How the Safe Client Led to Bybit's $1.5 Billion Hack

user avatar

by Giorgi Kostiuk

2 years ago


The recent $1.5 billion hack on Bybit revealed important lessons for the crypto world. This article explores how the attackers used the Safe Client to compromise systems.

Preliminary Conclusions About Safe App Compromise

Official reports revealed that a benign JavaScript file in the Safe app was replaced with malicious code on February 19 at 15:29:25 UTC. The attack specifically targeted Bybit’s Ethereum multisig wallet. The compromise occurred via a Safe developer machine, with a leaked account or API key.

The attack was directed at Bybit but could have affected any exchange or entity.None

Safe Official Statement

In its statement, Safe revealed that the attack was conducted by the Lazarus Group and affected a Bybit machine account, though Safe smart contracts remained unaffected. Additional security measures have been implemented to eliminate the attack vector. External security checks did not reveal vulnerabilities in Safe smart contracts or frontend source code.

Lazarus is a state-sponsored North Korean hacker group known for sophisticated social engineering attacks.None

Official FBI Report

The FBI reports that stolen assets were converted into BTC and other cryptocurrencies, likely to be laundered and turned into fiat via numerous addresses on various blockchains. Recommendations included blocking transactions with addresses connected to activity known as TraderTraitor by the FBI.

The attack has revealed numerous vulnerabilities in secure applications within the crypto space. Users and companies must remain vigilant and cautious about their systems’ security.

Tier I

Sector: #18291

Sealed Hiding Place Room

Resource Cache

Resource Cache

Tier I

Requires 25% Tier Progress to Claim
Meme Cache

Meme Cache

Tier I

Requires 50% Tier Progress to Claim
Equipment Cache

Equipment Cache

Tier I

Requires 75% Tier Progress to Claim

After collecting, hiding places will be stored in your inventory and can be opened with Keys.

Other news

Panel Discussion on Trading Insights at Zoomex After Party

A flagship panel titled 'Where's the Edge' will feature industry KOLs discussing trading strategies and market dynamics.

user avatarKenji Takahashi

Ollie Bearman to Host Interactive QA at Zoomex Event

Ollie Bearman will host an interactive QA session at the ZOOMEX TRADERS AFTER PARTY on October 7, 2026, providing a unique opportunity for traders and motorsport fans to engage directly.

user avatarDiego Alvarez

Zoomex to Host Traders After Party at TOKEN2049 Singapore

Zoomex is set to host the ZOOMEX TRADERS AFTER PARTY on October 7, 2026, at Echo Live Party in Singapore, featuring F1 driver Ollie Bearman, live music, and grand prizes.

user avatarMaria Fernandez

Celestia Developers Release Update for Corto Testing Environment

Celestia has released celestianode v0342corto for the Corto testing environment, aimed at operators participating in the testnet.

user avatarGustavo Mendoza

Starkware Releases Cairo v2195 for Developer Infrastructure

Starkware has launched Cairo v2195, a maintenance update focused on the developer toolchain for the Starknet ecosystem.

user avatarMiguel Rodriguez

Bitget Wallet Enhances Access to Tokenized Stocks with Reality Integration

Bitget Wallet has integrated Reality, allowing users access to over 1,700 tokenized stocks and ETFs.

user avatarRajesh Kumar

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.