Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Kim Jong Un’s sting: How North Korea orchestrated the biggest cyber heist in history
El Pais ^ | 4/4/25 | Manuel G. Pascual

Posted on 04/05/2025 11:17:45 AM PDT by EnderWiggin1970

It all happened overnight and in a matter of minutes. Ben Zhou, CEO of the cryptocurrency exchange Bybit, made a series of routine transfers from his home computer. A short while later, his company called to inform him that his reserves of Ethereum, the second most-used cryptocurrency after Bitcoin, worth $1.5 billion, had vanished. By then, the ethers had already been transferred to thousands of other people’s digital wallets. Bybit had just suffered the largest theft in history. Five days later, the FBI confirmed what some analysts suspected from the outset: the attack was the work of Lazarus, a hacking group supported by the North Korean government that has become the scourge of the crypto sector.

Zhou went out of his way to appear calm on social media immediately after the cyberattack, even sharing the heart rate displayed on his smartwatch to convey that everything was under control. The entrepreneur assured his clients affected by the theft that they would receive 100% of their deposits back. Fearing a panic in the sector, some of Bybit’s competitors, such as Byget, lent Zhou $100 million in interest-free ether to help repay their deposits, The New York Times reported.

But the damage was done. Less than 24 hours later, Bybit customers had withdrawn around $10 billion worth of cryptocurrency, almost half of the platform’s total managed volume. The value of Bitcoin, the benchmark cryptocurrency, fell 20% the day after the cyberattack, its worst day since the 2022 bankruptcy of FTX, the exchange run by Sam Bankman-Fried, the most popular crypto broker at the time.

(Excerpt) Read more at english.elpais.com ...


TOPICS: Business/Economy; Crime/Corruption; Foreign Affairs; Front Page News; Politics/Elections; Technical
KEYWORDS: 2022; 202502; 2p22; benzhou; bitcoin; bybit; crypto; cryptocurrency; currency; cybercrime; erythereum; exchange; ftx; hackers; lazarus; nkorea; norks; northkorea
Navigation: use the links below to view more comments.
first 1-2021-4041-50 next last
Most nations have organized crime. In North Korea, organized crime has a nation.

Reading this was really irritating. For all the sophistication of the Lazarus team, Bybit was making astonishing mistakes operationally. No serious online exchange should have CEO's sitting at home in their underwear making unilateral billion-dollar transfers.

Even smaller value, routine withdrawals and other transfers should only be happening with employees and hardware (and software) in dedicated secure facilities using silos - physically and computationally separate departments, such that multiple independent transactions need to be made to the blockchain to release funds (M of N multisig, in industry parlance). Combined with competent real-time monitoring and "3rd party" (another silo) verification of all such transaction requests, this would greatly complicate any hacking efforts. (Plus, any huge transfers should be broken down into reasonably smaller TX - they should have a policy of never doing a single TX over $100M for example, and staggering a serious of such TX at 1/minute for example to ensure no more than 1 TX is at risk at a time.

There are exchanges with great long term track records in this area (Kraken for example); those who are lax won't exist in the long term. Consumers should press for exchanges to publish the principles (but not precise details) used by exchanges to safeguard funds, and audits should be done to ensure they are followed.

The good news is this crime only affects centralized, 1st generation crypto exchanges (CEXs). Hackers can't empty the vaults of decentralized exchanges (DEXs) because they never have custody of customer funds. Once you exchange your old government money for crypto and get it off the exchange you can transact freely with other individuals and businesses without ever touching a bank/CEX and its vulnerabilities.

1 posted on 04/05/2025 11:17:46 AM PDT by EnderWiggin1970
[ Post Reply | Private Reply | View Replies]

To: EnderWiggin1970

NK says they’re sorry, will send a check to repay.


2 posted on 04/05/2025 11:21:56 AM PDT by SkyDancer ( ~ Am Yisrael Chai ~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SkyDancer
I thought it would be pallet loads of cash, like Obama.

3 posted on 04/05/2025 11:25:34 AM PDT by Waverunner
[ Post Reply | Private Reply | To 2 | View Replies]

To: SkyDancer

As soon as we submit payment of $14.99 to cover the cost of sending the check, right? ;-)


4 posted on 04/05/2025 11:30:48 AM PDT by EnderWiggin1970
[ Post Reply | Private Reply | To 2 | View Replies]

To: SkyDancer
> NK says they’re sorry, will send a check to repay. <

Just make sure they don’t try to repay with cash. Those rascals are pretty good at counterfeiting US currency.


5 posted on 04/05/2025 11:38:49 AM PDT by Leaning Right (It’s morning in America. Again.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: EnderWiggin1970
I wouldn't believe for a moment that it was North Korea, no more than the Russians created the Steele/Clinton/McCain dossier contents.

Anyone capable of pulling off a crypto scam is certainly capable of making it look like someone else did it.

The first investigation starts in house.

6 posted on 04/05/2025 11:52:57 AM PDT by T.B. Yoits
[ Post Reply | Private Reply | To 1 | View Replies]

To: EnderWiggin1970

Thanks for that insight. Wouldn’t they need someone to let them know that the CEO periodically makes transfers from a cold wallet to a hot wallet? Doesn’t sound like normal security protocols and just the type of lax security in place to facilitate a heist like this. In other words an inside job.


7 posted on 04/05/2025 11:56:23 AM PDT by HYPOCRACY (Long live The Great MAGA Kangz!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: EnderWiggin1970

Isn’t it about time things started randomly exploding in the hermit kingdom?

