TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bybit loses $1.5B in hack

320 点作者 tuananh3 个月前

43 条评论

mdaniel3 个月前
a related blog from Trail of Bits about the opsec failure of this: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43140754">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=43140754</a>
评论 #43142175 未加载
rkagerer3 个月前
There&#x27;s some info and speculation in these two (distinct) articles, but I&#x27;d love to know technical details of where the gaffs were.<p>eg. Was client software compromised? Did the multisig keyholders succumb to social engineering? Were the signers using airgapped machines &#x2F; hardware devices?<p><a href="https:&#x2F;&#x2F;archive.ph&#x2F;YMZrq" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;YMZrq</a><p><a href="https:&#x2F;&#x2F;blockworks.co&#x2F;news&#x2F;bybit-hack-raises-security-questions" rel="nofollow">https:&#x2F;&#x2F;blockworks.co&#x2F;news&#x2F;bybit-hack-raises-security-questi...</a>
评论 #43137931 未加载
评论 #43136753 未加载
评论 #43137102 未加载
philipwhiuk3 个月前
It&#x27;s obviously not a cold wallet if it&#x27;s connected to the exchange.
评论 #43130519 未加载
评论 #43131862 未加载
评论 #43130630 未加载
评论 #43136546 未加载
评论 #43130682 未加载
评论 #43130580 未加载
plantain3 个月前
How on earth is it possible they can cover a 1.5B loss? Are they really sitting on that much profit, or is the goal to ponzi it out from here, MtGox style?
评论 #43137423 未加载
评论 #43138035 未加载
评论 #43139075 未加载
评论 #43137876 未加载
评论 #43139260 未加载
评论 #43139355 未加载
评论 #43138723 未加载
评论 #43142540 未加载
评论 #43138078 未加载
评论 #43137452 未加载
评论 #43141317 未加载
Geee3 个月前
There should be something like a &quot;finalizing transaction&quot;, which both the sender and receiver need to sign after the first transaction has been mined, i.e. like an in-built escrow. If it&#x27;s not signed by both, then funds are returned. This wouldn&#x27;t protect against key leakage, but in this case, the tx was signed by accident. This would also protect against sending to wrong address.
评论 #43137325 未加载
评论 #43137112 未加载
zer0x4d3 个月前
I&#x27;m a huge crypto believer but I can admit that we don&#x27;t have a serious system if a person can just transfer over $1.5B from a well known crypto cold wallet to different accounts with nothing flagging it and no way to reverse it.
评论 #43136781 未加载
评论 #43136994 未加载
评论 #43137240 未加载
评论 #43137310 未加载
评论 #43137480 未加载
评论 #43138362 未加载
评论 #43137041 未加载
UncleMeat3 个月前
&quot;Please rest assured that all other cold wallets are secure.&quot;<p>Unreal.
评论 #43137264 未加载
qingcharles3 个月前
Can someone even explain what Bybit is actually about? I searched around when the hack was announced, but I&#x27;m very confused. Mostly what I saw said &quot;scam&quot; on it.<p>This isn&#x27;t your run-of-the-mill Coinbase style exchange, right?
评论 #43136841 未加载
评论 #43137600 未加载
mkagenius3 个月前
A crypto exchange WazirX was hacked for ~$300M, roughly 50% of the users fund gone.<p>There is no action on the CEO since the hack in July 2024. He sits in Dubai. He just got a nod from Supreme Court of SG to just average out the funds and distribute it among the users.<p>No action has been initiated against the company&#x2F;ceo for losing the fund. He is geared up to launch another company&#x2F;exchange.
评论 #43137762 未加载
评论 #43141357 未加载
评论 #43137887 未加载
sleazebreeze3 个月前
What are the chances that a Bybit insider is behind this?
评论 #43130900 未加载
评论 #43136143 未加载
karmakaze3 个月前
I have no idea how crypto exchanges work. Could someone ELI5 some of this? I have questions:<p>Did the cold storage wallet contain users&#x27; ETH? That seems implied by &quot;Can Cover Loss&quot;.<p>If so, why does a crypto exchange hold users&#x27; ETH in a wallet that can execute transactions without said user&#x27;s authorization&#x2F;password for each transaction. Doesn&#x27;t even Facebook require entering a password every time to change certain profile settings?<p>Or maybe more generally, why does there need to be such a large cold-storage wallet to run an exchange?<p>Also how or why would they have the assets to be able to cover this?<p>There&#x27;s some other seemingly conflicting info I found in searches for Bybit:<p>- Bybit is not legal in Canada. Bybit is restricted in Canada and other jurisdictions, including the United States, the United Kingdom, and Singapore.<p>- Bybit originates from Singapore, a global hub for cryptocurrency and blockchain technology. Singapore has a favorable regulatory environment for cryptocurrencies, which has attracted many exchanges to establish their headquarters there.<p>- There&#x27;s also a mix of results where some say Bybit is safe&#x2F;secure and others saying they aren&#x27;t (irrespective of this event). This story seems to indicate that they had measures to make it safe, but it didn&#x27;t save them.
