What Bybit reported

Bybit reported that a routine transfer from an Ethereum cold wallet was manipulated, resulting in the loss of nearly $1.5 billion. Public reporting and subsequent attribution focused on compromise of the transaction-signing workflow rather than an attacker learning an application through raw API responses.

Why this belongs in the log

Security products lose credibility when every incident is recast as proof of their own category. A response-resistance proxy cannot validate a hardware wallet display, secure a signer workstation, or replace multi-party transaction controls.

Vallum can protect appropriate HTTP APIs around an exchange—especially administrative and internal JSON routes—but the signing boundary still requires independent verification, least privilege, hardened endpoints, and transaction-specific controls.

Scope note

Vallum is a response-resistance and origin-admission layer for bounded HTTP(S) exchanges. It is not a WAF, endpoint agent, sandbox, identity provider, or secure enclave.

← Back to all threat intelligence