shazow pfp
shazow
@shazow.eth
Hot take: @safe wallets should have a default timelock for upgrades. It's a critical path that usurps all other security measures.
3 replies
0 recast
10 reactions

maurelian  pfp
maurelian
@maurelian.eth
Is that what happened with bybit? Best resource?
1 reply
0 recast
1 reaction

shazow pfp
shazow
@shazow.eth
Yea, blind signed a "musked" transaction (sounds like it implied it was just a swap to hot wallet) which turned out to be an upgrade in disguise. https://x.com/benbybit/status/1892963530422505586
2 replies
0 recast
2 reactions

shazow pfp
shazow
@shazow.eth
Ongoing investigative notes from @tayvano over here: https://github.com/tayvano/lazarus-bluenoroff-research/blob/main/hacks-and-thefts/bybit.md
1 reply
0 recast
1 reaction

shazow pfp
shazow
@shazow.eth
More here: https://blog.trailofbits.com/2025/02/21/the-1.5b-bybit-hack-the-era-of-operational-security-failures-has-arrived/
0 reply
0 recast
1 reaction