If a bank were to be hacked for $1.4 billion:
- Freeze withdrawals
- Inform government
- Set up an inquiry commission
- years of investigation
- Customers standing in queue
- Branches closed
- Competitors getting an advantage
Bybit exchange hacked $1.4 billion.
- CEO came live
- Industry united
- Competitors lend support
- 1 hr and everything back to normal
- Industry itself is tracking and freezing
- Zero withdrawal pending
This is what they don't like about crypto -> UNITY.
Some thoughts on the recent hack(s).
There is a pattern where hackers were able to steal large amounts of crypto from multi-sig “cold storage” solutions, as with ByBit, Phemex, WazirX and potentially others. In the most recent ByBit case, the hackers were able to make the front-end user interface show a legitimate transaction while the actual signing was for a different transaction. I am less familiar with the other cases, but they sound similar based on limited available info.
What’s more scary is that the affected exchanges used different multi-sig solution providers. The hackers, the Lazarus Group, are highly advanced and broad in their abilities to penetrate. It is still unclear whether the hackers were able to penetrate multiple signing devices, or the server side, or both in each of these cases.
Some people questioned my suggestion of halting all withdrawals as a standard security precaution (in a tweet I posted from a shuttle bus to the plane). My intention was to share a practical approach based on my experiences and observations, yet there is no absolute right or wrong in either approach. My guiding principle is always to lean on the safer side. After any security incident, pause everything, make sure we fully understand what happened, how hackers penetrated the systems, which devices were compromised, triple-check all is safe, and then resume operations.
Pausing withdrawals could cause more panic, of course. In 2019, we paused withdrawals for a week after a massive $40 million hack. When we resumed withdrawals (and deposits), we saw more deposits than withdrawals. Not saying this is a better approach. Every situation is different. It’s a judgment call. My tweet was to share what might work and my intention was to show support in a timely manner. I am sure Ben made the best decision based on the info he had.
Ben did a good job maintaining transparent communication and calmness in dealing with a challenging situation. That shows a sharp contrast to other less transparent CEOs, like WazirX, FTX, etc.
The cases mentioned here are all different. FTX was fraud. WazirX, I will refrain from commenting as there is an ongoing lawsuit.
Most importantly, we should never take security for granted. It is important to learn about security yourself so that you can choose the right tools for your needs. For this, I will share an article I wrote a few years ago. It’s a little outdated, but the fundamental concepts still apply. Stay SAFU! https://t.co/WYtTajg1sB
I do agree with CZ that if this hack was conducted through penetrating our internal systems such as any part of the withdraw system or one of our hot wallet was breached, we would've halted all withdraws until we find the root cause of the problem. In the case of yesterday, it was our ETH cold wallet which we use @safe that was breached, it had nothing to do with any of our internal systems so it was easy for me to make the call to maintain all withdraw and system functions of Bybit as usual.
Binance and CZ was among many of the partners and industry leaders that offered to help us during last night fiasco. We are extremely grateful and simply overwhelmed with all the support that we got. This was a truly tragic event for Bybit but the industry showed strength united together. I have faith that it's only up from now.