Unchained

How the $1.5 Billion Bybit Hack Could Have Been Prevented - Ep. 791


Listen Later

Crypto derivatives exchange Bybit just became the latest victim of North Korea’s elite hacking unit, the Lazarus Group. They didn’t brute-force their way in. They didn’t exploit some obscure vulnerability. Instead, they tricked a trusted developer, slipped in malicious code, and took off with a fortune.

How did this happen? Why was $1.5 billion sitting in a single wallet? What mistakes did Bybit and Safe make? And, more importantly, what needs to change to stop this from happening again?

This week, Mudit Gupta, chief information security officer at Polygon, joins Unchained to expose the security failures, the sophisticated tactics Lazarus used, and why crypto still hasn’t learned its lesson.

Show highlights:
  • 2:11 Mudit’s experience with North Korea’s Lazarus
  • 3:24 How Lazarus perpetrated the $1.5 billion hack
  • 5:55 Why Lazarus relies on social engineering over technical exploits
  • 7:34 Why Bybit was so specifically targeted by the hackers
  • 10:02 What Bybit should have done to prevent the exploit
  • 13:12 Why Mudit believes there was “no reason” to hold so much ETH in one single wallet
  • 15:57 Who should be a signer in multisigs
  • 17:46 How to prevent using a malicious website
  • 19:13 Why Safe should have done things differently, according to Mudit
  • 19:55 How Bybit and Safe handled crisis communication
  • 24:20 Mudit’s must-know security tips for protecting your crypto

  • Visit our website for breaking news, analysis, op-eds, articles to learn about crypto, and much more: unchainedcrypto.com

    Thank you to our sponsors!
    • Mantle
    Guest
    Mudit Gupta, Chief Information Security Officer at Polygon


    Links
    • Recent coverage of Unchained on the Bybit hack:
    • North Korean Hackers Are Winning. Is the Crypto Industry Ready to Stop Them?
    • The Chopping Block: Crypto’s Worst Week? Bybit Hack, Libra Scandal, & The Memecoin Reckoning
    • Bits + Bips: Markets Are Down Bad. When Will Crypto Recover?
    • Unchained: Bybit Flows Return to ‘Normal’ After Biggest-Ever Crypto Hack
    • Bybit Hack Forensics Report 
    • "Safe{Wallet} Statement on Targeted Attack on Bybit "
    • Learn more about your ad choices. Visit megaphone.fm/adchoices

      ...more
      View all episodesView all episodes
      Download on the App Store

      UnchainedBy Laura Shin

      • 4.6
      • 4.6
      • 4.6
      • 4.6
      • 4.6

      4.6

      1,184 ratings


      More shows like Unchained

      View all
      Real Vision: Finance & Investing by Real Vision Podcast Network

      Real Vision: Finance & Investing

      902 Listeners

      CoinDesk Podcast Network by CoinDesk

      CoinDesk Podcast Network

      644 Listeners

      The Breakdown by Blockworks

      The Breakdown

      742 Listeners

      The Pomp Podcast by Anthony Pompliano

      The Pomp Podcast

      1,833 Listeners

      On The Brink with Castle Island by Castle Island Ventures

      On The Brink with Castle Island

      293 Listeners

      What Bitcoin Did by Danny Knowles

      What Bitcoin Did

      275 Listeners

      Markets Outlook by CoinDesk

      Markets Outlook

      137 Listeners

      The Wolf Of All Streets by Scott Melker

      The Wolf Of All Streets

      250 Listeners

      Empire by Blockworks

      Empire

      166 Listeners

      Coin Stories with Natalie Brunell by Natalie Brunell

      Coin Stories with Natalie Brunell

      444 Listeners

      Raoul Pal: The Journey Man by Real Vision Podcast Network

      Raoul Pal: The Journey Man

      134 Listeners

      Forward Guidance by Blockworks

      Forward Guidance

      277 Listeners

      The Milk Road Show by The Milk Road Show

      The Milk Road Show

      51 Listeners

      a16z crypto podcast by a16z crypto, Robert Hackett, Sonal Chokshi

      a16z crypto podcast

      60 Listeners

      Limitless Podcast by Limitless by Bankless

      Limitless Podcast

      76 Listeners