DEVWorld 2026

Christopher von Hessert - Hacking a $4 billion piece of code

21:41 · 07 May 2026 – 08 May 2026 · YouTube

About this talk

In this talk, Christopher discusses the lucrative opportunities available in the blockchain and crypto sector, particularly in terms of bug bounty programs. He explains the recent significant hack of Bybit, where hackers exploited social engineering techniques to steal $1.5 billion worth of Ethereum tokens. The speaker emphasizes that hacking is often less complex than it appears, underscoring the role of social engineering rather than technical exploits. He advocates for developers to transition to blockchain technology, highlighting the enormous financial rewards from participating in ethical hacking and bug bounty platforms, such as Immunifi and Cantina. Additionally, he shares insights on the risk landscape related to phishing attacks and encourages developer engagement in finding vulnerabilities, noting that the payouts in the crypto domain can exceed those in traditional web environments.

Full transcript

We are ready for the final speaker of today. And I hope that you are as excited as I am because it sounds like what Christopher is going to tell us is how we can make a lot of money. Actually, what he claims is we can earn four billion. So, I'm very excited to hear about how blockchain can help you guys as developers to come to that dream.

Welcome, Christopher. Thank you. [Applause] Well, it's uh Hi, my name is Christopher. I work for uh Polyon Labs. Uh that is a blockchain company or software development company that builds blockchain technology. And it's been a very very interesting week. uh unless you don't read the news and don't have u you know I guess even in Tik Tok you've heard the news we've uh basically suffered uh the

biggest hack in crypto history uh um and I'm going to talk a little bit about it if my computer doesn't go to sleep. So um over here the the the the topic of my presentation is is obviously how can you make money? I've been uh uh I' I've been working in security and development and engineering for many many many years and I've recently uh like three four

years ago transition to working more on the blockchain technology on crypto companies and things like that and I want to tell you all there's a lot of money to be made and you should make the change from you know working for normal web companies or you know u IT companies moving all the way to blockchain technology and even if you don't this is where you should be

spending your weekends. This is where you should be spending uh your free time trying to hack protocols, trying to hack different companies. There's a lot of money to be made. So, I'm not sure how well you can see it. Obviously, resolution is not amazing, but these are all the hacks, a list of all the hacks that have happened in the crypto industry with the number one being

the one that happened last weekend. And on the other side, you can you have uh hackers, book bounty hackers. These are people that are basically, you know, day and night or even only on the weekends uh trying to hack different protocols in order to get uh some type of bug bounty report. For any of you guys that have been, you know, using like uh Buck Crowd or

Hacker One or everything else, the numbers in blockchain technology are completely absolutely nuts. Like like I I cannot believe the amount of money some of these people are making. Some of these people are actually like just fresh, you know, out of university and they're lucky sometimes, sometimes they're not so lucky to discover a bug that is worth millions and millions and millions. But let's move ahead. So,

what happened this weekend? No, this is like fresh, fresh, fresh. Um, hackers stole $1.5 billion uh or $ 1.5 billion dollars worth of tokens, specifically Ethereum tokens in this case, out of uh one of the biggest exchanges in the world called Bybit. And um you know, I want to demystify a little bit it. I wanted to show you how easy it was because a lot of people

read this and can imagine like oh I'm sure that you know the guys had to go through some crazy crypto type of zero knowledge proof and editing the solidity code and then you know all these crazy stuff and it actually was quite quite simple and here's the explanation what happened um the hackers in this case were able to compromise a developer that developer how they compromised it.

Fishing, social engineering, we'll go into that. Um, that developer unfortunately had the keys or had access to an S3 bucket and that S3 bucket obviously hosted the web page of uh safe multisig which is a which is one of the pages where you go and do transactions or um you know make the um yeah transactions transfers uh things like that. So they were able to basically change

the JavaScript in the web page and show something different to the user that was going. This is for example imagine going to your ABN AMRO to your ING to your Bank of America and suddenly saying like oh I'm going to transfer 10 bucks to uh my mom because she needs some money. Uh but you're seeing that you're transferring 10 bucks but somebody in the background actually changed

the web page and what you're actually doing is transferring all your money from your account. So that is really what happened. they they they compromised the developer. the developer had you know a lot of uh access control into the systems and uh when the biit people went to do a normal transaction I forgot exactly what type of transaction they were doing they signed the transaction and when

