{"id":829859,"date":"2025-02-26T08:11:41","date_gmt":"2025-02-26T14:11:41","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/02\/26\/bybit-reels-from-1-5b-hack-by-north-korea\/"},"modified":"2025-02-26T08:11:41","modified_gmt":"2025-02-26T14:11:41","slug":"bybit-reels-from-1-5b-hack-by-north-korea","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/02\/26\/bybit-reels-from-1-5b-hack-by-north-korea\/","title":{"rendered":"Bybit reels from $1.5B hack by North Korea"},"content":{"rendered":"<div>\n<div>\n<ol>\n<li><a href=\"https:\/\/coingeek.com\">Homepage<\/a><\/li>\n<li> > <\/li>\n<li><a href=\"https:\/\/coingeek.com\/news\/\">News<\/a><\/li>\n<li> > <\/li>\n<li><a href=\"https:\/\/coingeek.com\/news\/category\/business\/\"><br \/>\n                                Business<br \/>\n                       <\/a><\/li>\n<li> > <\/li>\n<li>Bybit reels from $1.5B hack by North Korea<\/li>\n<\/ol>\n<\/div>\n<p>The record-setting hack of the <a href=\"https:\/\/coingeek.com\/news\/tag\/bybit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bybit<\/a> digital asset exchange and the ensuing calls to roll back the <a href=\"https:\/\/coingeek.com\/news\/tag\/ethereum\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ethereum<\/a> network (again) prove the need for proper legal recourse when customers are illegally deprived of their assets.<\/p>\n<p>Panic spread through the \u2018crypto\u2019 world on February 21 after Bybit was hacked for over $1.4 billion worth of Ethereum\u2019s <a href=\"https:\/\/coingeek.com\/ethereum-co-founders-knew-eth-was-a-security-from-the-get-go-insider-says\/\" target=\"_blank\" rel=\"noreferrer noopener\">ETH<\/a> token, the largest exploit of its kind\u2014in crypto or beyond. The role of crypto Paul Revere was played by blockchain researcher <a href=\"https:\/\/x.com\/zachxbt\/with_replies\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">@ZachXBT<\/a>, who almost immediately flagged North Korea\u2019s infamous <a href=\"https:\/\/coingeek.com\/news\/tag\/lazarus-group\/\" target=\"_blank\" rel=\"noreferrer noopener\">Lazarus Group<\/a> of hackers as <a href=\"https:\/\/x.com\/arkham\/status\/1893033424224411885\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the culprits behind the Bybit exploit<\/a>.<\/p>\n<p>Bybit CEO Ben Zhou <a href=\"https:\/\/x.com\/benbybit\/status\/1892963530422505586\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed the exploit<\/a>, which occurred as the exchange was transferring tokens from an ETH <a href=\"https:\/\/coingeek.com\/news\/tag\/multi-signature\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-sig<\/a> cold wallet to its \u2018warm\u2019 wallet. The exploiters had installed malicious code that allowed Bybit staff to see what they believed was occurring.<\/p>\n<p>But behind the scenes, the hackers were altering the smart contract logic to grant themselves access to Bybit\u2019s <a href=\"https:\/\/coingeek.com\/wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cold wallet<\/a>. The entirety of the wallet\u2019s contents were then transferred to a different wallet outside Bybit\u2019s control.<\/p>\n<p>Bybit <a href=\"https:\/\/x.com\/Bybit_Official\/status\/1892965292931702929\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tried to calm the waters<\/a> by insisting that all customer funds were safe, but customers understandably freaked out and began flooding the exchange with withdrawal requests. Later, on a livestream, Zhou said 70% of these withdrawals had been \u201capproved and processed\u201d but warned that \u201cnetwork congestion\u201d meant customers might have to wait a few hours to be reunited with their funds.<\/p>\n<p>Bybit later said it had secured a \u201cbridge loan\u201d to ensure it had enough ETH to process \u2018in-kind\u2019 withdrawals. <a href=\"https:\/\/x.com\/lookonchain\/status\/1893852261027140041\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Lookonchain<\/a> reported that Bybit had received nearly 447,000 ETH via \u201cloans, whale deposits and ETH purchases\u201d from <a href=\"https:\/\/coingeek.com\/news\/tag\/galaxy-digital\/\" target=\"_blank\" rel=\"noreferrer noopener\">Galaxy Digital<\/a>, FalconX, Wintermute and others. By late Sunday, Zhou <a href=\"https:\/\/x.com\/benbybit\/status\/1893865556840775758\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">claimed<\/a> the site was back to \u201c100% 1:1 on client assets,\u201d and all withdrawals were processing as normal.