rNULLED3 个月前
&gt; have a wallet, work at bybit &gt; understand backdoor &gt; steal money from your account, some from others &gt; bybit pays you back &gt; still have money you stole
walterbell3 个月前
<p><pre><code> Bybit CEO Ben Zhou wrote on X that a hacker &quot;took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.&quot; </code></pre> &quot;Control&quot; has a specific meaning under UCC Article 12, which was ratified in 2022 and is slowly being adopted by U.S. states. It links some rights to control&#x2F;possession of keys, even if a blockchain asset may have been stolen before being sold, <a href="https:&#x2F;&#x2F;www.clearygottlieb.com&#x2F;&#x2F;news-and-insights&#x2F;publication-listing&#x2F;ucc-digital-asset-amendments-finalized" rel="nofollow">https:&#x2F;&#x2F;www.clearygottlieb.com&#x2F;&#x2F;news-and-insights&#x2F;publicatio...</a><p><i>&gt; Article 12 – dealing directly with the acquisition and disposition of interests (including security interests) in “controllable electronic records,” which would include Bitcoin, Ether, and a variety of other digital assets ... a good faith purchaser for value who obtains control (a “qualifying purchaser”) takes its interest free of conflicting property claims... Control under Article 12 is designed to be a technology-neutral functional equivalent of “possession.” It generally encompasses circumstances when a party has the “private key”</i>
评论 #43131070 未加载
评论 #43130873 未加载
评论 #43136847 未加载
ArtTimeInvestor3 个月前
When even professional companies that have billions of dollars under management can&#x27;t securely manage their crypto assets, how likely is it that individuals can?
评论 #43130949 未加载
评论 #43130959 未加载
mvdtnz3 个月前
Remember the golden rule that when it comes to crypto it is a scam 100% of the time. Congrats to the Bybit CEO on his newfound wealth.
fennecbutt3 个月前
And they keep everything in one wallet why?!?!<p>Surely you&#x27;d allocate a new wallet&#x2F;1m roughly and always keep it spread.
jauntywundrkind3 个月前
Terrifying to imagine how much funding terrorist states might be getting by hacks like this.
评论 #43136726 未加载
scrlk3 个月前
I wouldn&#x27;t be surprised if Bybit cuts a deal with the hacker to return the funds. There&#x27;s no way that $1.46 billion of marked ETH can be liquidated and off-ramped to fiat.
评论 #43130899 未加载
评论 #43136157 未加载
thesumofall3 个月前
In case of a state actor just imagine the weapons that could be bought with this kind of money and the potential lives lost due to this mess
insane_dreamer3 个月前
Given how many of these exchanges have been hacked (or were fraudulent), how is it that people still use them?
czhu123 个月前
Their English Wikipedia page is deleted as of 1:42am pst. Any idea what that’s about?
评论 #43137789 未加载
评论 #43137786 未加载
nodesocket3 个月前
My understand is that the original transaction was a small fraction of the total balance of ETH in the wallet. How then were they able to liquidate the entire ETH wallet?
Animats3 个月前
Who says ByBit can cover the loss? The article title says that but the article quotes do not. The CEO only said that their other cold wallets are intact and that withdrawals remain normal.<p>Bybit claims to be regulated by the Virtual Assets Regulatory Authority of Dubai.[1] But the lookup page at VARA says they only have &quot;In-principle approval&quot;, not a full license. &quot;Applicants holding an IPA are strictly prohibited from initiating operations, conducting any virtual asset activities, or servicing clients until they have obtained their full VASP licence from VARA.&quot;<p>Uh oh.<p>[1] <a href="https:&#x2F;&#x2F;www.vara.ae&#x2F;en&#x2F;licenses-and-register&#x2F;public-register&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vara.ae&#x2F;en&#x2F;licenses-and-register&#x2F;public-register...</a>
评论 #43137473 未加载
评论 #43137413 未加载
fjjjrjj3 个月前
More like byebit.<p>Unregulated asset exchanges. Haven&#x27;t we been there before a loong time ago?
sub73 个月前
These are not hacks, just like Mtgox, Celsius, FTX etc etc etc were not hacks. These are crypto insiders supporting the stablecoin so they can print and set a floor on prices before&#x2F;during potential mass sell off events.
m00dy3 个月前
We are in the middle of the bull market. fyi.
lofties3 个月前
&gt; &quot;Please rest assured that all other cold wallets are secure. All withdrawals are normal,&quot; he added.<p>There are no American infidels in Baghdad. Never!
