Connect with us

Uncategorized

North Korean Hackers Were Behind Crypto’s Largest ‘Theft of All Time’

Published

on

Blockchain analytics firm Arkham Intelligence said North Korea’s Lazarus Group was behind Bybit’s $1.46 billion hack.

In an earlier post on social media platform X, Arkham offered a bounty of 50,000 ARKM tokens for anyone who could identify the attackers for Friday’s hack. Later, the platform said onchain sleuth ZachXBT submitted «definitive proof» that the attackers were the North Korean hacker group.

«His submission included a detailed analysis of test transactions and connected wallets used ahead of the exploit, as well as multiple forensics graphs and timing analyses,» the post said.

Read more: Bybit Loses $1.5B in Hack but Can Cover Loss, CEO Confirms

The hack that rocked the crypto market and saw most prices tumbling was called the «largest crypto theft of all time, by some margin,» by Elliptic’s Tom Robinson, co-founder and chief scientist. «The next largest crypto theft would be the $611 million stolen from Poly Network in 2021. In fact it may even be the largest single theft of all time.»

Blockchain data provider Nansen told CoinDesk that the attackers first withdrew nearly $1.5 billion worth of funds from the exchange into a main wallet and then spread the funds across several others.

«Initially, the stolen funds were transferred to a primary wallet, which then distributed them across more than 40 wallets,» Nansen said. «The attackers converted all stETH, cmETH, and mETH to ETH before systematically transferring ETH in $27 million increments to over 10 additional wallets,» Nansen said.

The attack appeared to have been caused by something called «Blind Signing,» where a smart contract transaction is approved without the comprehensive knowledge of its contents.

«This attack vector is quickly becoming the favorite form of cyber attack used by advanced threat actors, including North Korea,» said blockchain security firm Blockaid’s CEO Ido Ben Natan. «It’s the same type of attack that was used in the Radiant Capital breach and the WazirX incident.»

«The problem is that even with the best key management solutions, today most of the signing process is delegated to software interfaces that interact with dApps. This creates a critical vulnerability — it opens the door for malicious manipulation of the signing process, which is exactly what happened in this attack,» he said.

Bybit CEO Ben Zhou wrote earlier on X that a hacker «took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.» He also confirmed that the exchange «is solvent even if this hack loss is not recovered.»

Oliver Knight contributed to the reporting of this story
Read more: Bitcoin, Ether Slump as Crypto Prices Dip on Report of Massive $1.5B Bybit Hack

Continue Reading
Click to comment

Leave a Reply

Ваш адрес email не будет опубликован. Обязательные поля помечены *

Uncategorized

Ether Supply Squeeze? Bybit Hacker Emerges as World’s 14th-Largest ETH Holder

Published

on

By

The Bybit hacker, supposedly a North Korean entity, is now one of the world’s largest ether holders, which may have bullish implications for the cryptocurrency’s spot price.

According to data from Arkham Intelligence and Coinbase executive Connor Grogan, this malicious actor holds 489,000 ETH, valued at approximately $1.34 billion, constituting about 0.4% of ether’s total supply, making it the 14th-largest Ether holder globally. That puts the hacker ahead of the Ethereum Foundation, Ethereum’s CEO Vitalik Buterin and Fidelity.

It’s important to note that the addresses linked to this entity are being closely monitored and backlisted by exchanges, which means the hacker will likely struggle to offload these coins in the market.

In simpler terms, the hacked ether supply is likely lost permanently. Furthermore, Bybit, which has reportedly secured a bridged loan from unnamed partners to cover nearly 80% of the ether lost in the Friday hack, will likely need to purchase coins in the market.

«As far as this supply is concerned, it’s essentially gone. No OTC desk or exchange will facilitate the movement of such a large amount. Meanwhile, Bybit is short 402k ETH. The bridge loan may cover immediate needs, but purchasing will still be necessary,» Vance Spencer, co-founder of the crypto VC firm Framework Ventures, said on X.

That probably explains why ether has bounced 2.6% to $2,730 from the overnight low of around $2,614. Funding rates in perpetual futures tied to ether remain positive, implying a bias for long positions, according to data source Coingecko.

Continue Reading

Uncategorized

Crypto Exchanges Start to Fill Bybit’s $1.4B Hole as Hackers Move Stolen Funds

Published

on

By

Crypto exchange Bitget has transferred 40,000 ether (ETH), worth $105 million, to Bybit, offering crucial support to its industry counterpart in the wake of the over billion-dollar hack suffered by the exchange.