\u00a0<\/p>\n<p>While Zhou insisted that Bybit\u2019s ETH wallet was the only one of its access points to be compromised in this fashion, <a href=\"https:\/\/x.com\/adamscochran\/status\/1893292386001866783\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">not everyone is convinced<\/a>. The thinking goes, if Lazarus could boldly infiltrate and exploit the exchange without Bybit\u2019s knowledge, how could it be sure that additional vulnerabilities aren\u2019t lurking in its existing hardware, servers, and other infrastructure?<\/p>\n<p>There are also suspicions that Bybit may have one or more moles in their midst. North Korea has become infamous for sending members of its hacking groups out into the wild with fake documentation\/backstories seeking jobs at blockchain projects. Once onboarded, they have a greater capacity to probe for flaws in security protocols with predictable results.<\/p>\n<p>As far as most Bybit customers are concerned, the immediate crisis is past. That said, Bybit still has a $1.4 billion hole in its books; it\u2019s just been papered over by new debt and other obligations.<\/p>\n<p><strong>Kim Jong-unbelievable<\/strong><\/p>\n<p>While everyone was focused on getting their money off Bybit as fast as possible, the hackers were busy laundering their ill-gotten gains.<\/p>\n<p>First, they split the stolen ETH into smaller chunks, which were then transferred to dozens of wallets. After that, the tokens were sent to various Ethereum-based <a href=\"https:\/\/coingeek.com\/the-defi-report-why-decentralised-finance-defi-matters-and-the-policy-implications\/\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized finance<\/a> (DeFi) platforms, including Sky (<a href=\"https:\/\/www.bnnbloomberg.ca\/business\/company-news\/2024\/08\/27\/defi-platform-makerdao-rebrands-itself-as-sky-to-bolster-usage\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the rebranded MakerDAO<\/a>), <a href=\"https:\/\/coingeek.com\/news\/tag\/okx\/\" target=\"_blank\" rel=\"noreferrer noopener\">OKX<\/a> DEX and <a href=\"https:\/\/coingeek.com\/news\/tag\/uniswap\/\" target=\"_blank\" rel=\"noreferrer noopener\">Uniswap<\/a>.<\/p>\n<p>The hackers\u2019 initial focus appears to have been on swapping ETH for DAI, the <a href=\"https:\/\/makerdao.com\/en\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">MakerDAO\/SKY-issued decentralized stablecoin<\/a> that lacks the ability to freeze tokens on-chain. Blockchain researchers Elliptic later <a href=\"https:\/\/www.elliptic.co\/blog\/bybit-hack-largest-in-history\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a> that, given Lazarus\u2019s traditional methods, the next step would be to send tokens to <a href=\"https:\/\/coingeek.com\/news\/tag\/coin-mixer\/\" target=\"_blank\" rel=\"noreferrer noopener\">coin mixers<\/a>. Lazarus has previously been <a href=\"https:\/\/coingeek.com\/tornado-cash-founders-charged-in-1-billion-money-laundering-scheme-including-for-north-korea\/\" target=\"_blank\" rel=\"noreferrer noopener\">flagged for using mixers<\/a> like <a href=\"https:\/\/coingeek.com\/news\/tag\/tornado-cash\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash<\/a> to obfuscate the trail of their getaway cars. (Good thing <a href=\"https:\/\/coingeek.com\/crypto-bros-money-launderers-celebrate-tornado-cash-ruling\/\" target=\"_blank\" rel=\"noreferrer noopener\">U.S. courts have taken a shine<\/a> to Tornado Cash, huh?)<\/p>\n<p>Bybit has offered a bounty of up to 10% of recovered tokens and <a href=\"https:\/\/x.com\/Bybit_Official\/status\/1893687749229563958\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">publicly thanked<\/a> several DeFi entities\u2014as well as the <a href=\"https:\/\/coingeek.com\/news\/tag\/tether\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tether<\/a> stablecoin issuer for freezing 181,000 <a href=\"https:\/\/coingeek.com\/news\/tag\/usdt\/\" target=\"_blank\" rel=\"noreferrer noopener\">USDT<\/a>\u2014for doing what they could to stem this tide.