Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Laura Shin. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Laura Shin or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

How the $1.5 Billion Bybit Hack Could Have Been Prevented - Ep. 791

44:21
 
Share
 

Manage episode 468874861 series 1822984
Content provided by Laura Shin. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Laura Shin or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Crypto derivatives exchange Bybit just became the latest victim of North Korea’s elite hacking unit, the Lazarus Group. They didn’t brute-force their way in. They didn’t exploit some obscure vulnerability. Instead, they tricked a trusted developer, slipped in malicious code, and took off with a fortune.

How did this happen? Why was $1.5 billion sitting in a single wallet? What mistakes did Bybit and Safe make? And, more importantly, what needs to change to stop this from happening again?

This week, Mudit Gupta, chief information security officer at Polygon, joins Unchained to expose the security failures, the sophisticated tactics Lazarus used, and why crypto still hasn’t learned its lesson.

Show highlights:

  • 2:11 Mudit’s experience with North Korea’s Lazarus
  • 3:24 How Lazarus perpetrated the $1.5 billion hack
  • 5:55 Why Lazarus relies on social engineering over technical exploits
  • 7:34 Why Bybit was so specifically targeted by the hackers
  • 10:02 What Bybit should have done to prevent the exploit
  • 13:12 Why Mudit believes there was “no reason” to hold so much ETH in one single wallet
  • 15:57 Who should be a signer in multisigs
  • 17:46 How to prevent using a malicious website
  • 19:13 Why Safe should have done things differently, according to Mudit
  • 19:55 How Bybit and Safe handled crisis communication
  • 24:20 Mudit’s must-know security tips for protecting your crypto

Visit our website for breaking news, analysis, op-eds, articles to learn about crypto, and much more: unchainedcrypto.com

Thank you to our sponsors!

Guest

  • Mudit Gupta, Chief Information Security Officer at Polygon

Links

Learn more about your ad choices. Visit megaphone.fm/adchoices

  continue reading

873 episodes

Artwork
iconShare
 
Manage episode 468874861 series 1822984
Content provided by Laura Shin. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Laura Shin or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

Crypto derivatives exchange Bybit just became the latest victim of North Korea’s elite hacking unit, the Lazarus Group. They didn’t brute-force their way in. They didn’t exploit some obscure vulnerability. Instead, they tricked a trusted developer, slipped in malicious code, and took off with a fortune.

How did this happen? Why was $1.5 billion sitting in a single wallet? What mistakes did Bybit and Safe make? And, more importantly, what needs to change to stop this from happening again?

This week, Mudit Gupta, chief information security officer at Polygon, joins Unchained to expose the security failures, the sophisticated tactics Lazarus used, and why crypto still hasn’t learned its lesson.

Show highlights:

  • 2:11 Mudit’s experience with North Korea’s Lazarus
  • 3:24 How Lazarus perpetrated the $1.5 billion hack
  • 5:55 Why Lazarus relies on social engineering over technical exploits
  • 7:34 Why Bybit was so specifically targeted by the hackers
  • 10:02 What Bybit should have done to prevent the exploit
  • 13:12 Why Mudit believes there was “no reason” to hold so much ETH in one single wallet
  • 15:57 Who should be a signer in multisigs
  • 17:46 How to prevent using a malicious website
  • 19:13 Why Safe should have done things differently, according to Mudit
  • 19:55 How Bybit and Safe handled crisis communication
  • 24:20 Mudit’s must-know security tips for protecting your crypto

Visit our website for breaking news, analysis, op-eds, articles to learn about crypto, and much more: unchainedcrypto.com

Thank you to our sponsors!

Guest

  • Mudit Gupta, Chief Information Security Officer at Polygon

Links

Learn more about your ad choices. Visit megaphone.fm/adchoices

  continue reading

873 episodes

Wszystkie odcinki

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play