icon
icon
icon
icon
Upgrade
Upgrade

News /

Articles /

Bybit's $1.5B Crypto Heist: Social Engineering, Safe Contract Exploit

Coin WorldWednesday, Feb 26, 2025 3:51 am ET
1min read

On February 21, 2025, cryptocurrency exchange Bybit suffered a significant security breach, resulting in the loss of nearly $1.5 billion in assets. The attack targeted the exchange's on-chain multisig wallet, exploiting a vulnerability in the Safe contract used to manage the funds.

The breach was discovered by SlowMist, a blockchain security firm, which published an analysis of the incident. According to their findings, the attacker gained multisig permission through a sophisticated social engineering attack, then exploited the delegatecall feature of the Safe contract to implant malicious logic. This allowed the attacker to bypass the multisig verification mechanism and transfer the funds to an anonymous address.

Bybit was using version 1.1.1 of the Safe contract at the time of the breach, which lacked the Guard mechanism, a key security feature introduced in version 1.3.0. If Bybit had upgraded to the latest version of the Safe contract and implemented proper Guard mechanisms, such as specifying a whitelist address that can receive funds and enforcing strict contract function ACL verification, the breach might have been prevented.

This incident serves as a reminder that even robust security measures like multisig wallets can be vulnerable if not properly maintained and updated. As the cryptocurrency industry continues to grow, it is crucial for exchanges and other custodial services to stay vigilant and implement the latest security measures to protect their users' assets.

Comments

Add a public comment...
Post
Refresh
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App