meta_pixel
Tapesearch Logo
Log in
Unchained

How the $1.5 Billion Bybit Hack Could Have Been Prevented - Ep. 791

Unchained

Laura Shin

News, Tech News, Business News

4.51.3K Ratings

🗓️ 28 February 2025

⏱️ 44 minutes

🧾️ Download transcript

Summary

Crypto derivatives exchange Bybit just became the latest victim of North Korea’s elite hacking unit, the Lazarus Group. They didn’t brute-force their way in. They didn’t exploit some obscure vulnerability. Instead, they tricked a trusted developer, slipped in malicious code, and took off with a fortune. How did this happen? Why was $1.5 billion sitting in a single wallet? What mistakes did Bybit and Safe make? And, more importantly, what needs to change to stop this from happening again? This week, Mudit Gupta, chief information security officer at Polygon, joins Unchained to expose the security failures, the sophisticated tactics Lazarus used, and why crypto still hasn’t learned its lesson. Show highlights: 2:11 Mudit’s experience with North Korea’s Lazarus 3:24 How Lazarus perpetrated the $1.5 billion hack 5:55 Why Lazarus relies on social engineering over technical exploits 7:34 Why Bybit was so specifically targeted by the hackers 10:02 What Bybit should have done to prevent the exploit 13:12 Why Mudit believes there was “no reason” to hold so much ETH in one single wallet 15:57 Who should be a signer in multisigs 17:46 How to prevent using a malicious website 19:13 Why Safe should have done things differently, according to Mudit 19:55 How Bybit and Safe handled crisis communication 24:20 Mudit’s must-know security tips for protecting your crypto Visit our website for breaking news, analysis, op-eds, articles to learn about crypto, and much more: unchainedcrypto.com Thank you to our sponsors! Mantle Guest Mudit Gupta, Chief Information Security Officer at Polygon Links Recent coverage of Unchained on the Bybit hack: North Korean Hackers Are Winning. Is the Crypto Industry Ready to Stop Them? The Chopping Block: Crypto’s Worst Week? Bybit Hack, Libra Scandal, & The Memecoin Reckoning Bits + Bips: Markets Are Down Bad. When Will Crypto Recover? Unchained: Bybit Flows Return to ‘Normal’ After Biggest-Ever Crypto Hack Bybit Hack Forensics Report  "Safe{Wallet} Statement on Targeted Attack on Bybit " Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

Imagine like if one developer had access to the bank's website and allowed people to transfer anything.

0:05.0

That would be very stupid and it's not, it doesn't happen anymore.

0:09.0

You will never hear of anything like that.

0:12.0

So why are we still having those scenarios in our industry is like, is very crazy.

0:19.0

Hi everyone, welcome to Unchained, your No High Presby. is like, it's very crazy.

0:24.1

Hi, everyone. Welcome to Unchained.

0:25.8

You're no hype resource for all things crypto.

0:27.5

I'm your host, Laura Shin.

0:30.7

We are now featuring quotes from listeners on the show.

0:33.8

Today we have one from Crypto Culgan on X,

0:38.1

responding to the recent episode on the Bybit hack with Taylor Monaghan and Jaunty about how the last risk group is targeting people, not products.

0:42.9

Cryptoculkin wrote, humans are still the weakest link in cybersecurity.

0:47.3

Sometimes you just need a single human error and the hackers are in.

0:51.0

Having good processes, for example, maker checker slash dual control, mitigate the risk,

0:56.8

but it can never be zero. To have your comment featured, write a review of the podcast overall,

1:01.9

or leave a comment on our video on YouTube or X. This is the February 28th, 2025 episode of Unchained.

1:09.0

Mantle is building the future of on-chain finance.

1:11.9

Experience its enhanced index fund,

1:14.3

Mantle banking, and MantleX.

1:16.5

Visit group.mantle.xy to learn more.

1:19.8

Today's guest is Mutukubta,

1:21.7

Chief Information Security Officer at Polygon.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Laura Shin, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Laura Shin and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.