
Cos(余弦)😶🌫️|Feb 21, 2025 16:48
Some details of Bybit Safe's multi signature being hacked:
Malicious implementation contract deployed at UTC 2022-02-19 7:15:23
0xbDd077f651EBe7f7b3cE16fe5F2b025BE2969516
The attacker used three owners to sign a transaction at UTC 2025-02-21 14:13:35 to replace the Safe implementation contract with a malicious contract
0x46deef0f52e3a983b67abf4714448a41dd7ffd6d32d32da69d62081c68ad7882
Malicious upgrade logic is embedded in STORAGE [0x0] through DELEGATECALL
0x96221423681A6d52E184D440a8eFCEbB105C7242
Subsequently, the attacker used backdoor functions sweepETH and sweepERC20 in the malicious contract to extract assets from the hot wallet
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink