Crypto Hacks Reach $1.5 Billion, Experts Urge Exchanges to Improve Bug Bounty Programs
As cryptocurrency losses from security breaches surge past $1.5 billion, cybersecurity experts are urging exchanges to improve bug bounty programs to attract top ethical hackers and strengthen platform security.
An "Out of Scope" Bug Led to a $1.4 Billion Hack
Ethical hacker Marwan Hachem believes that to prevent such exploits, exchanges must offer higher and more appealing bug bounty rewards to white hat hackers. According to Hachem, the bug bounty program of Safe, Bybit’s multisignature wallet provider, considered bugs related to the front and back-end out of scope, meaning those who identified these security issues were not eligible for rewards.
The Bybit Hack
The security professional said the Bybit hack happened because of a bug that was not in the scope rewarded by the bounty program. "What they considered out of scope led to the biggest crypto hack in history," Hachem told Cointelegraph. He added, "We often breach platforms through bugs found in out-of-scope assets. Ethical hackers wouldn’t get rewarded for such findings, but criminals exploited them and stole $1.5 billion from Bybit."
The Importance of Bug Bounties
Hachem said it’s better to pre-emptively give white hat hackers bigger rewards instead of waiting for a major hack to happen and offering 10% of the stolen funds as a white hat reward. The executive said this only "emboldens bad actors." "Motivating top ethical hackers to dedicate their time and attention to testing an exchange by offering higher rewards will greatly improve its security, will be a lot cheaper, and will safeguard its reputation," Hachem told Cointelegraph.
Adopting Stricter Security Measures
Alongside better bug bounty programs, a CertiK spokesperson said preventing future exploits like the Bybit hack requires adopting stricter security measures. These measures include air-gapped signing devices, non-persistent OS environments for transaction approvals, and enhanced authentication layers for high-value transactions.
Conclusion
The surge in crypto hack losses highlights the need for exchanges to take proactive measures to strengthen their security. By offering higher bug bounty rewards and adopting stricter security measures, exchanges can prevent catastrophic hacks and protect their users’ assets.
Frequently Asked Questions
- What is a bug bounty program?
A bug bounty program is a program where a company pays ethical hackers to find and report security vulnerabilities in their systems. - Why are bug bounty programs important for exchanges?
Bug bounty programs are important for exchanges because they allow them to identify and fix security vulnerabilities before malicious hackers can exploit them. - What is the current state of bug bounty programs in the cryptocurrency industry?
The current state of bug bounty programs in the cryptocurrency industry is that many exchanges have limited bug bounty programs or no bug bounty programs at all, leaving them vulnerable to security breaches. - What can be done to improve bug bounty programs in the cryptocurrency industry?
To improve bug bounty programs, exchanges should offer higher and more appealing bug bounty rewards to white hat hackers, and adopt stricter security measures such as air-gapped signing devices and non-persistent OS environments for transaction approvals.
