Syed Rahman details the crypto exchange’s response to what is thought to be the biggest-ever digital heist
Crypto exchange Bybit has asked for the smartest people in cybersecurity to help it recover the $1.5 billion it lost in what is believed to be the largest-ever single digital theft.
Dubai-based Bybit said hackers had gained control of a wallet of Ethereum and transferred the contents to an unknown address. It has told its customers that their cryptocurrency is safe and that those affected would be refunded - even if the hacked currency is not regained – as it has the assets to cover any unrecovered funds.
Bybit has asked the “the brightest minds in cybersecurity and crypto analytics” to help it recover the hacked funds. It is offering a reward of 10% of the amount recovered.
In a statement, Bybit co-founder and chief executive Ben Zhou said: “Bybit is determined to rise above the setback and fundamentally transform our security infrastructure, improve liquidity, and be a steadfast partner to our friends in the crypto community.”
Bybit has more than 60 million users worldwide and is the world’s second-largest cryptocurrency exchange by trading volume. But news of the hack has, according to the company, led to more than 350,000 requests from customers to withdraw their funds.
It said the hack was carried out by someone exploiting security controls when the company was making what is normally a regular transfer of Ethereum from an offline “cold” wallet to a “warm” wallet to cover its daily trading. The price of Ethereum dropped by nearly 4% immediately after reports of the hack but then returned to close to pre-hack levels.
While those behind the hack have not been identified, some have pointed the finger of suspicion at North Korean state hackers, such as the Lazarus Group, who have been accused of other major crypto attacks.
Possible
Due to the transparency of the blockchain, a concerted effort to trace the malicious actors is technically possible. According to some sources, more than $40 million has already been recovered. But the issue in such cases is often that the malicious actors are using thousands of transactions to launder the stolen funds, which are then cashed out before the accounts can be frozen by the service providers that have been alerted to what has happened.
In this way, the hackers can stay one step ahead. They can also exploit crypto mixers, such as Tornado Cash (which we have reported on). There are also issues arising from slow responses from service providers. As an example, $120 million was withdrawn from a cryptocurrency exchange called eXch, yet despite multiple requests from Bybit, eXch has not blocked any of these transactions; each of which earns eXch a fee.
Vulnerable
The targeting of Bybit was not an indicator of it being any more vulnerable than others in its sector. It was using so-called multisig cold wallets – basically hard drives that require multiple keys (or “signatures’’) to access the assets they protect - to transfer funds to a warm wallet for trading. This is viewed as a secure way to store assets, as even if one key is compromised access cannot be gained.
The hackers exploited the user interface of the cold wallet through a very sophisticated phishing attack that targeted those that held the keys. This is a clear reminder that the crypto world is still young and very vulnerable to cyber-attacks. In this case, even what was thought to be the safest option was not safe.
There will be many who are now concerned that what was believed to be the most secure procedure may not be as safe as was thought. With this happening at a time when restrictions are being removed in the US by the Trump presidency, the crypto market looks set for some thought-provoking times.
