otherwise, it is clear where the value comes from.

Yeah yeah yeah, then why everyone is losing their shit when the amount of worthless, centralized dollars they can buy per one Bitcoin decreases? Hmmm...

Re: Bybit loses $1.5B in hack

#324

Earlier quoted context omitted.

I'm not too sure but few things come to mind: 1. Upgrade protocol to include protections for well known cold wallets held by exchanges (ex: API call has to be made to the exchange's security endpoint to validate each transaction out of the wallet. Exchange staff would need to manually allowlist large transactions before they are transmitted). 2. Decentralized voting on reversal of transactions (90-95%+ vote needed to…

> 2. Decentralized voting on reversal of transactions (90-95%+ vote needed to reverse to avoid 51% attacks) Couldn't you technically just 'git checkout' a previous commit from before the fraudulent transaction occurred and pretend it never happened? Isn't the real problem that you'd have to convince a majority of users to do the same?

The DAO experiment ended this way. Once an exploit started siphoning tokens to a new fund, that same exploit allowed anyone the same maneuver. Fixing an exploit is changing the rules, and the experiment would have ended in deadlock without it.

Re: Bybit loses $1.5B in hack

#325
post #273

Earlier quoted context omitted.

Tether is an absolutely remarkable business, indeed. Basically an unregulated bank that pays no interest and follows no KYC/AML/ABC/CTF rules (because they just deal with wholesale, and then the Tethers are transacted on some permissionless "who, me?" blockchain). Remarkable dereliction of responsibility. I don't understand why we let them get away with it.

Yes, that's the concept of crypto. Uncensorable transactions. USDT is used in many countries that have capital controls, shoddy banks, or simply no proper payment infrastructure. Stablecoins work on week ends and are settled instantly. It's a superior form of money compared to what your average bank proposes. And of course that stablecoin providers conduct AML and KYC when you redeem/mint them. It's like complaining…

Selectively censorable. Tether has the ability to freeze any address, and has been making use of it for quite a while now.

Re: Bybit loses $1.5B in hack

#326

Earlier quoted context omitted.

A huge problem with signing EVM transactions using hardware wallets is that is common to be blind signing messages. The device has no knowledge of the SAFE EVM contract functions or any other context, it just asks you to sign an gobblygook opaque binary message so you may have no idea what's being signed, is my experience using multiple different vendor HW wallets. Not sure if that's what happened, but possible this…

Thanks for spelling this out, the explanation makes a lot of sense. You'd think they could at least show a blockie representing the contract, or reputational party who cryptographically vouched for it.

Sometimes you have the right contract, but an attacker is making you pass in different parameters than you think. The most popular hardware wallets don't help you with this; the Ledger Nano S for example just alerts you that you're passing some kind of data to the contract, so you're relying on your computer to show the details. This is a problem when, for example, you're interacting with a token or wallet contract, and you think you're telling it to transfer $ to Alice, but actually it's $$$$ to Bob.

But there are better options with larger screens, which actually display contract parameters on the secure device.

Re: Bybit loses $1.5B in hack

#327

Earlier quoted context omitted.

> with turing-complete arbitrary computations in EVM this becomes very difficult. I have very limited knowledge about EVM, but those computations are bounded by gas, right? Evaluating them is a finite process.

What you suggest is possible (evaluate the side effects of the transaction and present that information to the prospective signer). But at present they don't do that. I'm not sure about this specific case but often it's just a supplied text string (that can say anything) that's displayed. Basically the system depends on trust in whatever came up with the transaction payload.

You can at least display the parameters that you're passing into a contract function. That keeps you from getting hacked when interacting with a well-known trustworthy contract.

Re: Bybit loses $1.5B in hack

#328

Earlier quoted context omitted.

Yes, the profits are insane in that business. Binance was raided for a similar amount, and paid it out easily. Mtgox was raided for ₿650k ($60B in today's money), and plans to return ₿140k to traders. However, I believe most Mtgox investors are better off this way because they were forced to hold onto their investments; otherwise, they would have sold at around $1,000 or so.

This loss is more than 5% of their holdings.. To me that implies the supposed benefit of crypto is nonexistent. If an institution is making so much money off your crypto assets that they can return 5% of them, they are a bank doing whatever it was that was so evil.

Institution is making money from trading fees which are not too high percentage wise. But the trading activity is very high, for many reasons. A lot more people can participate, from all over the world. Some use it to circumvent sanctions. Some enjoy day trading (no need to deposit $25000, as with US stocks). There are literally millions of instruments to trade. Some like to write algorithms, arbitrage, market making etc. Some dream of 1000x returns (and few do get them).

Re: Bybit loses $1.5B in hack

#329

Earlier quoted context omitted.

The original idea with crypto was that the "code" was so strong, it removed the need for physical banks, tellers, FDIC, law enforcement, etc. The theory was, we can have everything the banking system has, but cheaper, because the only way to steal money was to break the crypto itself, hence "code is law". The industry cannot appeal to the protections of law enforcement, civil tort, and other features of the regulated…

> The original idea with crypto was that the "code" was so strong, it removed the need for physical banks, tellers, FDIC, law enforcement, etc. Is this really an accurate characterization of "the original idea"? And according to whom?

The Bitcoin paper pretty heavily alludes to this, though behind the guise of censorship resistant currency, which is exactly the same concern.

I personally know of at least one person who was able to escape Russia at the very beginning of the Ukraine war because cryptocurrency was a viable way for his brother in America to fund his escape despite sanctions and other hurdles.

Re: Bybit loses $1.5B in hack

#330

Earlier quoted context omitted.

Yes we definitely should have left all the sector unregulated or else how would we make a profit?

I never said that it should be unregulated, just that the sanction applied to BUSD had a political motive. Of course stablecoins are not securities, just like a 20$ note isn't a security.

The analogy to cash feels a bit strained. There's a difference in backing, don't you think?
Post reply on HN