<\/p>\n<div>\n<p>Notable for their exclusion from this \u2018thank you\u2019 card is eXch, a non-KYC (know your customer) exchange that <a href=\"https:\/\/x.com\/vxdb\/status\/1893373653129003043\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">received some of the stolen tokens<\/a>. On the Bitcoin Talk forum, eXch posted an email it received from Bybit asking it to freeze tokens, to which eXch <a href=\"https:\/\/x.com\/MistTrack_io\/status\/1893516845506011180\/photo\/1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">offered a flippant response<\/a> citing what it claimed were \u201cdirect attacks on the reputation of our exchange by ByBit over the past year.\u201d<\/p>\n<p>eXch went on to claim that it wanted \u201ca clear explanation as to why we should consider providing assistance to an organization that has actively undermined our reputation.\u201d Bybit\u2019s Zhou <a href=\"https:\/\/x.com\/benbybit\/status\/1893519210883744188\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tweeted<\/a> his hope that eXch would \u201creconsider\u201d its position, given that the situation was \u201creally not about Bybit or any entity, it\u2019s about our general approach towards hackers as an industry.\u201d\n<\/p>\n<\/div>\n<p>Responding to <a href=\"https:\/\/t.me\/investigations\/212\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">allegations by ZachXBT<\/a> (<a href=\"https:\/\/x.com\/bax1337\/status\/1893414227299172397\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">and others<\/a>) regarding its role in this affair, eXch <a href=\"https:\/\/bitcointalk.org\/index.php?topic=577207.1300\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">insisted<\/a> that it \u201cis NOT laundering money for Lazarus\/DPRK.\u201d eXch added that it had only processed an \u201cinsignificant portion of funds from the ByBit hack\u201d and said the fees derived from this \u201cisolated case\u201d would be \u201cdonated for the public good.\u201d<\/p>\n<p><strong>Does anyone have one of those Men in Black memory-wiping thingies?<\/strong><\/p>\n<p>The sheer scale of the heist, along with the fact that it was entirely focused on ETH, led to calls for Ethereum\u2019s gatekeepers to take a page out of history and roll the network back to its pre-hack state to \u2018undo\u2019 the theft.\u00a0<\/p>\n<p>In 2016, Ethereum <a href=\"https:\/\/coingeek.com\/its-all-decentralized-until-someone-gets-rekt\/\" target=\"_blank\" rel=\"noreferrer noopener\">chose that nuclear option<\/a> following the exploit of TheDAO, a <a href=\"https:\/\/coingeek.com\/news\/tag\/decentralized-autonomous-organization\/\" target=\"_blank\" rel=\"noreferrer noopener\">decentralized autonomous organization<\/a> that lost 3.6 million ETH. That was 9x the number of ETH tokens stolen from Bybit, although ETH was worth only a fraction of its current value in 2016.<\/p>\n<p>Following a contentious vote in which ETH whales were given a greater say than the plebs, the network underwent a hard fork that returned the tokens to their rightful owners. However, a vocal minority insisted this violated the \u2018code is law\u2019 tenet and chose to stick with the original network, which was renamed Ethereum Classic.<\/p>\n<p>While the suggestion of a new hard fork was raised almost immediately following news of Bybit\u2019s victimization, nobody expects Ethereum to go through all that again. For one thing, TheDAO\u2019s <a href=\"https:\/\/coingeek.com\/bitcoin101\/bitcoin-smart-contracts\/\" target=\"_blank\" rel=\"noreferrer noopener\">smart contract<\/a> imposed a month-long pause on transactions, meaning the stolen tokens were still technically there, just inaccessible absent the fork. Meanwhile, the Bybit tokens are being moved and converted as we speak.<\/p>\n<p>That said, calls for a rollback would have been much louder had Bybit not taken the as-yet-not-completely-understood financial steps to ensure customers weren\u2019t left holding the (empty) bag. The price of ETH, which took a precipitous dip as news of the hack broke, recovered most of its losses, only to sink again on February 24 after people remembered it was still ETH.\u00a0<\/p>\n<p><strong>A better way<\/strong><\/p>\n<p>Imagine that Bybit\u2019s losses involved a different token on a different chain, one that required its nodes\u2014including the entities responsible for processing transactions\u2014to abide by a set of <a href=\"https:\/\/bsvblockchain.org\/bsv-association-launches-new-network-access-rules\/\" target=\"_blank\" rel=\"noreferrer noopener\">Network Access Rules<\/a> (NAR). These rules would ensure an honest, law-abiding network environment, offering users greater transparency and a degree of confidence that\u2019s sorely lacking in most other chains.