▲ 249 ▼ Crypto exchange Bybit says a hacker took control of one of its cold Ethereum wallets, resulting in what analysts estimate was the loss of ~$1.5B worth of tokens (www.bloomberg.com) submitted 1 year ago by Mazdak@lemmy.org to c/technology@lemmy.world 45 comments fedilink hide all child comments
[–] muntedcrocodile@lemm.ee 25 points 1 year ago (8 children) How does one get ones hands on a cold wallet? permalink fedilink source hideshow 16 child comments replies: [–] Transform2942@lemmy.ml 64 points 1 year ago* (last edited 1 year ago) (1 child) My speculations: "insecure from the start" - as in , the wallet was never that "cold" with that amount of money, it's easy to imagine an "insider threat" the hackers could have gotten lucky and struck right when the company was doing legitimate operations on the wallet but probably it's a towering mountain of incompetence, composed of the elements above and more permalink fedilink source parent hideshow 2 child comments replies: [–] Evotech@lemmy.world 37 points 1 year ago (1 child) Room temperature wallet permalink fedilink source parent hideshow 2 child comments replies: [–] muntedcrocodile@lemm.ee 2 points 1 year ago Right next to their iq permalink fedilink source parent [–] FaceDeer@fedia.io 28 points 1 year ago (2 children) It's a common misconception that a "cold wallet" is offline. It's still on the blockchain like any other wallet, it's just the keys that aren't on any network-connected computer. It appears that in this case hackers managed to trick Bybit employees into entering the keys into a fake UI that gave the hackers access to them. permalink fedilink source parent hideshow 4 child comments replies: [–] Kualk@lemm.ee 14 points 1 year ago That’s room temperature wallet. It was used while claiming asset unused. It is not cold storage anymore. permalink fedilink source parent [–] Kualk@lemm.ee 6 points 1 year ago Tricked or “tricked”. permalink fedilink source parent [–] x00z@lemmy.world 17 points 1 year ago (1 child) permalink fedilink source parent hideshow 2 child comments replies: [–] dhork@lemmy.world 19 points 1 year ago (1 child) Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. And this is the first time I have heard the word "musked" in this context..... permalink fedilink source parent hideshow 2 child comments replies: [–] x00z@lemmy.world 9 points 1 year ago Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. I have no idea. I guess they'll release a lot more info regarding this in the next few days. And this is the first time I have heard the word “musked” in this context… I think his English isn't good looking at the rest of the message. Might be "masked" instead. permalink fedilink source parent [–] golli@lemm.ee 14 points 1 year ago (1 child) What I don't quite understand is how there is 1.5 billion in a single wallet. Or how are these things structured? This article puts their total assets under management at $15.7b, which are held in different cryptocurrencies with ethereum at just above $5b. So I am wondering how they have more than 1/6 of their Ethereum in a single wallet or were these multiple that were connected and got compromised through the same vulnerability? How expensive is it to have more individual wallets? Would it not be feasible to have it split in something like $100m chunks? Or any other more moderate size. permalink fedilink source parent hideshow 2 child comments replies: [–] DaPorkchop_@lemmy.ml 3 points 1 year ago Making more wallets would cost nothing more than a few hundred bytes of storage each for the keys. I have no idea why they wouldn't have split their funds into evenly sized wallets of, say, $1M each. permalink fedilink source parent [–] Zachariah@lemmy.world 13 points 1 year ago I recommend gloves. permalink fedilink source parent [–] dhork@lemmy.world 4 points 1 year ago Well, either it wasn't as offline as they all thought, or someone pulled off an epic inside job. permalink fedilink source parent [–] HappyTimeHarry@lemm.ee 3 points 1 year ago (1 child) Social engineering, they convinced multiple key holders to sign a transaction. permalink fedilink source parent hideshow 2 child comments replies: [–] muntedcrocodile@lemm.ee 5 points 1 year ago The weakest part of any secure system. permalink fedilink source parent [–] MintyFresh@lemmy.world 2 points 1 year ago With steely determination permalink fedilink source parent
[–] Transform2942@lemmy.ml 64 points 1 year ago* (last edited 1 year ago) (1 child) My speculations: "insecure from the start" - as in , the wallet was never that "cold" with that amount of money, it's easy to imagine an "insider threat" the hackers could have gotten lucky and struck right when the company was doing legitimate operations on the wallet but probably it's a towering mountain of incompetence, composed of the elements above and more permalink fedilink source parent hideshow 2 child comments replies: [–] Evotech@lemmy.world 37 points 1 year ago (1 child) Room temperature wallet permalink fedilink source parent hideshow 2 child comments replies: [–] muntedcrocodile@lemm.ee 2 points 1 year ago Right next to their iq permalink fedilink source parent