CC


8 posted on 04/05/2025 12:01:05 PM PDT by Celtic Conservative (My cats are more amusing than 200 channels worth of TV.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HYPOCRACY
I don't think the CEO should be personally doing these transfers any more than the CEO of Chase or Citibank should be personally moving money around in their banking operations.

Any requests for transfer should be sent to a number of separate entities. For example to a verification department, with the verification departments' software reflecting back to the requestor's webpage the details of the request so they can see if anything changed. And then to multiple other departments each of which would sign a transaction and submit it to the blockchain as well as back to the first department to ensure the details have not been altered by a copy/paste attack.

I'm not a security pro and this is just off the cuff; I'm sure more security measures and review checks could be added. But any system is only as secure as its weakest link, and so even an exchange boasting of great security is worthless if it has a back door for the CEO to login with PW=Admin and skip all the security "rigamarole."

9 posted on 04/05/2025 12:02:30 PM PDT by EnderWiggin1970
[ Post Reply | Private Reply | To 7 | View Replies]

To: T.B. Yoits

As the article mentions, Lazarus group has been ID’d as the culprit in dozens of attacks now. I agree with you in principle that obfuscation is a concern, but there’s been quite the body of evidence the last few years and I haven’t heard the Norks denying anything. I think they have gotten pretty arrogant in imagining themselves untouchable since they have state backing (and are funding the NK state, I don’t think this is going into individual hackers’ pockets.)


10 posted on 04/05/2025 12:06:04 PM PDT by EnderWiggin1970
[ Post Reply | Private Reply | To 6 | View Replies]

To: EnderWiggin1970

What scares me the most is that our government has no way to recover the losses, yet they are looking at implementing crypto as legal tender FOR the US. There is no FDIC insurance for crypto, and people can, and are, literally bankrupted in a milisecond and the FBI cannot do a thing about it. I know, it happened to me.


11 posted on 04/05/2025 12:12:05 PM PDT by RainMan ((Democrats ... making war against America since April 12, 1861))
[ Post Reply | Private Reply | To 1 | View Replies]

To: EnderWiggin1970

Hacky bumpy.


12 posted on 04/05/2025 12:14:54 PM PDT by MeneMeneTekelUpharsin (Freedom is the freedom to discipline yourself so others don't have to do it for you.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: T.B. Yoits

I don’t get it.

First I must admit my knowledge of crypto was limited.

But I have often heard , how crypto is supposed to be so safe. Because the block chain is stored in multiple computer systems world wide, and every specific transaction is tracked in those multiple systems.

From my limited knowledge, it should be impossible for crypto to just be stolen, because of how the block chain tracks every single transaction in multiple places.


13 posted on 04/05/2025 12:25:45 PM PDT by Dilbert San Diego
[ Post Reply | Private Reply | To 6 | View Replies]

To: EnderWiggin1970
Re: "The value of Bitcoin, the benchmark cryptocurrency, fell 20% the day after the cyberattack."

When did this happen? The link just says "after 2022."

14 posted on 04/05/2025 12:26:23 PM PDT by zeestephen (Trump Landslide? Kamala lost the election by 230,000 votes, in WI, MI, and PA.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Waverunner

So is that Nork money?


15 posted on 04/05/2025 12:35:06 PM PDT by SkyDancer ( ~ Am Yisrael Chai ~)
[ Post Reply | Private Reply | To 3 | View Replies]

To: EnderWiggin1970
They wanted to run a Mt. Gox without triggering a tipping point and fallout to worthlessness of what they had just stolen, and they did it.

But the script they ran and the fact that it is this f-----g easy, means a true systemic global Mt. Gox that decapitates BTC and triggers the complete implosion of all crypto is just around the corner. And sh!t is going to get real weird real fast when that happens...

16 posted on 04/05/2025 12:39:59 PM PDT by StAnDeliver (TrumpII)
[ Post Reply | Private Reply | To 1 | View Replies]

To: EnderWiggin1970

You save lots of cash by letting your people starve unless they join the army. Then you got money to hire hackers to make more money. Black market organ transplants from felons and political prisoners to rich foreigners very big money maker, too. Who says I can’t balance budget.


17 posted on 04/05/2025 12:47:39 PM PDT by Eleutheria5 (Every Goliath has his David. Child in need ofand thhere we CGM system. https://gofund.me/6452dbf1. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: EnderWiggin1970

This sneaky pete passive aggressive crap will only end when we put the world on notice that cyber crime is now an act of cyber war.

Then we start sinking ships, cratering planes, and seizing assets anywhere in the world by keyboard, quill and kinetic weapons.

A couple dozen prize ships docking in NYC crewed by the USN would send a message.

Hoist the Jolly Roger, the Clean Sweep Broom, and break out the kill stencils and rattle cans!


18 posted on 04/05/2025 12:52:56 PM PDT by Lowell1775
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dilbert San Diego
My understanding is that all Bitcoins are created equal and anonymous.

The only thing that changes during a transaction or a theft is the new residence of those particular Bitcoins.

The people who own Bitcoins have a unique 64 bit alpha-numeric pass code into their Bitcoin account, or multiple accounts.

Misplace your pass codes? Bye, bye, Bitcoins, at least until quantum computers can hunt them down.

Anyway, that is my anecdotal understanding.

19 posted on 04/05/2025 12:55:28 PM PDT by zeestephen (Trump Landslide? Kamala lost the election by 230,000 votes, in WI, MI, and PA.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: EnderWiggin1970

My wife likes to tell me that I’m very smart, and indeed it takes some brains to be a master electrician.

But after reading through this thread I’m once again slapped with just how ignorant I really am.


20 posted on 04/05/2025 1:06:20 PM PDT by 1FreeAmerican
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-50 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson