$1.5B crypto hack losses expose bug bounty flaws

As cryptocurrency losses from security breaches surge past $1.5 billion, cybersecurity experts are urging exchanges to improve bug bounty programs to attract top ethical hackers and strengthen platform security.
On March 3, blockchain security firm CertiK said that crypto lost from hacks in February had reached $1.53 billion, with the Bybit hack accounting for the majority of losses at more than $1.4 billion. Excluding the incident, CertiK reported that other exploits had resulted in $126 million in losses, including a $49 million Infini hack.
Ethical hacker Marwan Hachem told Cointelegraph that the surge in crypto hack losses highlighted a growing need for better bug bounty programs.
Hachem said that to prevent such exploits, exchanges must offer higher and more appealing bug bounty rewards to white hat hackers.
Hachem, chief operating officer at cybersecurity firm FearsOff, said crypto exchanges must offer higher rewards to ethical hackers to prevent similar exploits. According to the security professional, the bug bounty program of Safe, Bybit’s multisignature wallet provider, considered bugs related to the front and back-end out of scope, meaning those who identified these security issues were not eligible for rewards. The security professional said the Bybit hack happened because of a bug that was not in the scope rewarded by the bounty program. “What they considered out of scope led to the biggest crypto hack in history,” Hachem told Cointelegraph. He added: “We often breach platforms through bugs found in out-of-scope assets. Ethical hackers wouldn’t get rewarded for such findings, but criminals exploited them and stole $1.5 billion from Bybit.” Bybit’s official bug bounty offers a maximum of $4,000 on its website and up to $10,000 on HackerOne — amounts that pale in comparison to the potential rewards for malicious hackers. Hachem said it’s better to pre-emptively give white hat hackers bigger rewards instead of waiting for a major hack to happen and offer 10% of the stolen funds as a white hat reward. The executive said this only “emboldens bad actors.” “Motivating top ethical hackers to dedicate their time and attention to testing an exchange by offering higher rewards will greatly improve its security, will be a lot cheaper, and will safeguard its reputation,” Hachem told Cointelegraph. Related: Bybit hackers resume laundering activities, moving another 62,200 ETH Alongside better bug bounty programs, a CertiK spokesperson told Cointelegraph that preventing future exploits like the Bybit hack requires adopting stricter security measures. A CertiK spokesperson told Cointelegraph that air-gapped signing devices, non-persistent OS environments for transaction approvals and enhanced authentication layers for high-value transactions should become industry standards. “Regular red-team exercises and phishing simulations can also help mitigate social engineering risks,” the spokesperson said. CertiK’s report revealed that Bybit’s exploit resulted from a phishing attack that tricked multisignature signers into approving a malicious contract upgrade. Meanwhile, the Infini hack stemmed from an admin private key leak, allowing unauthorized withdrawals. CertiK said both incidents underscored the risks of blind signing and inadequate transaction verification. “These cases emphasize the need for stronger authentication, real-time transaction monitoring, and more resilient UI security to prevent manipulation,” CertiK added. Magazine: Elon Musk’s plan to run government on blockchain faces uphill battle
An “out of scope” bug led to a $1.4 billion hack
Adopting stricter security measures
Bitcoin (BTC) $ 107,249.00
Ethereum (ETH) $ 2,649.71
Tether (USDT) $ 1.00
XRP (XRP) $ 2.28
BNB (BNB) $ 682.42
Solana (SOL) $ 170.04
USDC (USDC) $ 0.999807
Dogecoin (DOGE) $ 0.220179
Cardano (ADA) $ 0.739623
TRON (TRX) $ 0.275980
Lido Staked Ether (STETH) $ 2,646.26
Wrapped Bitcoin (WBTC) $ 106,754.00
Sui (SUI) $ 3.57
Wrapped stETH (WSTETH) $ 3,178.66
Hyperliquid (HYPE) $ 32.19
Chainlink (LINK) $ 15.42
Avalanche (AVAX) $ 22.88
Stellar (XLM) $ 0.283867
Toncoin (TON) $ 3.40
LEO Token (LEO) $ 9.04
Shiba Inu (SHIB) $ 0.000014
Bitcoin Cash (BCH) $ 411.57
Hedera (HBAR) $ 0.182530
Litecoin (LTC) $ 95.68
USDS (USDS) $ 0.999864
WETH (WETH) $ 2,641.17
Polkadot (DOT) $ 4.49
Wrapped eETH (WEETH) $ 2,819.99
Monero (XMR) $ 340.10
Bitget Token (BGB) $ 5.23
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999297
Pepe (PEPE) $ 0.000014
Ethena USDe (USDE) $ 0.999349
Pi Network (PI) $ 0.707636
Coinbase Wrapped BTC (CBBTC) $ 107,017.00
WhiteBIT Coin (WBT) $ 31.50
Uniswap (UNI) $ 6.83
Aave (AAVE) $ 255.44
Dai (DAI) $ 0.999851
Bittensor (TAO) $ 424.54
NEAR Protocol (NEAR) $ 2.85
Aptos (APT) $ 5.31
OKB (OKB) $ 52.03
Jito Staked SOL (JITOSOL) $ 204.83
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Tokenize Xchange (TKX) $ 36.47
Ondo (ONDO) $ 0.920742
Internet Computer (ICP) $ 5.46
Cronos (CRO) $ 0.096822
Ethena Staked USDe (SUSDE) $ 1.17
Ethereum Classic (ETC) $ 18.42
Kaspa (KAS) $ 0.098547
Gate (GT) $ 20.19
Official Trump (TRUMP) $ 12.06
Mantle (MNT) $ 0.700694
Artificial Superintelligence Alliance (FET) $ 0.879980
sUSDS (SUSDS) $ 1.05
VeChain (VET) $ 0.026512
Render (RENDER) $ 4.37
Ethena (ENA) $ 0.386117
Cosmos Hub (ATOM) $ 4.78
USD1 (USD1) $ 0.999604
POL (ex-MATIC) (POL) $ 0.229156
Worldcoin (WLD) $ 1.33
Arbitrum (ARB) $ 0.411120
Lombard Staked BTC (LBTC) $ 106,520.00
Fasttoken (FTN) $ 4.42
Filecoin (FIL) $ 2.81
Algorand (ALGO) $ 0.213754
Jupiter (JUP) $ 0.584858
Celestia (TIA) $ 2.56
First Digital USD (FDUSD) $ 0.993268
Binance-Peg WETH (WETH) $ 2,658.72
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.59
Binance Staked SOL (BNSOL) $ 179.35
Bonk (BONK) $ 0.000019
Virtuals Protocol (VIRTUAL) $ 2.25
KuCoin (KCS) $ 11.28
Sonic (prev. FTM) (S) $ 0.441020
Injective (INJ) $ 14.27
Kelp DAO Restaked ETH (RSETH) $ 2,751.78
Optimism (OP) $ 0.753956
Stacks (STX) $ 0.835719
Fartcoin (FARTCOIN) $ 1.26
USDT0 (USDT0) $ 0.998012
Rocket Pool ETH (RETH) $ 2,994.04
NEXO (NEXO) $ 1.24
Flare (FLR) $ 0.018210
Story (IP) $ 4.24
Sei (SEI) $ 0.221163
Immutable (IMX) $ 0.620792
EOS (EOS) $ 0.749264
dogwifhat (WIF) $ 1.08
SPX6900 (SPX) $ 1.14
The Graph (GRT) $ 0.108264
XDC Network (XDC) $ 0.063068
Solv Protocol BTC (SOLVBTC) $ 107,061.00
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.998460
Curve DAO (CRV) $ 0.743570
Mantle Staked Ether (METH) $ 2,824.60