it executed they suddenly realized like oh hell why is all the money gone $1.5 billion dollars so um you know so in the end hacking mean, you know, it's not as complex as a lot of people think. It's, you know, that's why, you know, you got the meme like it's all just web two stuff and uh and social engineering. And the truth is it's it's true. It's

it's very very very simple to actually hack a protocol, to hack a bank, uh to, you know, people think that it's something really complicated that we're like math gurus that are looking at numbers in the matrix. No, it's super easy and it all starts with social engineering and fishing. And nowadays, this is like the number one problem that we have any company in the world has right

now is fishing. It all starts with a malicious link. It all starts with somebody telling you like, "Oh, I want to hire you. Here's you know, job wreck for a PDF with a job wreck." You open the PDF, dang, you're owned. Um, here's um, you know, like here's whatever. There's so many different things. PDFs, fake video calls, malicious extensions, uh, fake airdrops. Um, if you're developers over

here, VS Code has a ton of malicious extensions over there that basically will go into your machine and try to sweep whatever they want from username and passwords to crypto wallets. You can imagine it. So, um, you know, Discord verification l links, even dev world tickets. No, somebody may be selling you a Dev World ticket or or an event for Dev World. I imagine a lot of

you guys are signing up to like just random events because they're like free booze and free food and stuff like that. just click click click give my email. Like be careful. I'm not saying don't do it. I'm just saying be careful what you click and be careful what type of computers you use in order to click uh some of these things. Like if it's the same computer

where you're storing your your very precious NFTts and you're doing all your bank accounting and everything else like maybe rethink about where you know where you do different So who was behind this huge hack? Um we are attributing this to Lazarus. Lazerus is a hacking group. It is uh basically a hacking group that we believe it's sponsored by North Korea. Again, these are all beliefs because nobody

from North Korea came and said like, "Haha, yeah, it's me. H cool." No. Uh we all believe this is true. And uh you know there's also a lot of conspiracy theories of other things. You can read online of who was it and why and all those type of things. But the majority of the people actually believe that it was Lasserus. Even the FBI and many of the,

you know, online like Interpol and stuff like that are attributing this to the Lasserus group. And um this is not the first time that they do things like that. They've been doing this for a while. They've, you know, they've been part of the Sony Pictures hack where they actually released one of the movies uh before time. Um they also tried to hack a bank in India. uh

the wann to cry ransomware when ransomware was like you know every computer was being hacked by ransomware like North Korea was behind a lot of them of the majority of them and then the two biggest ones that were very very similar were the running network hack and the wazerex exchange hack all of them had the same type of attack vector they didn't go through the smart contracts

they didn't go to the blockchain they didn't go any different the only thing they did they compromised a developer or they compromised somebody an employee in the company. That employee in the company had elevated privileges to change web page to access banks or whatever it is. And that's it. It's that simple. Now go out and get rich, please. Now um so now I'm going to go a

little bit um you know this probably we can skip a bit but like what have we learned from all these hacks? If you guys are in crypto, uh if you guys are, you know, have wallets, have NFTts, are basically losing money right now because, you know, it's not Bitcoin is not doing that great, you know, here are a couple of recommendations. I'm going to skip it because

I really want to go to u the fun part. No. So, how can you make money hacking? And I'm saying hacking not in the way Lassos group is actually hacking, but in the way, you know, in a legal ethical type of way. I said before like hacker one buck crowd probably a lot of you are familiar probably a lot of your companies are using things like hacker

one for the bug bounty program I would dare you to go and look into the other side of the world or the dark side let's say the crypto side of things these are two of the biggest platforms that um uh uh blockchain companies normally post their bug bounty programs one of them is called cantina the other of them is called Immunifi and I want you to look

and probably you cannot see that because of the resolution solution the amount of bounties that are being paid over here. So for example, the company I work with, Polygon, our max bounty is a million dollars. If you find a critical vulnerability, if you find a critical bug, a critical way to hack our company, you can get paid almost a million dollars or even a million dollars of

