Digital Assets

Bybit Incident Research

How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.

Published February 2025

Share:

Research details

Context

The largest theft in cryptocurrency history didn’t exploit a smart contract vulnerability or a private key leak. It exploited the interface signers trusted to show them what they were signing. On 21 February 2025, attackers compromised Bybit’s Safe{Wallet} frontend and drained approximately $1.5 billion in digital assets, while every signer believed they were approving a routine transfer.

Key takeaways

  1. All three signers approved the transaction and none of them saw the real one. The compromised Safe interface displayed a routine transfer while the underlying transaction replaced the wallet’s implementation contract. Multi-signature controls verify that authorised people signed, not that they signed the right thing.
  2. Signers who relied on the Safe interface had no independent way to verify what they were authorising. Clear signing requires the hardware device or a separate trusted channel to display the actual recipient, amount, and contract action. This would have surfaced the discrepancy before the transaction was approved.
  3. The attack originated from a compromised developer machine at Safe{Wallet}, not from Bybit's own infrastructure. Any third-party service in the signing path is inside the security perimeter, whether or not the organisation treats it that way. Whitelisting, anomaly detection, least-privilege access, and regular testing of wallet providers are baseline controls, not optional hardening.

Contributors

  • Rex ZhangOneInfinity
  • Alice HsuOneInfinity
  • Daky WangOneInfinity
  • Jonathan HungOneInfinity
  • Tara ChangOneInfinity

Interested in working together?

Our team is expanding research across Web3, Cybersecurity, and AI.