<\/p>\n<p>Now imagine that this other network has a functional <a href=\"https:\/\/coingeek.com\/bitcoin-alert-key-still-pressing-legal-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">Alert System<\/a> that can (among other things) sound the alarm when \u2018crypto crooks\u2019 get their hands on tokens that don\u2019t belong to them. A system that could signal network nodes to freeze tokens in place before the bad guys can direct their stolen loot into a coin mixer or <a href=\"https:\/\/coingeek.com\/estimated-4b-laundered-via-dexs-coin-swaps-and-bridges-report\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-chain bridge<\/a>.<\/p>\n<p><em>Now<\/em>, imagine that this network can utilize these rules and tools to provide a service called <a href=\"https:\/\/bsvblockchain.org\/news\/taking-the-complexity-out-of-digital-asset-recovery\/\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Asset Recovery<\/a> (DAR). This allows theft victims to make a complaint, which would be investigated thoroughly to ensure that the victim has a rightful claim to the tokens in question.<\/p>\n<p>A court order is then obtained, and the network broadcasts the specifics to the network nodes, which are then obligated to freeze the tokens on-chain. The frozen tokens are then destroyed, and replacements are issued at the tip of the chain to their rightful owner(s), with the full history and origin of the tokens available to all.<\/p>\n<p>Sounds a lot like legitimate legal recourse in real life, doesn\u2019t it? Unless we missed that section of the <a href=\"https:\/\/coingeek.com\/bitcoin-16th-anniversary-reckoning-with-original-vision\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitcoin white paper<\/a> where it says the network is an anarchic hybrid of <a href=\"https:\/\/www.youtube.com\/watch?v=GoRPVsN2SVM\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Mos Eisley<\/a>\u00a0and <a href=\"https:\/\/youtu.be\/9yDL0AKUCKo?si=0iNU3j-5K0i5mu2i&#038;t=97\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Thunderdome<\/a>, it seems like the basic laws of property should still apply on the blockchain, shouldn\u2019t they?<\/p>\n<p>Just sayin\u2019, but if the Bybit scandal had occurred on <a href=\"https:\/\/bsvblockchain.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">this network<\/a>, the uproar wouldn\u2019t have lasted past lunchtime.<\/p>\n<p>Watch: Chronicle Upgrade, Teranode, and Bitcoin Stewardship<\/p>\n<p><iframe src=\"https:\/\/www.youtube.com\/embed\/jbG2Lv62O4M?si=jNQlWK1laUyhBSE8&#038;controls=0\" frameborder=\"0\" allowfullscreen> title=&#8221;YouTube video player&#8221; frameborder=&#8221;0&#8243; allow=&#8221;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&#8221; referrerpolicy=&#8221;strict-origin-when-cross-origin&#8221; allowfullscreen=&#8221;&#8221;><\/iframe><\/p>\n<div>\n<p><h3>Tagged:<\/h3>\n<\/p>\n<\/div><\/div>\n<p><a href=\"https:\/\/coingeek.com\/bybit-reels-from-1-5b-hack-by-north-korea\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Steven Stradbrooke<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Homepage &gt; News &gt; Business &gt; Bybit reels from $1.5B hack by North Korea The record-setting hack of the Bybit digital asset exchange and the ensuing calls to roll back the Ethereum network (again) prove the need for proper legal recourse when customers are illegally deprived of their assets. Panic spread through the \u2018crypto\u2019 world<\/p>\n","protected":false},"author":1,"featured_media":829860,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[86510,94044],"tags":[],"class_list":{"0":"post-829859","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-bybit","8":"category-reels"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/829859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=829859"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/829859\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/829860"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=829859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=829859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=829859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}