
🚨 Cyvers Alerts 🚨|Feb 21, 2025 16:04
🚨UPDATE🚨It seems that @Bybit_Official's #ETH multisig cold wallet was compromised through a deceptive transaction that tricked signers into unknowingly approving a malicious smart contract logic change.
UI deception: Signers saw the correct address and a trusted @safe URL, but the actual signing message modified the smart contract logic.
Complete takeover: This allowed the hacker to gain control of the cold wallet and transfer all ETH to an unknown address.
Read more from Co-founder 👇
https://x.com/benbybit/status/1892963530422505586?t=PC6BrK6bWNNDTeoh-cJ_cQ&s=09
Blind signing risk: Minutes before the hack, the attacker re-implemented @Bybit_Official's Safe multisig wallet, redirecting calls to their malicious contract.
No further signatures needed: Once compromised, the hacker had full control over the wallet, similar to past #WazirX and #Radiant Capital attacks.
Example upgrade transaction: https://etherscan.io/tx/0x57c446161b32c2bb4bc2b309cdc680bea8d703f0ae19f59f6e042c01063e441b
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink