> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Yeah, it sounds like an attack on the Metamask extension, or the browser hosting it.
The $1.5B Bybit Hack
71–80 of 140 posts
Re: The $1.5B Bybit Hack
#72Re: The $1.5B Bybit Hack
#73Earlier quoted context omitted.
Crypto has reversible transactions when both parties agree to use that functionality in advance (well, the reasonably programmable ones do, anyway) It's not a bug if both parties give consent, which sounds like a wonderful way to transact, to me!
But, when you REALLY want reversibility is when the transaction is done without your consent — when stuff is stolen and you want it back. Thieves will not tend to consent to reversible transactions.
Re: The $1.5B Bybit Hack
#74My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.
Yea, how is it that multiple people signed a transaction for over a billion dollars of assets without due diligence? If you did this for non crypto there would be lawyers, bankers, etc involved in the transaction. Root certificate authorities have already solved this problem with signing rituals which take place in person in an air gapped vault on specialized hardware and multiple parties as witness.
Re: The $1.5B Bybit Hack
#75> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
it is possible to infect the offline computer by infecting a USB drive with stealth malware which then propagates to the offline one.
It could also be an inside job in exchange for an employee getting a kickback from N. Korea . it's not like this has not happened in the past. Imagine being a low-paid employee at an exchange and being enticed by an offer for tens of millions by North Korea to pretend to be hacked and infect one's own computers with the malware supplied by North Korea. This would be easy for an employee to do, who has access to the computers, and then pass it off as a hack.
Re: The $1.5B Bybit Hack
#76My understanding is this multisig failed because, like most security, everyone just pressed yes and didn’t communicate, investigate, or ask questions, defeating the purpose of a multisig.
Yea, how is it that multiple people signed a transaction for over a billion dollars of assets without due diligence? If you did this for non crypto there would be lawyers, bankers, etc involved in the transaction. Root certificate authorities have already solved this problem with signing rituals which take place in person in an air gapped vault on specialized hardware and multiple parties as witness.
Re: The $1.5B Bybit Hack
#77> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Isn't cold storage about where the keys are? You still need to be able to actually interact with a chain.
Re: The $1.5B Bybit Hack
#78Earlier quoted context omitted.
Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…
>But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. That's not really a viable strategy. It has been tried a few times - Mittelwerk and Kőbánya spring to mind - but you can't really build a self-contained factory. If your enemy can't bomb the factory, they'll bomb the roads and railways serving your factory, they'll bom…
All true, and German WW2 production kept increasing despite the bombing.
Re: The $1.5B Bybit Hack
#79I really do not understand why they do not separate these into multiple separate wallets
This was a multisig - meaning M out of N signatures from different signing devices were needed to sign a transaction. The attacker infected enough signer devices to go unnoticed and the signers failed to verify what they were signing on air-gapped devices
Re: The $1.5B Bybit Hack
#80Earlier quoted context omitted.
Is cash silly? It has the same property (non-reversibility)
> Is cash silly? No, of course not. Adjusting your comment for the situation: > Is $100.00 in cash silly? It has the same property (non-reversibility) No, not silly if that's what I am comfortable to keep on me (wallet, mattress, etc) and I'm mugged/robbed most people will recover. (Especially if you're also able to afford the inherent risk of crypto.) > Is $1,500,000,000.00 in cash silly? It has the same property (n…
- Height: 66.3mm
- Width: 156mm
- Thickness: 0.0043 inches = 0.11mm
- Weight: 1.0g
So the volume is 1138mm3. You need 15M notes so that's just over 17 cubic meters or approximately 603 cubic feet, which is a cube roughly 2.6 meters (8.5 feet) on each side, weighing in at 15 metric tons or 33,000 pounds. Put another way, that's over half the volume of a standard twenty foot shipping container (~1100 cubic feet).
But let's get it more compact. The current gold price seems to be about $2939 per Troy ounce, which is 31.1035g. You need 510,378 Troy ounces, which is actually heavier at 15.87 metric tons but way more compact. Given a density of 19.32g/cm3 that's 822,000cm3 or 0.822 cubic meters or 29 cubic feet.
Whatever the case, it's a lot less practical to steal.
[1]: https://en.wikipedia.org/wiki/United_States_one-hundred-doll...