$OM died.
A top 50 coin.
Gone.
$6 billion erased like it never mattered.
This is your reminder:
Make your money,
And get out.
In #crypto, nothing is guaranteed.
Not the team.
Not the tech.
Not the hype.
Only your risk management.
Only your discipline.
If this didn’t humble you,
You’re not gonna make it.
Survive first. Win later.
Latest Update: Bybit has already fully closed the ETH gap, new audited POR report will be published very soon to show that Bybit is again Back to 100% 1:1 on client assets through merkle tree, Stay tuned.
Join us on war against Lazarus - https://t.co/EEkj05V2xZ
Industry first bounty site that shows aggregated full transparency on the sanctioned Lazarus money laundering activities. V1 includes:
- Becoming a bounty hunter by connecting your wallet and help tracing the fund, when your submitted bounty leads to freeze, bounty is paid upfront upon instantly at freezing.
-All freezer gets 5% of the bounty, exchange, mixers and all.
- live ranking of good and bad actor and their response time to deal with the sanctioned Lazarus group transactions. You don't want to end up on the bad actor list , it's a record of you helping to facilitate sanctioned transactions.
- Live API wallet address update for exchange, Chainanalysis, @arkham@elliptic@trmlabs
We have assigned a team to dedicate to maintain and update this website, we will not stop until Lazarus or bad actors in the industry is eliminated. In the future we will open it up to other victims of Lazarus as well.
V2 coming up:
-Live update on latest wallet with latest balance, this will serve as open bounty, bounty hunter can claim a wallet and own that part of the journey for x amount of time when the wallet is moving.
-Regulator Tools
-
**More idea, feedback welcomed, please leave at comment, a lot more improvement needed**
LET THE HUNTING SEASON BEGIN!
I do agree with CZ that if this hack was conducted through penetrating our internal systems such as any part of the withdraw system or one of our hot wallet was breached, we would've halted all withdraws until we find the root cause of the problem. In the case of yesterday, it was our ETH cold wallet which we use @safe that was breached, it had nothing to do with any of our internal systems so it was easy for me to make the call to maintain all withdraw and system functions of Bybit as usual.
Binance and CZ was among many of the partners and industry leaders that offered to help us during last night fiasco. We are extremely grateful and simply overwhelmed with all the support that we got. This was a truly tragic event for Bybit but the industry showed strength united together. I have faith that it's only up from now.
Some thoughts on the recent hack(s).
There is a pattern where hackers were able to steal large amounts of crypto from multi-sig “cold storage” solutions, as with ByBit, Phemex, WazirX and potentially others. In the most recent ByBit case, the hackers were able to make the front-end user interface show a legitimate transaction while the actual signing was for a different transaction. I am less familiar with the other cases, but they sound similar based on limited available info.
What’s more scary is that the affected exchanges used different multi-sig solution providers. The hackers, the Lazarus Group, are highly advanced and broad in their abilities to penetrate. It is still unclear whether the hackers were able to penetrate multiple signing devices, or the server side, or both in each of these cases.
Some people questioned my suggestion of halting all withdrawals as a standard security precaution (in a tweet I posted from a shuttle bus to the plane). My intention was to share a practical approach based on my experiences and observations, yet there is no absolute right or wrong in either approach. My guiding principle is always to lean on the safer side. After any security incident, pause everything, make sure we fully understand what happened, how hackers penetrated the systems, which devices were compromised, triple-check all is safe, and then resume operations.
Pausing withdrawals could cause more panic, of course. In 2019, we paused withdrawals for a week after a massive $40 million hack. When we resumed withdrawals (and deposits), we saw more deposits than withdrawals. Not saying this is a better approach. Every situation is different. It’s a judgment call. My tweet was to share what might work and my intention was to show support in a timely manner. I am sure Ben made the best decision based on the info he had.
Ben did a good job maintaining transparent communication and calmness in dealing with a challenging situation. That shows a sharp contrast to other less transparent CEOs, like WazirX, FTX, etc.
The cases mentioned here are all different. FTX was fraud. WazirX, I will refrain from commenting as there is an ongoing lawsuit.
Most importantly, we should never take security for granted. It is important to learn about security yourself so that you can choose the right tools for your needs. For this, I will share an article I wrote a few years ago. It’s a little outdated, but the fundamental concepts still apply. Stay SAFU! https://t.co/WYtTajg1sB
🚀 @Bybit_Official became the world’s second-largest crypto exchange, while the leading exchange, @Binance, has lost some market share due to previous regulatory issues.
That's strong: $26M for those who experienced some problems with Notcoin deposits on Bybit.
Bybit CEO @benbybit announced a compensation plan for those who were affected by delayed deposits and platform performance issues.
👏👏