Security· ★★★★· bearish·

Analysts: Bybit attack ran through Safe interface, not code

  • Bybit hack on Feb. 21, 2025: about $1.5 billion stolen, FBI linked the attack to North Korea (TraderTraitor)
  • The attack ran through stolen Safe developer credentials and a spoofed frontend; Bybit's infrastructure was not compromised
  • Ledger issued bulletins 023 and 025: vulnerabilities fixed in Ethereum app 1.22.2/1.22.3 and Secure SDK 26.6.1
  • Safe introduced Safe Shield with pre-transaction checks and similar-address detection
Why it matters: It shows that multisigs and hardware wallets offer no protection if the frontend and signing process are compromised, changing the approach to custodian security.
Source: TokenPost