Close Menu
    Facebook X (Twitter) Instagram
    Friday, May 16
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Bybit $1.4b theft originated from compromised Safe UI
    Crypto

    Bybit $1.4b theft originated from compromised Safe UI

    James WilsonBy James WilsonFebruary 26, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    An independent audit confirmed that North Korea’s Lazarus Group infiltrated Safe’s infrastructure to compromise Bybit’s ethereum wallet.

    A forensic analysis conducted by Sygnia Labs and Verichain found that Bybit’s security integrity remained intact despite an attack on its Ethereum (ETH) cold wallet on Feb. 21.

    The Dubai-based crypto exchange reported the theft of over 400,000 ethereum, worth approximately $1.4 billion, from its Safe-provided multi-signature wallet last week. Initial speculation suggested that one of Bybit’s signers had been compromised by Lazarus. However, the post-mortem audit traced the root cause to a Safe developer machine.

    “They hot swapped the Gnosis Safe UI with JS code that only targeted Bybit’s cold wallet,” Haseeb Qureshi, managing partner at Dragonfly explained. 

    This means Lazarus successfully compromised a Safe developer with access to specific frontend deployment credentials, allowing bad actors to disguise malicious transactions.

    Safe acknowledged the findings, reaffirming that Bybit’s security remained intact while confirming the attack vector. The protocol also stated that its internal investigation found no vulnerabilities in the Safe smart contracts or source code.

    Following the recent incident, the Safe{Wallet} team conducted a thorough investigation and have now restored Safe{Wallet} on Ethereum mainnet with a phased rollout. The Safe team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated.

    Safe post mortem

    Martin Koeppelmann, co-founder of Gnosis, the team behind Safe, thanked Bybit CEO Ben Zhou for his leadership during the crisis. Koeppelmann emphasized the need for additional security layers and reducing reliance on web2 technology to prevent similar incidents in the future.

    Safe always put security first. Including securing its web frontend. It was compromised anyway. We need to add more layers of security like:
    * making it easy to verify transactions independent of what is shown on the front end
    * having additional processes to co-sign that also do… https://t.co/tW4eRmWzoj

    — koeppelmann.eth 🦉💳 (@koeppelmann) February 26, 2025





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhat to expect from today’s Senate digital assets hearing
    Next Article Solana-based Pump.fun regains control of its X page after brief hijack
    James Wilson

    Related Posts

    Dow jumps 330 points as S&P 500 logs strong weekly gain 

    May 16, 2025

    4 Best Crypto Signals for Binance 2025

    May 16, 2025

    Defense Against Dark Web: The Best Dark Web Monitoring Tools 2025

    May 16, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Dow jumps 330 points as S&P 500 logs strong weekly gain 

    4 Best Crypto Signals for Binance 2025

    Defense Against Dark Web: The Best Dark Web Monitoring Tools 2025

    Where and How to Buy Bonfida (FIDA) token? 2025

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Dow jumps 330 points as S&P 500 logs strong weekly gain 

    May 16, 2025

    4 Best Crypto Signals for Binance 2025

    May 16, 2025

    Defense Against Dark Web: The Best Dark Web Monitoring Tools 2025

    May 16, 2025
    Lithosphere News Releases

    Colle AI Optimizes Bitcoin Utility to Improve Multichain NFT Distribution

    May 16, 2025

    Atua AI Refines Multichain Operations for Enterprise Adaptability

    May 16, 2025

    AGII Enhances Contract Speed With Lightweight Autonomous Logic

    May 16, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.