Here’s How the Bybit Hacker Stole $1.5B Worth Ethereum?

Share This Post

The post Here’s How the Bybit Hacker Stole $1.5B Worth Ethereum? appeared first on Coinpedia Fintech News

The recent Bybit hack of $1.5 billion has raised serious security concerns, with reports confirming the attackers used a highly sophisticated method to drain millions in crypto assets. Crypto analyst David Leung has provided a detailed breakdown of how the attack unfolded, revealing major lapses in Bybit’s security.

Arkham reports that the bybit



Centralised ExchangeCrypto trading and Information





hack happened through “Blind Signing,” a method that lets transactions be approved without seeing all the details. The attackers compromised Bybit’s ETH cold wallet, moving nearly $1.5 billion in assets into one wallet before spreading them across multiple wallets. Draining funds from the most secured platforms reveals the true nature of crypto assets since there are no uniform laws for international crimes it will be difficult for Bybit to recover the losses. In this context, Bybit has announced a 50,000 ARKM bounty for the attackers further investigations are on. 

Let’s see what happened and how to stay protected. 

How the Attack Happened

The hackers deployed a trojan contract along with a backdoor contract, setting up a trap for Bybit’s upgradeable multisig wallet. They tricked the wallet’s signers into authorizing a seemingly harmless ERC-20 token transfer. However, this transaction contained a delegate call, a function that allowed them to alter the contract’s core logic. Instead of a simple transfer, the attackers used the trojan contract to replace the wallet’s master contract with their own backdoor contract, giving them full control.

Once in control, the hackers executed commands to sweep all available ETH, mETH, stETH, and cmETH tokens from the wallet. Interestingly, the backdoor contract was built to do just two things—transfer ETH and ERC-20 tokens to an address of their choosing. This allowed them to quickly drain the funds before Bybit could react.

Security Red Flags Ignored

Leung further pointed out several red flags that should have halted the transaction. First of all, the transfer was directed to an unlisted contract that wasn’t ERC-20 compliant, involved zero tokens, and used a delegate call, which modifies contract logic. These loopholes should have triggered a compliance check, yet the transaction was still approved. The fact that these security measures failed suggests the attackers had inside knowledge of Bybit’s operations.

Could This Have Been Prevented?

David emphasized that stronger pre- and post-signing security checks could have prevented the attack. If independent security layers had reviewed the transaction, they could have identified the suspicious elements before approval. The hack highlights the growing sophistication of crypto attacks and the urgent need for better security protocols in the industry.

Never Miss a Beat in the Crypto World!

Stay ahead with breaking news, expert analysis, and real-time updates on the latest trends in Bitcoin, altcoins, DeFi, NFTs, and more.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Litecoin (LTC) Faces 25% Crash? Traders Brace for a Sell-Off

The post Litecoin (LTC) Faces 25% Crash Traders Brace for a Sell-Off appeared first on Coinpedia Fintech News Amid the ongoing market uncertainty, while the majority of cryptocurrencies are

Think You Own Your Money? Why Non-Custodial Banking Is the Future of Finance

The post Think You Own Your Money Why Non-Custodial Banking Is the Future of Finance appeared first on Coinpedia Fintech News Imagine waking up one day to discover that your bank has frozen your

Mooshot Passes $1M in Presale Funding: What’s Next For This New Meme Coin?

The post Mooshot Passes $1M in Presale Funding: What’s Next For This New Meme Coin appeared first on Coinpedia Fintech News The rising numbers give a clear picture of Mooshot’s growth The

Bitcoin Price Analysis: Bulls Fight for Control as Bears Threaten a Massive Sell-Off

Bitcoin is trading at $96,688 with a market capitalization of $191 trillion and a 24-hour trading volume of $4488 billion, moving within an intraday range of $94,805 to $99,262 as technical

Cardano Stabilizes, But Skyren DAO’s Free Airdrop to Remittix Investors Steals the Spotlight

The post Cardano Stabilizes, But Skyren DAO’s Free Airdrop to Remittix Investors Steals the Spotlight appeared first on Coinpedia Fintech News After weeks of volatility, Cardano (ADA) has found

$5.7M Bybit Crypto Scam Lands Ex-Employee Nearly 10 Years in Prison—Details

A former payroll processing staff member at Bybit, Ho Kai Xin, has recently been sentenced to nine years and 11 months in jail on February 20 The charges stemmed from her fraudulent activities that