/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Source: Bybit hackers planted malicious code to manipulate transactions by compromising a developer's computer at crypto wallet provider Safe, used by Bybit

On the night of Feb. 21, Ben Zhou, the chief executive of the cryptocurrency exchange Bybit, logged on to his computer to approve what appeared to be a routine transaction.

New York Times David Yaffe-Bellany

Context & Ripple Effects

The incident first surfaced as suspicious outflows from Bybit and was then tied to a compromised cold Ethereum wallet. Subsequent coverage described UI manipulation and social engineering around employee devices; this account places the compromise upstream, at a developer machine used by wallet provider Safe.

That makes the event more than a failure of a single signer or wallet: the reported attack path reached the transaction-approval environment on which Bybit relied. The later movement of stolen ETH through swaps shows why containment and transaction review matter after an approval-path breach.

First-order effects

  • Bybit and Safe face an immediate incident scope that includes the compromised developer endpoint, the code it could have affected, and the transaction-display and approval path used by Bybit.
  • The report reinforces that an apparently routine approval could be manipulated before it reached the executive signer, consistent with the previously reported UI manipulation of employee devices.

Second-order effects

  • Exchanges using third-party wallet infrastructure will need to scrutinize whether their signing controls independently verify transaction details rather than relying on a provider-controlled interface.
  • Wallet providers face pressure to harden developer access and software-release controls, since a compromise in that layer can undermine customers’ cold-wallet governance without directly taking a signer’s credentials.

Third-order effects

  • If similar incidents persist, crypto custody security will be judged less by whether assets are labeled “cold” and more by the integrity of the software supply chain and human approval interfaces around those assets.
  • The case adds to the post-theft challenge of tracing and moving stolen assets, sustaining the sector’s broader trust and operational-resilience problem rather than isolating risk to any one exchange.

The trend: Crypto custody is shifting from a narrow focus on key storage toward end-to-end assurance of the software, interfaces, and people that authorize transactions.

Discussion

  • @evil-genius @evil-genius on bluesky
    I remeber when the whole point of crypto was a decentralized currency that wouldn't be subject to banks and institutional stupidity.  —  Losing billions because some third party companies employee's incompetence doesn't sound like it [embedded post]
  • @frichetten.com Nick Frichette on bluesky
    New details on the ByBit/Safe{Wallet} breach, and uhhh wow, some really silly blunders on the DPRK side.  They still succeeded which is the most upsetting part of all of this.  Let's bully some threat actor tradecraft!  A🧵  —  x.com/safe/status/...
  • @safe @safe on x
    Investigation Updates and Community Call to Action
  • @schorlukas @schorlukas on x
    tl;dr - It was a targeted attack, only the Bybit Safe was affected - It took 19 days (+ preparation) to pull off the attack - Attack circumvented 2FA - We need better transaction verification UX & industry efforts for secure (decentralized) frontends, not just smart contracts
  • @safe @safe on x
    Safe{Wallet} is fully back! Our entire stack—including all networks, and the Safe API—is now fully restored and ready for use! Check live status updates here: https://status.safe.global/ Thank you for your patience and support!
  • @talbeerysec Tal Be'ery on x
    A simplified flowchart of the ByBit Heist: 1. Attackers infects a Safe{wallet} Dev machine with malware, 2. Rides its session to change wallet website, 3. Changed website offer malicious Tx to ByBit signers, 4. which transfer ownership to attackers. 5. Attackers withdraws $1.5B […
  • @talbeerysec Tal Be'ery on x
    A few interesting details from @Mandiant report on @safe wallet hack leading to @Bybit_Official breach. 1. The initial access seems to be a social engineering a developer to “help” with a Docker FinTech project, as described by @SlowMist_Team @im23pds [image]