Alex Garcia pfp
Alex Garcia
@alexgarcia
In case anyone is interested, Bybit Hack Forensics Report: https://docsend.com/view/s/rmdi832mpt8u93s7 TL;DR: - Hackers injected malicious code into app.safe.global on Feb 19, 2025, targeting Bybit’s Ethereum Multisig Cold Wallet. - The attack was triggered automatically during Bybit’s next transaction on Feb 21, 2025. - Investigation suggests Safe.Global’s AWS or CloudFront credentials were compromised, allowing attackers to modify the JavaScript file. - The malicious code was found in the Wayback Machine archive, confirming its legitimacy. - Further investigation is needed to determine the full impact and root cause. Bottom line: A supply chain attack was used to compromise a key security tool, leading to a targeted wallet exploit.
3 replies
21 recasts
36 reactions

sid pfp
sid
@sidsethi
Great thread @alexgarcia We're working on this problem at @earthfast https://warpcast.com/sidsethi/0x6f7c4fd8
1 reply
0 recast
2 reactions

Alex Garcia pfp
Alex Garcia
@alexgarcia
Nice!👀
0 reply
0 recast
0 reaction