官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

加密历史

2025: the Bybit theft and the limits of a transaction signature

The FBI's attribution record documents a major theft; a valid signature alone does not establish informed approval.

Incident history · February 2025 · 1 min read

研究文章和参考条目以英语发布。导航提供七种语言。

人物与项目

本文目录
  1. The public attribution
  2. The signing question
  3. 来源与原始文件

The public attribution

The FBI's 26 February 2025 notice attributed approximately $1.5 billion stolen from Bybit on or about 21 February to North Korean TraderTraitor activity. The notice described conversions across assets and distribution across thousands of addresses, and supplied addresses associated with the theft.

That record establishes the agency's attribution and its published tracing leads. It is not a substitute for a full technical postmortem of every component involved. An address can be a useful indicator while the exact human operator or intermediate service role still requires additional evidence.

The signing question

The broader security issue is whether the people authorising a transaction can independently verify its actual effect. A signature proves authorisation by a key under a particular message format. It does not prove that an interface displayed the correct destination, call or resulting permissions.

This is why frontend integrity, Safe modules and typed-data review belong in a custody assessment. Requiring several signatures can reduce single-key risk while still leaving a shared display or software dependency. This analytical distinction is general; the FBI notice alone should not be cited as proof of a particular user-interface exploit.

来源与原始文件

相关阅读

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包