Source: Bybit hackers planted malicious code to manipulate transactions by compromising a developer's computer at crypto wallet provider Safe, used by Bybit
On the night of Feb. 21, Ben Zhou, the chief executive of the cryptocurrency exchange Bybit, logged on to his computer to approve what appeared to be a routine transaction.
Context & Ripple Effects
The incident first surfaced as suspicious outflows from Bybit and was then tied to a compromised cold Ethereum wallet. Subsequent coverage described UI manipulation and social engineering around employee devices; this account places the compromise upstream, at a developer machine used by wallet provider Safe.
That makes the event more than a failure of a single signer or wallet: the reported attack path reached the transaction-approval environment on which Bybit relied. The later movement of stolen ETH through swaps shows why containment and transaction review matter after an approval-path breach.
First-order effects
- Bybit and Safe face an immediate incident scope that includes the compromised developer endpoint, the code it could have affected, and the transaction-display and approval path used by Bybit.
- The report reinforces that an apparently routine approval could be manipulated before it reached the executive signer, consistent with the previously reported UI manipulation of employee devices.
Second-order effects
- Exchanges using third-party wallet infrastructure will need to scrutinize whether their signing controls independently verify transaction details rather than relying on a provider-controlled interface.
- Wallet providers face pressure to harden developer access and software-release controls, since a compromise in that layer can undermine customers’ cold-wallet governance without directly taking a signer’s credentials.
Third-order effects
- If similar incidents persist, crypto custody security will be judged less by whether assets are labeled “cold” and more by the integrity of the software supply chain and human approval interfaces around those assets.
- The case adds to the post-theft challenge of tracing and moving stolen assets, sustaining the sector’s broader trust and operational-resilience problem rather than isolating risk to any one exchange.
The trend: Crypto custody is shifting from a narrow focus on key storage toward end-to-end assurance of the software, interfaces, and people that authorize transactions.