it. We have in the last five years, we have paid $7 million in bounties. And out of those $7 million, $3 million were on three different bugs. So we've paid three people um more than or a million dollars, even a little bit more than a million dollars because of bugs that they found. And I obviously cannot share full details of what it was, but I can tell

you they were quite simple. You don't have to be a solidity guru. You don't have to be a Rust mega engineer and understand memory management and all those type of things. It was relatively quite simple stuff like oh you missed a comma over here or oh you didn't initialize the proxy or things like that. No you also have on the other side like the cantina platform it's

also another platform you got unis swap I assume are people familiar with unis swap and then some of these protocols. Yeah. Yeah that's good. Cool. So these are kind of the biggest crypto protocols you would see. They are exchanges. They're decentralized. my screen saver again. Um, unis swap is paying 15 million for a critical vulnerability. Unis swap is the biggest biggest biggest decentralized exchange in the crypto

world. You discover a bug over there, you can get paid up to $15 million in order to find a bug over there. And it can be anything. It doesn't have to be like crazy stuff. Again, it can be a web two bug. It can be a cloudfare token that you discovered. It can be a S3 bucket that was opened know typical things that most you know web

two developers and engineers are actually working on on a daily basis. So um yeah you got a lot of other protocols but you could see that at least the top five over here are paying more than a million dollars. The same happening on on the Munifi side of things like you know the top protocol over here that is Polygon paid 7 million. The next one paid $2.6

million already. Everybody has paid more than a million dollars already in bulk bounty platforms. And if you compare that to places like hacker one or buck crowd, you're not going to find these numbers. So I, you know, I I encourage you to have a look to try to, you know, hack something, find something. You don't have to be a security guru again, you know, and and basically

um yeah, see if you can make some money. So another way you can make money in crypto or in blockchain technologies or with blockchain companies are competitions. Um this is something a little bit different from the web to world. No, this is something that you don't really see that much in in other platforms and uh you know they've created a kind of bug bounty platform uh or

bug bounty strategy that is called a competition. It's basically throughout a specific uh time, let's say one or two weeks, please hack me. That that that's basically it. It's like here's my web page, here's my smart contracts, here is all my assets, here's my AWS, here's my stuff. Try to hack me in these two weeks. And if you hack me in these two weeks, you got a

big, you know, pot of money that can be spared. So the amount of money in competitions is not huge. We're not normally talking about million dollars. There are a couple of million-dollar bug bounties like right this is right now. So right now you have all these competitions going on. You have a one from Ethereum that is $2 million but then the rest are you know between 50,000

to 100,000 and the bugs that are discovered over the the the reports and bugs that are discovered over there actually shared the money is shared between everybody that discovers over it. So the payouts are a little bit less, but there are so many and there's I I promise you there's so little people doing these things that if you discover like a low vulnerability, you can get a,000

2,000 $3,000 even more. Sometimes because of the amount of competitions that are going on in parallel, they receive very little people submitting reports and stuff like that. and um and suddenly you discover a low when you get like $10,000 and you're like did I get just $10,000 for submitting like a stupid GitHub uh you know end file that was submitted or or you know a leaked key

or anything like that and yeah because nobody is submitting reports. So what is really that I'm trying to tell you over here it's there are no people there are very little security people there are very little engineers there are very little developers in this new industry that is starting to developed I assume that everybody here is starting to hear more and more about it they're starting to

hear more about the scams they're starting to hear more about the NFTs but you should start hearing more about the real companies that are being built over here they are no different than the companies that are at exposition over here. No, that they're just software development companies building software in an open-source manner and specifically targeting block uh blockchain technologies and open source. No. So, um if you

got time, if you uh are are looking for something to do in your weekends uh after the event or stuff like that and you like coding, you think you're good at discovering some stuff, go and check some of these platforms. See if you can discover something. I promise you there is a lot of money to be made compared to like traditional web two bug bounty hunting and

things like that. Um I'm going to go through a couple of uh I think two or three of the biggest payouts the world have ever seen in buck bounty. And this is like this is not cryptosp specific or anything like that. Obviously these people found bug bounties in the crypto world but like this guy which is called the satay or something like that. He goes by that

name he got $10 million out of a critical vulnerability. This is the biggest called the biggest bug bounty in industry. At least known book bounty in industry because I'm sure there's a lot of people that have discovered very crazy stuff in the world and got paid a very good amount of bounty but you know we don't we don't talk about it or you know they don't want

