Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Technology
  3. Crypto exchange Bybit says a hacker took control of one of its cold Ethereum wallets, resulting in what analysts estimate was the loss of ~$1.5B worth of tokens

Crypto exchange Bybit says a hacker took control of one of its cold Ethereum wallets, resulting in what analysts estimate was the loss of ~$1.5B worth of tokens

Scheduled Pinned Locked Moved Technology
technology
45 Posts 30 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T [email protected]

    My speculations:

    • "insecure from the start" - as in , the wallet was never that "cold"

    • with that amount of money, it's easy to imagine an "insider threat"

    • the hackers could have gotten lucky and struck right when the company was doing legitimate operations on the wallet

    • but probably it's a towering mountain of incompetence, composed of the elements above and more

    E This user is from outside of this forum
    E This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #11

    Room temperature wallet

    muntedcrocodile@lemm.eeM 1 Reply Last reply
    0
    • muntedcrocodile@lemm.eeM [email protected]

      How does one get ones hands on a cold wallet?

      G This user is from outside of this forum
      G This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #12

      What I don't quite understand is how there is 1.5 billion in a single wallet. Or how are these things structured?

      This article puts their total assets under management at $15.7b, which are held in different cryptocurrencies with ethereum at just above $5b.

      So I am wondering how they have more than 1/6 of their Ethereum in a single wallet or were these multiple that were connected and got compromised through the same vulnerability? How expensive is it to have more individual wallets? Would it not be feasible to have it split in something like $100m chunks? Or any other more moderate size.

      D 1 Reply Last reply
      0
      • muntedcrocodile@lemm.eeM [email protected]

        How does one get ones hands on a cold wallet?

        facedeer@fedia.ioF This user is from outside of this forum
        facedeer@fedia.ioF This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #13

        It's a common misconception that a "cold wallet" is offline. It's still on the blockchain like any other wallet, it's just the keys that aren't on any network-connected computer.

        It appears that in this case hackers managed to trick Bybit employees into entering the keys into a fake UI that gave the hackers access to them.

        K 1 Reply Last reply
        0
        • D [email protected]

          I'm so glad I have no crypto of any kind. It's the wild west with no savings insurance, so once it's gone, it's gone.

          facedeer@fedia.ioF This user is from outside of this forum
          facedeer@fedia.ioF This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #14

          Depends which exchange you're using.

          S 1 Reply Last reply
          0
          • L [email protected]

            They'll just roll back the blockchain. Ethereum is a centrally controlled cryptocurrency, though its fans claim otherwise. It's been rolled back before.

            N This user is from outside of this forum
            N This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #15

            This is either a person who hasn't followed ETH since 2016 or is intentionally spreading misinformation.

            It HAS been rolled back once, when the blockchain was in its infancy. But to say that it is still "centrally controlled" suggests having no idea what has happened in the 9 years since.

            1 Reply Last reply
            0
            • M [email protected]
              This post did not contain any content.
              N This user is from outside of this forum
              N This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #16

              lol good

              1 Reply Last reply
              0
              • facedeer@fedia.ioF [email protected]

                It's a common misconception that a "cold wallet" is offline. It's still on the blockchain like any other wallet, it's just the keys that aren't on any network-connected computer.

                It appears that in this case hackers managed to trick Bybit employees into entering the keys into a fake UI that gave the hackers access to them.

                K This user is from outside of this forum
                K This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #17

                Tricked or “tricked”.

                1 Reply Last reply
                0
                • M [email protected]
                  This post did not contain any content.
                  cupcakezealot@lemmy.blahaj.zoneC This user is from outside of this forum
                  cupcakezealot@lemmy.blahaj.zoneC This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #18

                  how is $1.5 billion in worth calculated because no way bitcoin tokens are worth more than $20.

                  x00z@lemmy.worldX T P 3 Replies Last reply
                  0
                  • K This user is from outside of this forum
                    K This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #19

                    That’s room temperature wallet. It was used while claiming asset unused.

                    It is not cold storage anymore.

                    1 Reply Last reply
                    0
                    • cupcakezealot@lemmy.blahaj.zoneC [email protected]

                      how is $1.5 billion in worth calculated because no way bitcoin tokens are worth more than $20.

                      x00z@lemmy.worldX This user is from outside of this forum
                      x00z@lemmy.worldX This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #20

                      401,347 ETH

                      cupcakezealot@lemmy.blahaj.zoneC 1 Reply Last reply
                      0
                      • M [email protected]
                        This post did not contain any content.
                        G This user is from outside of this forum
                        G This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #21

                        lolfomo

                        1 Reply Last reply
                        0
                        • muntedcrocodile@lemm.eeM [email protected]

                          How does one get ones hands on a cold wallet?

                          x00z@lemmy.worldX This user is from outside of this forum
                          x00z@lemmy.worldX This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #22

                          D 1 Reply Last reply
                          0
                          • x00z@lemmy.worldX [email protected]

                            D This user is from outside of this forum
                            D This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #23

                            Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job.

                            And this is the first time I have heard the word "musked" in this context.....

                            x00z@lemmy.worldX 1 Reply Last reply
                            0
                            • D [email protected]

                              Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job.

                              And this is the first time I have heard the word "musked" in this context.....

                              x00z@lemmy.worldX This user is from outside of this forum
                              x00z@lemmy.worldX This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #24

                              Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job.

                              I have no idea. I guess they'll release a lot more info regarding this in the next few days.

                              And this is the first time I have heard the word “musked” in this context…

                              I think his English isn't good looking at the rest of the message. Might be "masked" instead.

                              1 Reply Last reply
                              0
                              • x00z@lemmy.worldX [email protected]

                                401,347 ETH

                                cupcakezealot@lemmy.blahaj.zoneC This user is from outside of this forum
                                cupcakezealot@lemmy.blahaj.zoneC This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #25

                                x00z@lemmy.worldX 1 Reply Last reply
                                0
                                • M [email protected]
                                  This post did not contain any content.
                                  T This user is from outside of this forum
                                  T This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #26

                                  The money is not gone, is just that someone else has it.

                                  1 Reply Last reply
                                  0
                                  • M [email protected]
                                    This post did not contain any content.
                                    S This user is from outside of this forum
                                    S This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #27

                                    I gotta get in on this hacking gig. Anyone know if any hacker groups are hiring?

                                    /s for CSIS

                                    1 Reply Last reply
                                    0
                                    • E [email protected]

                                      Room temperature wallet

                                      muntedcrocodile@lemm.eeM This user is from outside of this forum
                                      muntedcrocodile@lemm.eeM This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #28

                                      Right next to their iq

                                      1 Reply Last reply
                                      0
                                      • M [email protected]
                                        This post did not contain any content.
                                        P This user is from outside of this forum
                                        P This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #29

                                        ELI5 why we cannot "rollback" Ethereum

                                        https://xcancel.com/TimBeiko/status/1893412457567383559#m

                                        1 Reply Last reply
                                        0
                                        • facedeer@fedia.ioF [email protected]

                                          Depends which exchange you're using.

                                          S This user is from outside of this forum
                                          S This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #30

                                          Anybody who keeps their money on an exchange any longer than necessary is just asking for trouble. An exchange is like a public toilet. You get in, you shit, and you get the fuck out. You don't hang around in a public toilet.

                                          Self custody or GTFO.

                                          facedeer@fedia.ioF 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups