Research details
Context
The largest theft in cryptocurrency history didn’t exploit a smart contract vulnerability or a private key leak. It exploited the interface signers trusted to show them what they were signing. On 21 February 2025, attackers compromised Bybit’s Safe{Wallet} frontend and drained approximately $1.5 billion in digital assets, while every signer believed they were approving a routine transfer.
Key takeaways
- All three signers approved the transaction and none of them saw the real one. The compromised Safe interface displayed a routine transfer while the underlying transaction replaced the wallet’s implementation contract. Multi-signature controls verify that authorised people signed, not that they signed the right thing.
- Signers who relied on the Safe interface had no independent way to verify what they were authorising. Clear signing requires the hardware device or a separate trusted channel to display the actual recipient, amount, and contract action. This would have surfaced the discrepancy before the transaction was approved.
- The attack originated from a compromised developer machine at Safe{Wallet}, not from Bybit's own infrastructure. Any third-party service in the signing path is inside the security perimeter, whether or not the organisation treats it that way. Whitelisting, anomaly detection, least-privilege access, and regular testing of wallet providers are baseline controls, not optional hardening.
Contributors
- Rex ZhangOneInfinity
- Alice HsuOneInfinity
- Daky WangOneInfinity
- Jonathan HungOneInfinity
- Tara ChangOneInfinity
Related Research

Recent Centralized Platform Hack Tactics & Mitigation
Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.
Read the analysis
DMM Bitcoin May 2024 Incident Analysis
Reconstructing the probable attack behind DMM Bitcoin’s $305 million loss through on-chain forensic evidence.
Read the analysis
From Control Boundary to Insurance Claim: The CER Framework
When an AI system causes a loss, can it be controlled, reconstructed, and recovered through insurance? A framework for answering that question.
Explore the frameworkInterested in working together?
Our team is expanding research across Web3, Cybersecurity, and AI.