to disclose it. This guy made $10 million by discovering something that is relatively trivial in in like smart contracts and things like that which is uh an unalized proxy. That means that uh you know one of the smart contracts that was deployed they basically didn't initialize the variables. No similar to any web two technology JavaScript or stuff like that you know when when you when you compile

something and you start running it you need to initialize variables to make sure that you know everything uh that the environmental variables are appropriate and all type of things. So in this case, wormhole which is um a bridge moves money hundreds of thousands of millions of billions nowadays of money. These guys forgot to initialize one of their smart contracts. The variables were not set and therefore somebody

else could have been able to initialize those variables and for example say like oh I'm the owner of this smart contract now or uh I have you know whatever millions of dollars in my wallet because they forgot to initialize. So the guy reported this to Wormhole and because Wormhole had so much money at risk because of these things, they paid him $10 million. So you can imagine

that for a company to pay $10 million to a bug bounty hunter means that the thing that he discovered, you know, could have basically, you know, put down the whole company, not not only losing funds from the company itself, but losing all their users funds. you know, I'm not sure how much money does Wormhole actually move and own and all those type of things, but I'm sure

it's in the billions right now. So, again, that's uh absolutely crazy. Um, the next one, which I actually like because this is uh this is a fun one. Um, this guy Aurora uh sorry, the guy is named Pawning uh but saved a project that was called Aurora H. he kind of find a way to make money infinite. So this project was deploying was uh was was deploying

some smart contracts in this case and when they deployed some smart contracts there was a bug that basically allowed you to mint infinite amount of tokens uh um or basically uh create infinite amount of tokens when you withdraw. So you would probably say like hey I'm going to withdraw $100. I'm going to withdraw $10. he found a way to infinitely withdraw money and basically that the uh

the balance never changes. So I withdraw I have $100 I withdraw 100 I continue having a 100. There was a bug over there in the smart contract specifically uh there were some commas that were not properly set. Um and this guy discovered it and basically he was paid six million yes $6 million uh for this bug bounty. And again, this these are not yes, these are smart

contracts. Yes, this is solidity. But in the end, this is just normal scripting. This is normal uh coding. And he just discovered a bug into these smart contracts um and got paid $6 million. And this is not the first time he's done it. He actually has like six others that he's gone uh won more than a million dollars in those in these type of yeah, as you

can see, there's a lot of money to be made. Um, just to give you a lot of a little bit more of encouragement uh on on on joining bug bounty hunting and finding bugs and crypto protocols and blockchain technology and stuff like that. Here is an example of payouts from Immunifi. No, normally if you go into if you go and discover like a bug and uh you

know it's a low thing and you know probably doesn't matter and stuff like that. Most companies will not pay you one cent. They're like ah thank you for reporting here is a nice hopefully t-shirt or or something like that they will give you. But that's not the same in blockchain technology in in crypto technologies. We will pay you for any piece of information you can give us

because right now it may be a low thing. It may be informational. It may be not important or anything like that. But you know this mixed with something else can actually become a bigger attack vector. So as you can see over here of the total buck bounties that have been paid that is in the millions or hundreds of millions in the last at least four or five

years basically um a million dollars were paid for low severity findings. Yeah. And almost a little bit more than half a million dollars were paid for informational likeformational bounties. That's absolutely crazy. Like I' I've been in web two technologies working for SAS companies. We would never pay for anformational. It was always like thank you for informationational. Uh here's a t-shirt. We'll send it to your home. That

was all you got. In web two, web three, in crypto blockchain uh companies and stuff like that, we'll give you something. We'll give you 300 bucks. We'll give you 500 bucks. we'll give you a thousand bucks even for informational stuff that doesn't have an actual security attack vector. So there's a lot of money to be made in in these type of technologies. Um you got a couple

of the links over there that I shared. Um I think this is my last slide. Yes, this is my last slide. Thank you for listening. I hope uh you've learned something. I hope you discover something how we actually join blockchain companies and crypto companies. They're they're in a very interesting and fun place to work nowadays and uh they pay very well. So uh thank you

From event

DEVWorld 2026

07 May 2026 – 08 May 2026

All event videos
Back to Watch