Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesBotsEarnCopy
$1.5 billion crypto hack exposes bug bounty flaws

$1.5 billion crypto hack exposes bug bounty flaws

GrafaGrafa2025/03/04 06:50
By:Isaac Francis

The recent $1.4 billion hack of cryptocurrency exchange Bybit has highlighted significant vulnerabilities in bug bounty programs, which are crucial for attracting ethical hackers to strengthen platform security.

Ethical hacker Marwan Hachem emphasised that the Bybit hack was facilitated by an "out of scope" bug, which was not covered by the exchange's bug bounty program.

Hachem noted that Bybit's bug bounty offers a maximum reward of $4,000 on its website and up to $10,000 on HackerOne, amounts that are dwarfed by the potential gains for malicious hackers.

He suggested that offering higher rewards to white hat hackers could prevent similar exploits by motivating them to identify vulnerabilities before they are exploited by criminals.

The Bybit hack, attributed to North Korea's Lazarus Group, involved sophisticated phishing techniques and manipulation of the exchange's multi-signature approval process.

Blockchain analytics firm CertiK reported that crypto losses from hacks in February reached $1.53 billion, with Bybit's incident accounting for the majority of these losses.

CertiK also emphasised the need for stricter security measures, including air-gapped signing devices and enhanced authentication layers for high-value transactions.

Regular red-team exercises and phishing simulations can help mitigate social engineering risks, which were central to the Bybit exploit.

"What they considered out of scope led to the biggest crypto hack in history," Hachem pointed out.  

This incident underscores the importance of comprehensive bug bounty programs and robust security protocols to safeguard against increasingly sophisticated cyber threats in the cryptocurrency sector.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Bitcoin’s Grip Loosens As Altcoins Capture the Spotlight

In Brief Michaël van de Poppe sees potential altcoin advantages from Bitcoin Dominance's decline. Major projects like Cardano, Solana, and Toncoin show increasing volume and potential. Investors should maintain calmness during corrections and update their strategies accordingly.

Cointurk2025/05/29 11:25
Bitcoin’s Grip Loosens As Altcoins Capture the Spotlight

UNI Rises Over 11% Amid Whale Purchases

TokenTopNews2025/05/29 11:00
UNI Rises Over 11% Amid Whale Purchases