Taking a step back from this attack, it looks like the new crypto-reality is far far far immature security-wise & compliance-wise ("compliance to what??" you can ask me). While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals…
> those crypto bros, a bunch of failed morons (self-proven by all these hacks) Bankers are a bunch of idiots, too. I know this to be true because that one investment bank collapsed a bunch of years ago. In all seriousness though, ETH is just a commodity; a bearer instrument; a thing. It's similar to gold or cash in some ways. If you store it properly, you're fine. If you give it to someone untrustworthy who loses it,…
The $1.5B Bybit Hack
81–90 of 140 posts
Re: The $1.5B Bybit Hack
#82Earlier quoted context omitted.
Actually we have been at war with North Korea continously since the 1950s, we only have a cease fire with them. The Korean War ended with an armistice signed on July 27, 1953, which stopped active fighting but did not establish a formal peace treaty. https://en.m.wikipedia.org/wiki/Korean_conflict I know that soldiers stationed in South Korea get paid at the wartime rate.
Only another 300 years to beat the record between Netherlands and the Isles of Scilly. Maybe the US and North Korea will sign a peace treaty in the 24th century. Captain Picard can mediate.
Re: The $1.5B Bybit Hack
#83The online security world is so wild. In pretty much any other field of engineering, foreign nation states explicitly targeting the thing you built is just kinda out of scope. There's no skyscraper in existence that is designed to withstand sustained artillery shelling, and your car is not going to withstand a tank shell either. Neither do they have to be designed to that specification. If North Korea killed someone…
The state of online security hasn't changed much. What has changed is that there is an digital (as opposed to gold) international form of money whose transactions cannot be reversed or stopped. Bybit and those holders of large crypto are operating with a fundamentally different threat model where its worthwhile for an attacker to invest millions of dollars of effort (for the Bybit payout even tens or hundreds of mill…
The members are state sponsored and young/bright. Top 0.1℅ academic sorts. At one point, the BBC got access to a conversation with one of the hackers, and their only question was "how much do you get paid?" (the context was that the hacker thought they were talking to Someone else in the tech space)
Apparently they aren't paid very well at all. Far less than the average Western IT worker. Their lives are not luxurious either. They're in barracks style living quarters with strict schedules and travel. Presumably, the anonymous Lazarus hacker was putting out a probing question because they must have been ruminating about what life on the other side would be like, what they are really worth, etc.
That's part of the power of Lazarus, the ability to dedicate resources far in excess of what most expect due to their indentured servant hackers (the opportunity to join is presented as a gift, Which to some extent it is because it does come with the extremely rare opportunity to travel. Many of them are in China.)
Re: The $1.5B Bybit Hack
#84Earlier quoted context omitted.
Your logic is backwards. Factories are not designed to withstand sustained aerial bombardment because the chance of sustained aerial bombardment is small to non-existent due to effective (geopolitical) mitigations. But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. You do not just throw your hands up in the air and say:…
>But, if you are in a active war and being actively bombed, then you absolutely design your factories to be resistant to sustained aerial bombardment. That's not really a viable strategy. It has been tried a few times - Mittelwerk and Kőbánya spring to mind - but you can't really build a self-contained factory. If your enemy can't bomb the factory, they'll bomb the roads and railways serving your factory, they'll bom…
If nobody knows where your factory is, it looks like a parking lot from the air and you have multiple smaller factories instead of one big factory to mitigate the impact of a damage event you are resistant to aerial bombardment, even if your ceiling isn't any sturdier than a normal factory roof. Same if the factory is out in the open but everybody thinks your drone factory produces windshield wipers
Re: The $1.5B Bybit Hack
#85Earlier quoted context omitted.
Isn't cold storage about where the keys are? You still need to be able to actually interact with a chain.
My understanding of "cold storage" was always that they keys are not accessible to the internet. That could be stored on paper, a flash drive or engraved in metal and put in a safe, or it could be in a regular digital wallet on a device never connected to the internet. If you want to do transactions, put it on an airgapped device, create the transaction, then move the transaction to an internet-connected device to br…
The internet is adversarial, a cold wallet should only be reachable by a wrench attack.
Re: The $1.5B Bybit Hack
#86Re: The $1.5B Bybit Hack
#87In a multisig interaction there are 3 ways to get hacked: - The multisig smart contract is owned - The computer you're signing on is owned - The hardware wallet (ledger, trezor) you're using is owned The multisig contract in question here (Gnosis Safe) has shown to be incredibly robust, and hardware wallets are very difficult to attack, so the current weak point is the computer. Cryptocurrency companies need to start…
Re: The $1.5B Bybit Hack
#88> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Cold storage means the coins are stored offline. If the offline computer has malware, it is possible to tamper with the transaction data at the offline stage. Cold storage means signing the transaction offline and then broadcasting it on the online computer. if both are tampered then in theory this is possible by both computers showing erroneous data (where the offline computer tampers with the transaction by signing…
The emphasis is on running the correct software. If you have to input cryptographic data every time you boot that's okay because you're offline and should be in a secure room (no internet connected devices).
But yeah, malware attack is still possible if you don't have a secure chain and that's a long one.
Re: The $1.5B Bybit Hack
#89> attackers stole approximately $1.5B from their multisig cold storage wallet. At this time, it appears the attackers compromised multiple signers’ devices, manipulated what signers saw in their wallet interface, and collected the required signatures while the signers believed they were conducting routine transactions. If hackers can get remote access and 'manipulate what signers saw in their wallet interface' that d…
Cold storage means the coins are stored offline. If the offline computer has malware, it is possible to tamper with the transaction data at the offline stage. Cold storage means signing the transaction offline and then broadcasting it on the online computer. if both are tampered then in theory this is possible by both computers showing erroneous data (where the offline computer tampers with the transaction by signing…
"Cold storage" has come to mean that the keys are stored in some offline location. It doesn't necessarily mean that the keys are hard to access or that the money being moved is otherwise hard to get to. That is used to be what it means, but practically, a wallet on a hardware keychain is called "cold" exactly the way a wallet whose keys are split up on slips of paper between 5 different physical vaults is "cold."
Re: The $1.5B Bybit Hack
#90Taking a step back from this attack, it looks like the new crypto-reality is far far far immature security-wise & compliance-wise ("compliance to what??" you can ask me). While it is nearly impossible to steal $100mn from one of the mega-banks, those crypto bros, a bunch of failed morons (self-proven by all these hacks), manage to lose people's money. Now.. I am not defending the banking system (and its ethics/morals…
I'm not sure how you'd do compliance, though. At least not universally. You could (which I suppose is your point) implement compliance requirements for crypto companies operating facilities on your soil. That doesn't really do anything for decentralized systems though