Bybit’s $1.4B Hack: The Biggest in History

Bybit’s $1.4B Hack: The Biggest in History

Bybit’s $1.4B Hack: The Biggest in History

Yesterday, Bybit CEO Ben Zhou announced they had been compromised, with 401,000 ETH stolen ($1.4B). This marks the third major hack in six months attributed to Lazarus, North Korea’s state-backed hacking group, which has stolen over $3B to date. Bybit follows WazirX ($234M) and Radiant ($51M) as the latest victim.


The Attack Pattern: Exploiting Safe-Based Security

All three hacks targeted ETH and used Safe’s multisig smart contract. Safe allows organizations to store funds in a smart contract with predefined spending rules. A typical multisig setup requires multiple signers (e.g., 3 out of 5) to authorize transactions.

To breach these Safe-based wallets, attackers have two primary methods:

1?? Hacking Safe’s infrastructure

2?? Compromising authorizers’ endpoints and tricking them into signing malicious transactions.


How the Bybit Hack Happened

While the exact details are unclear, it likely mirrors the Radiant and WazirX breaches. Lazarus compromised the computers of transaction authorizers. Victims believed they were approving legitimate transactions, but in reality, they signed a fraudulent one.

In Bybit’s case, they were transferring funds and instead of authorizing a simple transfer, they unknowingly signed a transaction that swapped Safe’s implementation for a backdoored version.

The compromised contract (0x96221423681a6d52e184d440a8efcebb105c7242) manipulated the calldata, redirecting control to the attacker’s malicious contract. Game over.


Preventing Future Attacks: Institutional-Grade Security

These hacks are not inevitable. Enterprises must strengthen security with B2B custody solutions designed for institutional needs. Ledger Enterprise (https://enterprise.ledger.com/) provides a dedicated custody platform with built-in governance rules:

? Device access control

? Multi-level transaction approvals (e.g., CFO sign-off for large transfers)

? Whitelisting to ensure wallets can only send to approved destinations

? End-to-end security, with verification on secure hardware devices, and Clear Signing

Even if Lazarus compromised every laptop in an organization, final approval on a secure screen would prevent unauthorized transactions. Unlike on-chain multisig, Ledger Vault’s governance is enforced off-chain, eliminating this attack vector.


Tradelink: Mitigating Exchange Risk

Ledger Enterprise also offers Tradelink, an off-exchange trading platform that reduces counterparty risk.


For Individuals: The Case for Self-Custody

These attacks highlight the importance of self-custody. While exchanges are useful for trading, they should not be used for long-term storage. To stay secure:

?? Use a hardware wallet

?? Manage backups properly

?? Always verify transactions before signing

?? Never blind-sign transactions, especially on Ethereum

Ledger is working to provide Clear Signing for the entire ecosystem, but that requires support from partners for proper integration. We encourage you to review our Clear Signing page and see how you can help push for all smart contracts to have Clear Signing. Since it is not currently available for all Ethereum smart contracts, blind signing remains an option, but at your own risk. EIP-712 transactions are clear-signed on Ledger devices for Safe smart contracts, but embedded calldata transactions and proxies are not yet fully supported. This is coming soon.


Introducing “Transaction Check”: A Game-Changer for Security

Even with clear signing, users must determine if a transaction aligns with their intent. Ledger’s upcoming “Transaction Check” feature will:

? Simulate the transaction before it is sent to the device

? Display a clear-signed transaction with a risk assessment

This world-first security feature could save millions (or even billions) in losses over the coming years. Stay tuned.

Wladimir da S. Vaz ?????? ETcurious

Founder and CEOs(as) | airfun | . ??? Aos de pouca sorte (preparo): ??????? Wick, E.T. Wick! . ??? Eu gostaria de fazer uma . ??. reserva para o jantar. ??????. X PAX. ??. Obrigado!

4 周

[PT-BRA ????] . ??? Pílulas de Sabedoria ?? ?? A chuva que atrapalha o dia de praia é a mesma que ajuda um agricultor O calor que ajuda o vendedor de sorvete é o que atrapalha quem vende cobertor Um carro quebrado é ruim pro dono Mas, é bom pro arrumador A gente tem que entender Que nem todo dia é dia da gente Vai ter o dia que sai tudo como planejado E vai ter o dia que sai tudo diferente Vai ter os dias frios Os dias quentes Os dias que você erra para poder acertar lá na frente é a vida é roda gigante meu amigo E quando você tá lá em cima A vista é Bela E n?o importa quantas vezes você vai para baixo O importante mesmo é tá nela ?????? Excelente semana a todos! Foto: roda gigante de S?o Paulo e a maior da América Latina. Ela está localizada no Parque Candido Portinari, ao lado do Parque Villa-Lobos.

  • 该图片无替代文字
回复
Engr Naib Khan

$1.5M+ Raised by Startups Portfolio || 70+ MVPs Developed || Idea to MVP in 4 Weeks || AI Agents as a Service |Data scientist| Web3, Blockchain, Web & Mobile Apps, Cloud, DevOps, UI/UX, AI researcher

4 周

This hack highlights the urgent need for improved security measures in the crypto industry. Exchanges must prioritize cold wallet security, implement multi-layered authentication, and strengthen governance protocols to prevent such breaches. What additional safeguards do you think could help mitigate these risks?

回复
RUCHIKA KUMARI

Business Development Executive/ Lead Generation/Project Management-International Market

1 个月

Thank you so much for sharing this post. Crypto security is more important than ever. To enhance security, we need more robust countermeasures. By deploying better governance, secure hardware approvals, constant monitoring, and threat intelligence, we can detect and stop many security breaches. #CyberSecurity #CryptoSecurity

回复

要查看或添加评论,请登录

社区洞察

其他会员也浏览了