Live data from Hacker News

The $1.5B Bybit Hack

blog.trailofbits.com

11–20 of 140 posts

Re: The $1.5B Bybit Hack

#11
post #10

In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…

They should only use a computer that is air gapped to go online only when signing something. This is an op sec failure to not have this procedure

That’s precisely what happened in this attack.

They were attacked when they went online

Re: The $1.5B Bybit Hack

#12

In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…

Or, you know, employ technology that allows for mistakes to be fixed.

Re: The $1.5B Bybit Hack

#13
The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone with a missile or even destroyed a minor building or something, there would be public outrage and swift (military) repercussions.

But online, it's the wild wild west. The North Koreans can throw anything they want at your systems and the main response you get is "lol get good noob, should have built more secure systems" despite the opposing side literally having quite literally hundreds of people specifically trained to take on organisations like yours.

Not saying the Bybit people couldn't have been more careful of whatever, but let's appreciate how wild the online environment actually is sometimes.

Re: The $1.5B Bybit Hack

#14

In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…

The missing part is that you cannot apply the same procedure to 1 ETH as you would to 1k ETH, regardless of the technology being used.

Re: The $1.5B Bybit Hack

#15

Taking a step back from this attack, it looks like the new crypto-reality is far far far immature security-wise & compliance-wise ("compliance to what??" you can ask me). While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals…

Being in the thick of it, I can tell you the compliance side is pushing towards what exists in traditional finance, be IT, money laundering, accounting practices etc. At least in Europe and to a lesser extent the US. If you go working at new banks (say Revolut or N26) or at growing asset-managing crypto companies in Europe you'll find the landscape to be extremely similar.

As far as I'm concerned, if you're parking money with a company based in an area that has lax regulation you're holding the gun that'll shoot your foot. I have a hard time seeing something like this happen at Bitpanda or Kraken, though you never know.

Re: The $1.5B Bybit Hack

#16
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversible transactions is a feature for fiat money

Reversible transactions would generally be a bug regarding cash & hard assets of which cryptocurrency is trying to imitate.

Re: The $1.5B Bybit Hack

#17
post #10

Earlier quoted context omitted.

They should only use a computer that is air gapped to go online only when signing something. This is an op sec failure to not have this procedure

That’s precisely what happened in this attack. They were attacked when they went online

No, the computers were pre infected. If they used airgapped systems only to sign there would be almost no vector to from other than some major zero click zero day stuff, in that case everyone is screwed

Re: The $1.5B Bybit Hack

#18
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Is cash silly? It has the same property (non-reversibility)

Re: The $1.5B Bybit Hack

#19
post #7

The other side of this coin is all the companies and infrastructure that has popped up, which intentionally or not enables the laundering of ill-gotten cryptocurrency [1]. I have a hard time feeling sympathy here because I consider cryptocurrency to be fundamentally silly. Reversible transactions of fiat currency transactions is a feature not a bug. I feel like securing something like this is practically impossible.…

Reversible transactions is a feature for fiat money Reversible transactions would generally be a bug regarding cash & hard assets of which cryptocurrency is trying to imitate.

Crypto has reversible transactions when both parties agree to use that functionality in advance (well, the reasonably programmable ones do, anyway)

It's not a bug if both parties give consent, which sounds like a wonderful way to transact, to me!

Re: The $1.5B Bybit Hack

#20
post #2

> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…

Yeah, it sounds like an attack on the Metamask extension, or the browser hosting it.
Post reply on HN