Загрузка видео...

Не удалось загрузить видео

На главную

The $1.46 ByBit hack is WAY SIMPLER then you Think! Simple explanation along with the permanent solution (which we built already and will be showing off at #ETH Denver). Everything we know and why in 🧵below🌂

12,213 просмотров • 1 год назад •via X (Twitter)

Комментарии: 11

Фото профиля Mehow
Mehow1 год назад

2/ In detail. The attackers hijacked the UI of the @safe multisig signers. The end point of that signature is a @Ledger. Watch the stream from @benbybit and he tells you that indeed he just didn't really look at the Ledger screen and essentially transferred control of the assets to the hackers (this means that the other signers fell victim to the same hack).

Фото профиля Mehow
Mehow1 год назад

3/ There's probably nothing wrong with the on chain code at @safe. The problem is at the end point, the Ledger in this case. The end point doesn't understand the safe protocol or what addresses it's actually signing. Incredibly unlikely that the Ledger was fooled in this case. It probably just displayed a bunch of non human readable addresses or "business as usual" messaging. Ben and the other signers saw what they usually see and just signed it.

Фото профиля Mehow
Mehow1 год назад

4/. So how do you prevent this from ever happening again. Step 1. Stop using non human readable addresses. Just use names that are cryptographically tied to their seeds. It's like decentralized, private, Paypal for all of crypto. Check out our beta at @SwissFortress.com. This software was developed by @MatterFi_com. If our system is used the Ledger and our own custom hardware wallets will display the name of the counterparty along with a KYC proof. Both are cryptographic proofs meaning they are not spoof-able. This means that regardless of the manipulation done by the hackers in the safe UI in normal operations the ledger would simply say "send ETH to hot wallet (along with crypto proof)" that the ledger ITSELF would understand. Meanwhile any hacked transaction submitted for signing to the Ledger will display an error message similar to what you get when you go to a website that has known malware. Ergo: hack not impossible but infinitely easier to catch.

Фото профиля Mehow
Mehow1 год назад

5/ Prevention. Step 2. The final solution that beefs this security up even more is to use end to end crypto proofs to manage all off chain funds in custody. We're are currently deploying this tech at a major Fortune 100 customer in US/Europe. In this scenario, again built by @MatterFi_com, end user private keys are used to manipulate all the crypto on and off chain. So in our ideal deployment the cold wallet would be automated and managed via HSM and controlled by end to end crypto proofs always displayed on hardware devices. We can even integrate the off chain crypto proof engine with DeFi multisig storage solutions such as safe. Then the possibility of the web UI hack and "the URL looked correct" error @benbybit is impossible. That's because when you are running end to end crypto proofs OFF CHAIN you don't need web3 anything. Our tech removes VAST swathes of the possible attack surface. Here to help, DM us or see us at DNA house and Bit angeles at ETH Denver.

Фото профиля Milk Road
Milk Road2 лет назад

Wall Street ain't ready for this... Coinbase launched Base ~1 year ago This Layer 2 blockchain has raked in ~$1.2M every week on average Now Wall Street is FOMOing into crypto. Front run them by reading Milk Road. 5 minutes. Every day. For free.

Фото профиля ⚡DigitalFellow 🦆
⚡DigitalFellow 🦆1 год назад

I'm not a hacker, but every time I try to log in to Bybit using Google Authentication, it feels like my assets aren't safe.

Фото профиля Mehow
Mehow1 год назад

Yes that’s right. They could be way safer. Note you don’t need GA to use any non custodial wallet. Thats because every transaction on chain is signed with your private key. So what we did is made it that every transaction either on or off chain is signed by your keys. So now you just need one wallet to control all your assets and you don’t need GA. So in our custody system the users sign for say a bid/ask or instant transfer to another user or their own withdrawal with their keys just like they do for a transfer or defi on chain. Meanwhile the HSMs directly understand the protocol and since they get a crypto proof from the user no multisig signing required at all by people. So our custody system largely eliminates the need for cold storage as the vulnerability is the custodians keep needing to use cold storage for daily ops which is exactly what the hackers are exploiting. I’ll drop a simple video on that soon.

Фото профиля John_Sarson
John_Sarson1 год назад

We need this tech pls

Фото профиля Mehow
Mehow1 год назад

Ya I already tagged ByBit. We have a really strong advisory team now @michaelterpin @Coachkcrypto @CryptoRocky CryptoBirb and @brockpierce was one of our OG seed investors. So now all the right conversations are being had to get this rolled out and for example #mega Make Etherium Great Again via private automated addressing. To reserve a name you can. go to And feel free to join our zealy campaign at to join beta report bugs and earn some tokens.

Фото профиля Robb Allen
Robb Allen1 год назад

@JCryptoRider Nice

Фото профиля Leroy Jay
Leroy Jay1 год назад

This is a major hack in crypto history. Surely this tech is needed now more than ever.

Похожие видео