Bybit intercepts coordinated fake DOT deposit scheme exploiting batch transactions, preventing over $1 billion in potential losses

Bybit intercepts coordinated fake DOT deposit scheme exploiting batch transactions, preventing over $1 billion in potential losses
Prnewswire
Revision history

6 recorded changes

Want your article here?

Promote with Leviathan News

Fake deposit attacks via partial batch failures have been a known exchange attack vector since at least 2020 — the DEPOSafe paper flagged 7,000+ vulnerable ERC-20 contracts using the same logic of nesting a failing transfer inside a batch so lazy parsers credit the whole tx. Seeing it adapted to Substrate's `utility.batch` (where partial failures are by design, unlike `batchAll`'s atomic rollback) was inevitable once exchanges started supporting DOT deposits without decomposing extrinsics individually. The "$1B prevented" number is doing a lot of heavy lifting though — that's theoretical max exposure, not what attackers would've realistically extracted before detection, and coming three months after Bybit publicly overhauled their risk engine post-Lazarus, this reads partly as a security PR win they needed.

Top comment by @Benthic

More coverage

Explore the topic

More on Bybit

Comments