评论 #43138049 未加载
评论 #43138183 未加载
ycombinatrix3 个月前
&gt;Bybit CEO Ben Zhou wrote on X that a hacker &quot;took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.&quot;<p>Um how tf does a cold wallet get hacked?
评论 #43137965 未加载
k__3 个月前
Whelp, you better shorted $SAFE.
gosub1003 个月前
[flagged]
评论 #43130663 未加载
评论 #43130605 未加载
评论 #43130551 未加载
评论 #43135241 未加载
评论 #43130556 未加载
jameson3 个月前
I found it funny that the idea of blockchain, which, the system trusts no single entity but trusts transaction consensus, yet one trusts a single entity who holds your wallet and risk of losing if they get hacked while there&#x27;s no mediators&#x2F;regulators to revert the transaction
russnes3 个月前
Kim Jong 1337 hacker strikes again
throwaway_v3 个月前
woops
tombert3 个月前
The entirety of the cryptocurrency world is so obviously a &quot;Chesterton&#x27;s Fence&quot; situation.<p>Every pseudo-intellectual thinks that the fiscal world is &quot;too complicated&quot; and they&#x27;re going to &quot;simplify&quot; it by making some token, only for people to realize that the monetary world <i>is just complicated</i>, and they have to reinvent everything that already existed in the traditional banking system.<p>I had to do some work on an ACH system a couple years ago [1], and I read through a large chunk of the ACH standard, which was about 800 pages. It&#x27;s easy to see and hear that and think &quot;that&#x27;s way too complicated, what could possibly be so hard about money transfers that necessitates an 700 page specification??&quot;, but as I read it and saw how many edge cases it took into account, it was easy to see why it got so huge. It turns out that dealing with money is just a really hard problem at scale.<p>I fell for the cryptocurrency hype of 2021, and I will fully acknowledge that that came out of a complete lack of understanding of how fiscal systems work. I wish everyone else would just grow up already.<p>[1] Usually disclaimer: not hard to find my work history, it&#x27;s not hidden, but I ask that you do not post anything about it (or at least any proper nouns about it) here.
评论 #43131080 未加载
评论 #43130877 未加载
评论 #43136583 未加载
tw19843 个月前
another &quot;exchange was hacked&quot; story, why I am not surprised.
评论 #43130698 未加载
huang_chung3 个月前
Society has devolved a bit when not long ago a heist like this would involve sieging Nakatomi Plaza, now it takes just finding a bug in someone&#x27;s defective Python codes.
评论 #43139166 未加载
评论 #43137144 未加载
评论 #43130668 未加载
评论 #43133401 未加载
评论 #43141294 未加载
chabes3 个月前
From the article:<p>&gt; The wallet in question appears to have sent 401,346 ETH ($1.1 billion) as well as several other iterations of staked ether (stETH) to a fresh wallet, which is now liquidating mETH and stETH on decentralized exchanges, etherscan shows. The wallet has sold around $200 million worth of stETH so far.<p>If you showed me a paragraph like this a decade ago and told me it was from 2025, I would have a difficult time believing you.
评论 #43136722 未加载
评论 #43130673 未加载
评论 #43133363 未加载
FabHK3 个月前
Crypto use case: Finance North Korea&#x27;s nuclear missile program.
评论 #43139853 未加载
评论 #43141337 未加载
评论 #43140297 未加载
faefox3 个月前
[flagged]
评论 #43136406 未加载
评论 #43130681 未加载
评论 #43130883 未加载
toomuchtodo3 个月前
<a href="https:&#x2F;&#x2F;www.web3isgoinggreat.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.web3isgoinggreat.com&#x2F;</a>
ChrisMarshallNY3 个月前
As Frank Drebin would say, “Nothing to see here.”<p><a href="https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=aKnX5wci404" rel="nofollow">https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=aKnX5wci404</a>
guluarte3 个月前
[flagged]
评论 #43130715 未加载
评论 #43130796 未加载
medellin3 个月前
Old man yells at cloud vibes every time a crypto post comes on HN.<p>No interesting discussions ever. Just axes being sharpened and people who dislike it taking the opportunity to gloat. I would characterize the pro crypto people but I don’t see any. Which is said because over the last 5 years I have found crypto, bitcoin, and stable coins to be extremely useful when helping family members in emerging markets.<p>But hey it’s all trash, the west doesn’t need it so let’s all dance on its grave.. i guess we will keep dancing for another 15 years.
评论 #43136642 未加载