icon
icon
icon
icon
$300 Off
$300 Off

News /

Articles /

Safe Wallet Admits Role in $1.5B Bybit Hack Amid Industry Backlash

Coin WorldThursday, Feb 27, 2025 1:25 am ET
1min read

Safe Wallet Confirms Role in $1.5 Billion Bybit Hack Amid Industry Criticism

Safe Wallet, a popular cryptocurrency wallet provider, has confirmed its involvement in the recent $1.5 billion hack of Bybit, a major cryptocurrency exchange. The hack, which occurred earlier this month, saw hackers exploit a vulnerability in Safe Wallet's infrastructure to gain unauthorized access to Bybit's cold wallet.

The attack reportedly originated from a compromised developer machine and involved a disguised malicious transaction that facilitated unauthorized access. Safe Wallet has since clarified that its smart contracts were not compromised in the attack, and that the forensic review of external security researchers did not indicate any vulnerabilities in the Safe smart contracts or source code of the frontend and services.

In response to the incident, Safe Wallet has implemented additional security measures and announced an industry-wide initiative to improve transaction verifiability across the ecosystem. The company has also stated that it will release a full post-mortem report once the investigation concludes.

However, Safe Wallet's explanation has not been well-received by members of the crypto community. Many users, including prominent industry figures, have criticized it as insufficient and vague. Changpeng Zhao (CZ), the former CEO of Binance, expressed doubts about Safe Wallet's handling of the situation, questioning the security of the developer machine, the deployment of code to Bybit's production environment, and how the hackers were able to bypass Ledger verification steps.

Another analyst advocated for stronger security management, confirming that while the smart contract layer was intact, the attack had tampered with the front end. This enabled the hackers to manipulate transactions, describing this as a classic supply chain attack and warning that all user-interactive services involving frontends, APIs, and similar infrastructure could be at risk.

Last week, hackers stole 40,000 ETH from Bybit's cold wallet. Initially, reports suggested that the North Korean Lazarus Group carried out the attack, and now the US Federal Bureau of Investigation (FBI) has confirmed their involvement. The public service announcement has identified the operation as "TraderTraitor," with the FBI urging virtual asset service providers, including exchanges, blockchain analytics firms, and decentralized finance (DeFi) services, to block transactions connected to the addresses involved in the laundering efforts.

Comments

Add a public comment...
Post
User avatar and name identifying the post author
EmergencyWitness7
02/27
Safe Wallet's explanation feels like a weak link.
0
Reply
User avatar and name identifying the post author
throwaway0203949
02/27
Holding $ETH, diversifying to avoid similar losses.
0
Reply
User avatar and name identifying the post author
Liteboyy
02/27
FBI's on it, but can we trust Safe?
0
Reply
User avatar and name identifying the post author
Holiday_Context5033
02/27
Lazarus Group always causes chaos in crypto.
0
Reply
User avatar and name identifying the post author
Fauster
02/27
Bybit hack = 🚨 warning for weak supply chains.
0
Reply
User avatar and name identifying the post author
Historical_Hearing76
02/27
Safe Wallet's explanation feels like a smokescreen. How can we trust them when details are sketchy?
0
Reply
User avatar and name identifying the post author
JobuJabroni
02/27
@Historical_Hearing76 True, sketchy details aren't reassuring.
0
Reply
User avatar and name identifying the post author
AbuSaho
02/27
This hack's like a ticking time bomb. If the frontend was compromised, who's to say others aren't in the same boat?
0
Reply
User avatar and name identifying the post author
johnnyko55555
02/27
Safe Wallet's explanation feels like a puzzle with missing pieces. Transparency is key, but they're playing it cool for now.
0
Reply
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App