The biggest hack ever – and its paradoxical influence on the price of ETH

The biggest hack ever – and its paradoxical influence on the price of ETH
The rocket will save it: picture from a North Korean school. Image of (Stephan) via Flickr.com. License: Creative Commons

At the weekend the Bybit stock exchange was hacked. With a prey of around $ 1.5 billion in ether, this was the biggest crypto paint ever – and probably even the greatest theft in history. Behind the hack there is a well -known villain, while bybit puts it away amazingly carelessly. The consequences for the price of Ethereum, on the other hand, are paradoxical.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

Bybit was chopped on Friday evening. The crypto exchange registered in Dubai lost a good 400.000 ether, in the form of native ETH, but also staked ether (Steth, Cmeth). This corresponds to 0.42 percent of all ETH and a value of around $ 1.5 billion.

The Bybit hack is thus the largest hack of the ecosystem ever. He sets the previous record, the Hack of Poly Network, just over $ 600 million, far in the shade. In general, the bybit hack is the most expensive hack ever, even, as the blockchain analyst Elliptic thinks, the greatest theft in human history.

baner a:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

The victim of this greatest theft of all time, bybit, is of course difficult to hit – but, surprisingly, does not go bankrupt. Bybit CEO Ben Zhou immediately announced that the stock exchange could remain liquid and take over the damage. Another BYBIT manager, Shunyet, explains in an interview with Colin Wu what happened in the dramatic hours after the hack: the stolen ether accounted for about 70 percent of the total ETH portfolio, so the stock exchange had to temporarily switch off ETH payments and gradually decreased, especially for larger customers with a high volume.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

Thanks to the help of other exchanges, such as Bitget and MexC, as well as large OTC dealers, bybit was able to quickly close the gaps. With cheap loans, the stock exchange filled up its ether and, less than 12 hours after the hack, operated withdrawals. That a stock exchange is so easy for the biggest hack of all time – that too is record -breaking.

The crime scene is also sensational.

How to crack the gold standard of wallet security

Bybit kept her ether in a cold multinisig wallet: a wallet that is not connected to the Internet, but is secured by several keys. This is actually the absolute gold standard of security. It should be unhappy.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

However, the hackers gained access through a sophisticated, multi -layered attack. First you cloned the interface through which the key custodians sign transactions with the Cold Wallet. Then you managed to guide this to the cloned interface so that you sign a prepared transaction. However, this has not deducted any ether from the wallet, but changed the code of the Smart Contract so that the hackers received full access to it.

The hack is a masterpiece on so many levels: it initially needs access to the interface. After that, the signers involved must be made to visit the cloned page and also sign a transaction that should actually be suspicious. According to experts, the last step, the manipulation of the smart contracts, also requires a deep insight into the EVM, the surroundings of the smart contracts. How this could succeed remains speculation for the time being. There was a mole at Bybit? Were hardware wallets that are used for signing, manipulated?

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

There is more clarity, on the other hand, who the hackers are.

This country is behind the hack

After Arkham Intelligence put out a bounty, the analyst ZachxBt demonstrated traces that lead to the Lazarus Group from North Korea. He did not find the traces in the hack itself, but in what happened afterwards: the subsequent transactions with which the hackers veiled the prey combined them with an address that was involved in earlier Lazarus hacks. The pattern of money laundering also follows the standard of Lazarus, as Elliptic explains:

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

  • First the tokenized ether like Steth is switched to decentralized stock exchanges against native ether
  • These are then distributed via complex transaction patterns to a variety of wallets and
  • Via decentralized Bridges to various blockchains
  • To be further veiled by mixers like Tornado Cash or Cryptomixer

This happened. The 400.000 ether landed on 50 different wallets, each of which is about 10.000 ether held. These were then systematically emptied. As far as possible, some stock exchanges and service providers, such as Tether, have intervened by blacklists and confiscation. But the absolute majority of the prey moves freely on the blockchain, sometimes Ether has already been exchanged for dollars over Exch, a rather black change platform,.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

So North Korea is probably the largest ether holder. Lazarus is something like the country’s hacker elite. They are still known from the Ransomware wave Wannacry, which also caught Deutsche Bahn, but also from a large number of large cryptoks, such as Ronin (Axie Infinity), Harmony, Atomic Wallet or, only last year, the Indian Stock Exchange Wazirx, who lost $ 230 million to Coins. Actually, North Korean hackers have attacked companies in South Korea, but now they are looking for victims around the world with ransomware and hacks.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

The hackers are highly professional and creative. Overall, they are attributed to hacks of more than three billion dollars. This puts a significant proportion of the country’s gross national product, which is only about $ 40 billion, and, even more, of his access to foreign exchange, which is significantly more difficult by financial sanctions. Some observers believe that the country can only pay its nuclear weapons program thanks to the proceeds from crypto hacks, which is probably speculation.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

There are also estimates that Lazarus of the 14.-The biggest Bitcoin-Holder is.

What does that mean for the price of ETH?

You can only speculate about the influence of the hack on the price of ether. On the one hand, the hack does not pay into the trust in Ethereum, especially if there are further discussions, whether the developers and stakers should reverse the hack through a rollback, i.e. a hardfork,. But technically, the hack can also be good for the price.

Because first of all, Bybit pushed the ether to plug the gap in the balance sheet. She did not bought the stock exchange, but borrowed, hoping that there will be a chance to get it back from the hacker. This should be excluded from the Lazarus Group. Because the hackers have never negotiated or returned a prey. For Bybit, the loan only causes interest. To avoid this, it will buy ether as quickly as possible.

banera:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

Lazarus on the other side is a patient player. The process of money laundering stretches over numerous steps, so it takes years for the Ether to be completely sold. If at all. Lazarus still has numerous millions of hacks from 2016. In practice, the hack has withdrawn a large amount of ether for the market. Not much different than a sovereign fund would do.

And basically the 400 are.000 Ether exactly that: a state fund from North Korea, consisting of coins that the government has acquired through a hack and which, depending on the need and opportunity, it will only be used in terms of droplets.

baner a:hover imgbox-shadow:0 0 20px 5px rgba(255,0,0,0.6);

Article written by

×