#BYBIT HACKED! $1.5B stolen! Massive!
🚨First analysis what happened 🚨
Multisig cold wallets are designed for enhanced security, requiring multiple signatures from different parties to authorize transactions. However, in this case, attackers exploited a UI vulnerability to deceive signers into unknowingly approving a malicious transaction.
The wallet’s interface displayed a legitimate-looking transfer request, showing the correct destination address. This misled signers into believing they were authorizing a routine transaction from the cold wallet to a warm wallet for business operations. In reality, the signing request didn’t just transfer funds—it altered the smart contract logic of ByBit’s ETH cold wallet.
This change handed control over to the hackers, bypassing all security measures. Once in control, they drained the entire wallet, transferring $1.5B worth of ETH to an unknown address.
ByBit’s founder and CEO, Ben Zhou, @benbybit insists that this breach was limited to a single ETH cold wallet, with all other cold wallets remaining secure. Withdrawals on the exchange continue as usual—but the scale of this attack is unprecedented. As news spreads, expect a wave of mass withdrawals and heightened scrutiny over ByBit’s security infrastructure.
@arkham picture used. Thanks
