Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stablecoins are rewriting the rules of traditional finance

    July 5, 2025

    Jerome Powell defies Trump, keeps crypto restrictions at Fed

    July 5, 2025

    Solana captures 95% of tokenized stock trading volume in massive DeFi pivot

    July 5, 2025
    Facebook X (Twitter) Instagram
    Saturday, July 5
    • About
    • Contact us
    • Privacy Policy
    Facebook X (Twitter) LinkedIn YouTube
    Blockchain Echo
    Banner
    • Lithosphere News Releases
    • Bitcoin
    • Crypto
    • Ethereum
    • Litecoin
    • Altcoins
    • Blockchain
    Blockchain Echo
    Home » Bybit $1.4b theft originated from compromised Safe UI
    Crypto

    Bybit $1.4b theft originated from compromised Safe UI

    John SmithBy John SmithFebruary 26, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    An independent audit confirmed that North Korea’s Lazarus Group infiltrated Safe’s infrastructure to compromise Bybit’s ethereum wallet.

    A forensic analysis conducted by Sygnia Labs and Verichain found that Bybit’s security integrity remained intact despite an attack on its Ethereum (ETH) cold wallet on Feb. 21.

    The Dubai-based crypto exchange reported the theft of over 400,000 ethereum, worth approximately $1.4 billion, from its Safe-provided multi-signature wallet last week. Initial speculation suggested that one of Bybit’s signers had been compromised by Lazarus. However, the post-mortem audit traced the root cause to a Safe developer machine.

    “They hot swapped the Gnosis Safe UI with JS code that only targeted Bybit’s cold wallet,” Haseeb Qureshi, managing partner at Dragonfly explained. 

    This means Lazarus successfully compromised a Safe developer with access to specific frontend deployment credentials, allowing bad actors to disguise malicious transactions.

    Safe acknowledged the findings, reaffirming that Bybit’s security remained intact while confirming the attack vector. The protocol also stated that its internal investigation found no vulnerabilities in the Safe smart contracts or source code.

    Following the recent incident, the Safe{Wallet} team conducted a thorough investigation and have now restored Safe{Wallet} on Ethereum mainnet with a phased rollout. The Safe team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated.

    Safe post mortem

    Martin Koeppelmann, co-founder of Gnosis, the team behind Safe, thanked Bybit CEO Ben Zhou for his leadership during the crisis. Koeppelmann emphasized the need for additional security layers and reducing reliance on web2 technology to prevent similar incidents in the future.

    Safe always put security first. Including securing its web frontend. It was compromised anyway. We need to add more layers of security like:
    * making it easy to verify transactions independent of what is shown on the front end
    * having additional processes to co-sign that also do… https://t.co/tW4eRmWzoj

    — koeppelmann.eth 🦉💳 (@koeppelmann) February 26, 2025





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhat to expect from today’s Senate digital assets hearing
    Next Article Solana-based Pump.fun regains control of its X page after brief hijack
    John Smith

    Related Posts

    Stablecoins are rewriting the rules of traditional finance

    July 5, 2025

    Solana captures 95% of tokenized stock trading volume in massive DeFi pivot

    July 5, 2025

    $300 into $60k? 3 coins with Dogecoin-style upside

    July 5, 2025
    Leave A Reply Cancel Reply

    Top Posts

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    About Us

    Stay updated on the world of cryptocurrency
    Your one-stop source for daily crypto news and insights
    Blockchainecho.info: Your trusted daily crypto companion

    Most Popular

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Copyright © 2025
    • Home
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.