{"id":15394,"date":"2025-02-27T20:17:12","date_gmt":"2025-02-27T20:17:12","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=15394"},"modified":"2025-02-27T20:17:12","modified_gmt":"2025-02-27T20:17:12","slug":"cz-criticizes-safe-wallets-post-mortem-on-bybit-hack","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=15394","title":{"rendered":"CZ Criticizes Safe Wallet\u2019s Post-Mortem on Bybit Hack"},"content":{"rendered":"<div>\n<p>Former Binance CEO Changpeng Zhao (CZ) has criticized Safe Wallet\u2019s post-mortem update on the Bybit hack, calling it \u201cnot that great\u201d and raising concerns about how attackers tricked multiple signers.<\/p>\n<p>His comments follow an audit report stating that the breach resulted from a compromise of Safe\u2019s infrastructure rather than the exchange\u2019s systems.<\/p>\n<h2>Safe\u2019s Response<\/h2>\n<p>Forensic investigations found that compromised Safe Wallet credentials led to the nearly $1.5 billion Bybit <a href=\"https:\/\/cryptopotato.com\/bitcoin-price-crashes-on-reports-of-alleged-1-5b-bybit-security-incident\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\">exploit<\/a>. In a statement on X on Wednesday, the crypto wallet provider confirmed the findings, stating that the hack stemmed from a \u201ccompromised Safe Wallet developer machine.\u201d<\/p>\n<p>The company <a href=\"https:\/\/x.com\/safe\/status\/1894768522720350673\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"external\">highlighted<\/a> that the reports did not identify vulnerabilities in its smart contracts or front-end source code. It also announced that it had fully rebuilt and reconfigured its infrastructure and changed all credentials, ensuring the attack vector was \u201cfully eliminated.\u201d<\/p>\n<p>However, CZ <a href=\"https:\/\/x.com\/cz_binance\/status\/1894787596443885698\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"external\">criticized<\/a> the statement, saying:<\/p>\n<blockquote>\n<p>\u201cThis update from Safe is not that great. It uses vague language to brush over the issues. I have more questions than answers after reading it.\u201d<\/p>\n<\/blockquote>\n<p>He questioned what \u201ccompromising a Safe {Wallet} developer machine\u201d meant and how the attack happened, asking whether social engineering or a virus was involved. He also inquired how the developer machine had access to an account operated by Bybit and whether the code was deployed directly to production.<\/p>\n<p>Further concerns were raised about how the attackers bypassed Ledger verification, whether blind signing was involved, or if signers failed to verify properly.<\/p>\n<h2>The Report and Updates<\/h2>\n<p>On February 26, Bybit <a href=\"https:\/\/x.com\/benbybit\/status\/1894768736084885929\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"external\">released<\/a> a forensic audit conducted by Sygnia and Verichains about the attack. The audit revealed that Safe developer\u2019s credentials had been compromised, giving hackers access to the wallet\u2019s infrastructure, which led to signers being deceived into approving a malicious transaction.<\/p>\n<p>According to the report, the exploit was carried out using \u201cmalicious JavaScript code\u201d that had been injected into Safe\u2019s Amazon Web Services system two days earlier. The script activated only when transactions came from specific contract addresses, including Bybit\u2019s multi-sig contract and another address suspected to belong to the criminal.<\/p>\n<p>Just two minutes after the hack, the attackers removed the malicious code from Safe\u2019s system and disappeared. Forensic experts and the company have also confirmed that Bybit\u2019s infrastructure was not compromised.<\/p>\n<p>Since the incident, Bybit has <a href=\"https:\/\/x.com\/lookonchain\/status\/1893121934210084981\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"external\">borrowed<\/a> 40,000 ETH from Bitget to meet withdrawal demands, which have since been repaid. The firm has also <a href=\"https:\/\/cryptopotato.com\/ethereum-bounces-back-as-bybit-closes-gap-on-hack-losses\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\">restored<\/a> its reserves through loans, asset purchases, and whale deposits, securing 446,870 ETH valued at $1.23 billion. CEO Ben Zhou <a href=\"https:\/\/x.com\/benbybit\/status\/1893865556840775758\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"external\">confirmed<\/a> that the exchange now has 100% backing for client assets.<\/p>\n<p>The post <a href=\"https:\/\/cryptopotato.com\/cz-criticizes-safe-wallets-post-mortem-on-bybit-hack\/\" rel=\"nofollow\">CZ Criticizes Safe Wallet\u2019s Post-Mortem on Bybit Hack<\/a> appeared first on <a href=\"https:\/\/cryptopotato.com\/\" rel=\"nofollow\">CryptoPotato<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Former Binance CEO Changpeng Zhao (CZ) has criticized Safe Wallet\u2019s post-mortem update on the Bybit hack, calling it \u201cnot that great\u201d and raising concerns about how attackers tricked multiple signers. His comments follow an audit report stating that the breach resulted from a compromise of Safe\u2019s infrastructure rather than the exchange\u2019s systems. Safe\u2019s Response Forensic [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-15394","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/15394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15394"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/15394\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}