shazow
@shazow.eth
Hot take: @safe wallets should have a default timelock for upgrades. It's a critical path that usurps all other security measures.
3 replies
0 recast
10 reactions
maurelian
@maurelian.eth
Is that what happened with bybit? Best resource?
1 reply
0 recast
1 reaction
shazow
@shazow.eth
Yea, blind signed a "musked" transaction (sounds like it implied it was just a swap to hot wallet) which turned out to be an upgrade in disguise. https://x.com/benbybit/status/1892963530422505586
2 replies
0 recast
2 reactions
J. Valeska π¦π©π«
@
how all signers saw the same UI? all hacked or somehow the hackers can change multisig UIs out there in the wild?
1 reply
0 recast
0 reaction
shazow
@shazow.eth
Unclear. I'm guessing the first one was swindled through malware/false transaction, and the rest didn't bother verifying the transaction very closely.
0 reply
0 recast
0 reaction