
Analysts: Bybit attack ran through Safe interface, not code
- —Bybit hack on Feb. 21, 2025: about $1.5 billion stolen, FBI linked the attack to North Korea (TraderTraitor)
- —The attack ran through stolen Safe developer credentials and a spoofed frontend; Bybit's infrastructure was not compromised
- —Ledger issued bulletins 023 and 025: vulnerabilities fixed in Ethereum app 1.22.2/1.22.3 and Secure SDK 26.6.1
- —Safe introduced Safe Shield with pre-transaction checks and similar-address detection
Why it matters: It shows that multisigs and hardware wallets offer no protection if the frontend and signing process are compromised, changing the approach to custodian security.
Source: TokenPost