[–] Evotech@lemmy.world 37 points 1 year ago (1 child) Room temperature wallet permalink fedilink source parent hideshow 2 child comments replies: [–] muntedcrocodile@lemm.ee 2 points 1 year ago Right next to their iq permalink fedilink source parent
[–] muntedcrocodile@lemm.ee 2 points 1 year ago Right next to their iq permalink fedilink source parent
[–] FaceDeer@fedia.io 28 points 1 year ago (2 children) It's a common misconception that a "cold wallet" is offline. It's still on the blockchain like any other wallet, it's just the keys that aren't on any network-connected computer. It appears that in this case hackers managed to trick Bybit employees into entering the keys into a fake UI that gave the hackers access to them. permalink fedilink source parent hideshow 4 child comments replies: [–] Kualk@lemm.ee 14 points 1 year ago That’s room temperature wallet. It was used while claiming asset unused. It is not cold storage anymore. permalink fedilink source parent [–] Kualk@lemm.ee 6 points 1 year ago Tricked or “tricked”. permalink fedilink source parent
[–] Kualk@lemm.ee 14 points 1 year ago That’s room temperature wallet. It was used while claiming asset unused. It is not cold storage anymore. permalink fedilink source parent
[–] x00z@lemmy.world 17 points 1 year ago (1 child) permalink fedilink source parent hideshow 2 child comments replies: [–] dhork@lemmy.world 19 points 1 year ago (1 child) Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. And this is the first time I have heard the word "musked" in this context..... permalink fedilink source parent hideshow 2 child comments replies: [–] x00z@lemmy.world 9 points 1 year ago Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. I have no idea. I guess they'll release a lot more info regarding this in the next few days. And this is the first time I have heard the word “musked” in this context… I think his English isn't good looking at the rest of the message. Might be "masked" instead. permalink fedilink source parent
[–] dhork@lemmy.world 19 points 1 year ago (1 child) Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. And this is the first time I have heard the word "musked" in this context..... permalink fedilink source parent hideshow 2 child comments replies: [–] x00z@lemmy.world 9 points 1 year ago Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. I have no idea. I guess they'll release a lot more info regarding this in the next few days. And this is the first time I have heard the word “musked” in this context… I think his English isn't good looking at the rest of the message. Might be "masked" instead. permalink fedilink source parent
[–] x00z@lemmy.world 9 points 1 year ago Do I understand this correctly, then, that this was some sort of MITM attack where valid requests to the multisig parties were replaced by malicious code while still appearing to be valid to the signers? That must be an inside job. I have no idea. I guess they'll release a lot more info regarding this in the next few days. And this is the first time I have heard the word “musked” in this context… I think his English isn't good looking at the rest of the message. Might be "masked" instead. permalink fedilink source parent
[–] golli@lemm.ee 14 points 1 year ago (1 child) What I don't quite understand is how there is 1.5 billion in a single wallet. Or how are these things structured? This article puts their total assets under management at $15.7b, which are held in different cryptocurrencies with ethereum at just above $5b. So I am wondering how they have more than 1/6 of their Ethereum in a single wallet or were these multiple that were connected and got compromised through the same vulnerability? How expensive is it to have more individual wallets? Would it not be feasible to have it split in something like $100m chunks? Or any other more moderate size. permalink fedilink source parent hideshow 2 child comments replies: [–] DaPorkchop_@lemmy.ml 3 points 1 year ago Making more wallets would cost nothing more than a few hundred bytes of storage each for the keys. I have no idea why they wouldn't have split their funds into evenly sized wallets of, say, $1M each. permalink fedilink source parent
[–] DaPorkchop_@lemmy.ml 3 points 1 year ago Making more wallets would cost nothing more than a few hundred bytes of storage each for the keys. I have no idea why they wouldn't have split their funds into evenly sized wallets of, say, $1M each. permalink fedilink source parent
[–] dhork@lemmy.world 4 points 1 year ago Well, either it wasn't as offline as they all thought, or someone pulled off an epic inside job. permalink fedilink source parent
[–] HappyTimeHarry@lemm.ee 3 points 1 year ago (1 child) Social engineering, they convinced multiple key holders to sign a transaction. permalink fedilink source parent hideshow 2 child comments replies: [–] muntedcrocodile@lemm.ee 5 points 1 year ago The weakest part of any secure system. permalink fedilink source parent
[–] muntedcrocodile@lemm.ee 5 points 1 year ago The weakest part of any secure system. permalink fedilink source parent
[–] MintyFresh@lemmy.world 2 points 1 year ago With steely determination permalink fedilink source parent