The funds transferred are from Bitget’s own reserves, not user deposits, which remain securely stored on the platform and can be cross checked through the proof of reserves, the exchange’s CEO, Gracy Chen, said in a note shared with CoinDesk, while assuring more support if needed.

«At Bitget we strongly believe in supporting the community and everyone contributing towards the growth of crypto,» Chen said.

A suspected North Korean entity drained approximately $1.4 billion in ether from Bybit on Friday. The hack prompted an unprecedented wave of withdrawal requests from users, with the exchange successfully processing 99% of them, effectively facing a significant market stress test.

Part of the stolen funds started to move during Asian afternoon hours on Saturday with over 5,000 ETH moved through eXch mixer — a service that masks wallet address — before being sent to bridge protocol ChainFlip where the stash was converted to bitcoin (BTC).

In an X post, ChainFlip said it couldn’t block fund movements as it was a fully decentralized applications that relies on automated smart contracts, but that it had «turned off some frontend services to stop the flow.»

On the other hand, Bitget has blacklisted wallets tied to the hacker that drained ether worth millions from Bybit on Friday.

«We will block any transactions flowing in from illicit addresses to the exchange once it has been monitored. Our team of security, and researchers, are currently tracking these activities,» Chen said.

Despite the hack, Bybit had managed to process over 350,000 withdrawal requests and has since restored normal withdrawal operations, per an X post.

Continue Reading

Uncategorized

Arthur Hayes Proposes Rolling Back Ethereum Network to Negate $1.4B Bybit Hack

Published

on

By

Arthur Hayes, BitMEX co-founder and major ether (ETH) holder, asked Ethereum co-founder Vitalik Buterin to rollback the network in order to assist hacked exchange Bybit, which lost nearly $1.4 billion in ether (ETH) on Friday.

«@VitalikButerin will you advocate to roll back the chain to help @Bybit_Official. My own view as a mega $ETH bag holder is $ETH stopped being money in 2016 after the DAO hack hardfork. If the community wanted to do it again, I would support it because we already voted no on immutability in 2016 [wh]y not do it again?» Hayes said on X.

Buterin was yet to reply as of time of publication.

The Bybit hack came into light on Friday when on-chain analyst ZachXBT noted suspicious outflows of over $1.4 billion from the exchange, with the attacker quickly swapping mETH and stETH for ether through a decentralized exchange.

The attacker then split 10,000 ETH to 39 different addresses and another 10,000 ETH to nine addresses, Gautham Santhosh, co-founder of Polynomial.fi, explained on X.

Bybit CEO Ben Zhou said that the hacker «took control of the specific ETH cold wallet and transferred all the ETH in the cold wallet to this unidentified address.» Zhou confirmed that the exchange «is solvent even if this hack loss is not recovered.»

One of the potential ways to address hacking is to roll back the blockchain. It involves reverting the blockchain to a state before the occurrence of a specific event, in this case, the hack. That way, malicious transactions resulting from the hack can be erased, effectively restoring lost or stolen funds. Implementing a rollback requires consensus from the network participants.

For instance, in 2016, the Ethereum network was rolled back using a hard fork to reverse a theft of $60 million in ether from The DAO (30% of all ETH in circulation back then). The hard fork split the chain into two – Ethereum and Ethereum Classic.

In 2019, Binance’s CEO Changpeng Zhao and his team considered pushing for a rollback on the Bitcoin network following a $40 million hack. However, the Bitcoin mining community criticized the idea of going back against the principle of decentralization and immutability, which are fundamental to blockchain technology.

Immutability is a security feature that prevents data from being changed after it’s added to the blockchain to make it trustworthy and tamper-proof. There are similar concerns regarding a potential Ethereum rollover.

«I wish we could roll back for the Bybit hack, I’m not against the idea. But the DAO hack was 15% of ETH with a clean recovery path. Today, a rollback would break bridges, stablecoins, L2s, RWAs and so much more. ETH ecosystem is just too interconnected now for a clean solution like 2016,» Santhosh said.

Sina 21st Capital explained that Ethereum is now stuck between a rock and a hard place.

«Ethereum is toast. They can roll back the chain and destroy what is left of the decentralization claim or allow North Korean baad actors to keep $1.4B of ETH and unleash an eternal internal battle. Either way, it is terrible,» Sina 21st Capital said on X.

Ether has dropped nearly 3% in 24 hours, but continues to trade rangebound between $2,600 and $2,800, CoinDesk data show.

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.