[]
BTC$86,483-0.30%ETH$2,006.15-0.93%USDT$1.00-0.04%XRP$2.33-3.78%BNB$634.091.52%SOL$137.75-2.24%USDC$1.000.01%DOGE$0.19-3.02%ADA$0.73-2.23%TRX$0.232.52%STETH$1,998.78-0.67%WBTC$86,351-0.27%LINK$15.51-0.08%TON$3.879.25%AVAX$21.95-1.44%LEO$9.77-0.16%XLM$0.29-1.16%SUI$2.735.85%WSTETH$2,391.79-1.71%USDS$1.00-0.03%SHIB$0.00001408-5.18%HBAR$0.19-2.71%LTC$93.17-0.57%DOT$4.55-2.12%OM$6.550.26%BCH$325.46-1.79%BGB$4.97-1.40%WETH$2,005.42-1.17%PI$0.825.04%USDE$1.00-0.01%BSC-USD$1.000.18%HYPE$14.222.56%WEETH$2,129.97-1.14%WBT$29.160.59%XMR$223.830.21%UNI$6.72-1.98%APT$5.921.14%NEAR$2.96-1.79%PEPE$0.00000837-3.93%DAI$1.00-0.03%SUSDS$1.050.14%OKB$49.96-0.23%ICP$6.01-2.65%GT$23.54-0.59%TKX$35.900.42%ONDO$0.91-1.37%MNT$0.850.79%CBBTC$86,473-0.31%AAVE$182.83-0.34%CRO$0.10-3.67%ETC$17.87-1.98%FDUSD$1.00-0.03%SUSDE$1.160.23%TAO$268.500.45%ENA$0.431.32%TRUMP$11.19-3.33%VET$0.03-2.41%ATOM$4.81-2.28%TIA$3.704.29%RENDER$3.94-0.96%POL$0.23-0.55%BUIDL$1.000.00%KAS$0.07-2.25%FIL$3.00-3.45%S$0.60-1.36%LBTC$86,383-0.34%ALGO$0.210.23%ARB$0.38-1.74%FTN$4.030.35%JUP$0.54-2.52%IP$5.80-4.57%OP$0.900.53%FET$0.54-2.94%KCS$11.391.35%SOLVBTC$86,277-0.57%USDT0$1.000.42%RSETH$2,085.77-1.02%WETH$2,008.14-0.67%MOVE$0.49-4.74%MKR$1,414.555.31%NEXO$1.181.24%IMX$0.64-1.73%WLD$0.951.52%BNSOL$143.32-2.69%XDC$0.07-3.20%STX$0.732.32%QNT$75.84-1.50%BONK$0.00001355-6.79%SEI$0.21-0.79%DEXE$17.952.91%USDC.E$1.000.15%INJ$10.44-3.87%GRT$0.10-0.90%RETH$2,268.53-1.08%THETA$0.98-1.32%USD0$1.00-0.00%LDO$1.03-0.67%BERA$8.287.22%FLR$0.01-1.68%EOS$0.57-0.77%

Advertisement

Safe Wallet Found Responsible for ByBit’s $1.5 Billion Hack

Binance founder CZ criticized Safe after ByBit’s audit revealed the point-of-failure exploited by North Korean hackers.
By: Squiffs • February 26, 2025
Safe Wallet Found Responsible for ByBit’s $1.5 Billion Hack

ByBit, the second largest centralized exchange (CEX) in the world, released third-party audits today, which identified multi-signature security protocol Safe’s Safe{Wallet} arm as the point-of-failure in last week’s record-breaking $1.5 billion hack.

The audit from Sygnia Labs said, “The forensics investigation of the three signers’ hosts suggests the root cause of the attack is malicious code originating from Safe{Wallet}’s infrastructure.”

Verichain’s audit confirmed the findings and said, “The benign JavaScript file of app.safe.global appears to have been replaced with malicious code…specifically targeting the Ethereum Multisig Cold Wallet of ByBit.”

Safe, which was spun off from Gnosis, is the largest multi-signature wallet provider in DeFi, and released a statement from its Safe{Wallet} arm stating, “This attack targeted to the Bybit Safe was achieved through a compromised Safe{Wallet} developer machine resulting in the proposal of a disguised malicious transaction.”Safe clarified that the exploit compromised a single wallet and that Safe’s smart contracts remain unaffected.

Since the attack, ByBit successfully covered the $1.5 billion hole left in its business over the weekend through bridge loans and market buys of Ether. However, the attack vector raises security concerns around Safe as the industry mulls over the chances of a repeat attack.

CZ Calls Out Safe

Binance founder Changpeng Zhao (CZ) took to social media to criticize Safe’s statement. “This update from Safe is not that great. It uses vague language to brush over the issues. I have more questions than answers after reading it.” said CZ.

CZ cited unanswered questions such as “How did they hack this particular machine?…how did a developer machine have access (to a Bybit wallet)?...how did they fool the Ledger verification system?”

He went on to imply that Binance does not utilize Safe Wallets in its operations.

"Lazarus is probably the world's most sophisticated hacker group, which was able to (socially) engineer their way into the system. Once we complete our investigation we will share all findings transparently," responded Gnosis co-founder Stefan George.

Our articles are stored on Filecoin.

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.