$1.5 BILLION Bybit Hack: Insiders Reveal Shocking New Details!
Monday, 10 March 2025 · 2 min read · Listen to the episode ↗
The Bybit hack, revealing a $1.46 billion theft by the Lazarus group, underscores significant vulnerabilities in crypto security protocols, particularly involving cold wallets. The incident, identified as a supply chain attack, sparked discussions on the need for standardized security measures and better operational processes in the cryptocurrency space. Additionally, the conversation highlighted the potential role of smart contracts in enhancing transaction verification to mitigate risks associated with centralized exchanges and large wallet holdings.
On February 21st, Zackxbt reported suspicious outflows from Bybit totaling $1.46 billion, indicating a significant hack attributed to the Lazarus group, linked to North Korea, which may have stolen over 400,000 ETH. Bybit acted swiftly to stabilize withdrawals and secure customer deposits, avoiding a bank run. The hack involved Bybit's cold wallet, raising concerns about security protocols. A key figure noted that four signers were involved in a transaction, but only three had signed before the hack was executed. Cybersecurity experts were engaged to investigate, focusing on the four signatories who were in different locations and used specific laptops for transactions.
Two main hypotheses emerged regarding the hack: a malicious front end served by the server or malware on the signer computers. The investigation required analyzing browser caches to identify any malicious activity during the signing process. Initial evidence suggested an external source, specifically Amazon S3, as the origin of the attack, which began with the injection of malicious code into Bybit's JavaScript resources. The attackers masked the true destination of the transaction to appear legitimate and restored the JavaScript files afterward to cover their tracks.
The incident was identified as a supply chain attack, highlighting the lack of standardized security frameworks in crypto compared to traditional banking. Recommendations for Bybit included implementing stricter operational processes, better transaction monitoring, and advanced security measures like hardware security modules (HSM). The discussion emphasized the need for audits in crypto and the importance of information sharing among exchanges to enhance security.
Concerns were raised about the risks of keeping large sums in a single wallet, with suggestions to use multiple wallets and apply risk management principles. The differences between crypto and banking were highlighted, particularly the finality of crypto transactions. The guest proposed that smart contracts could include additional verification steps to enhance security, although they are not foolproof.
Acknowledgment was given to the team for their swift response following the incident, with reflections on the significant costs of improving security in the crypto space. Recommendations for crypto safety included avoiding large amounts on centralized exchanges, storing funds in cold wallets, and using secure options like Ledger Wallets. The importance of protecting funds was emphasized, noting that once lost, money cannot be recovered.
This summary was generated from the episode transcript and can contain mistakes.