Close Menu
FintechFetch
    FintechFetch
    • Home
    • Fintech
    • Financial Technology
    • Credit Cards
    • Finance
    • Stock Market
    • More
      • Business Startups
      • Blockchain
      • Bitcoin News
      • Cryptocurrency
    FintechFetch
    Home»Cryptocurrency»CZ Criticizes Safe Wallet’s Post-Mortem on Bybit Hack
    Cryptocurrency

    CZ Criticizes Safe Wallet’s Post-Mortem on Bybit Hack

    FintechFetchBy FintechFetchFebruary 28, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Former Binance CEO Changpeng Zhao (CZ) has criticized Safe Wallet’s post-mortem update on the Bybit hack, calling it “not that great” and raising concerns about how attackers tricked multiple signers.

    His comments follow an audit report stating that the breach resulted from a compromise of Safe’s infrastructure rather than the exchange’s systems.

    Safe’s Response

    Forensic investigations found that compromised Safe Wallet credentials led to the nearly $1.5 billion Bybit exploit. In a statement on X on Wednesday, the crypto wallet provider confirmed the findings, stating that the hack stemmed from a “compromised Safe Wallet developer machine.”

    The company highlighted that the reports did not identify vulnerabilities in its smart contracts or front-end source code. It also announced that it had fully rebuilt and reconfigured its infrastructure and changed all credentials, ensuring the attack vector was “fully eliminated.”

    However, CZ criticized the statement, saying:

    “This update from Safe is not that great. It uses vague language to brush over the issues. I have more questions than answers after reading it.”

    He questioned what “compromising a Safe {Wallet} developer machine” meant and how the attack happened, asking whether social engineering or a virus was involved. He also inquired how the developer machine had access to an account operated by Bybit and whether the code was deployed directly to production.

    Further concerns were raised about how the attackers bypassed Ledger verification, whether blind signing was involved, or if signers failed to verify properly.

    The Report and Updates

    On February 26, Bybit released a forensic audit conducted by Sygnia and Verichains about the attack. The audit revealed that Safe developer’s credentials had been compromised, giving hackers access to the wallet’s infrastructure, which led to signers being deceived into approving a malicious transaction.

    According to the report, the exploit was carried out using “malicious JavaScript code” that had been injected into Safe’s Amazon Web Services system two days earlier. The script activated only when transactions came from specific contract addresses, including Bybit’s multi-sig contract and another address suspected to belong to the criminal.

    Just two minutes after the hack, the attackers removed the malicious code from Safe’s system and disappeared. Forensic experts and the company have also confirmed that Bybit’s infrastructure was not compromised.

    Since the incident, Bybit has borrowed 40,000 ETH from Bitget to meet withdrawal demands, which have since been repaid. The firm has also restored its reserves through loans, asset purchases, and whale deposits, securing 446,870 ETH valued at $1.23 billion. CEO Ben Zhou confirmed that the exchange now has 100% backing for client assets.

    SPECIAL OFFER (Sponsored)

    Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

    LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleUp just 8% in 5 years, what’s going on with the National Grid share price?
    Next Article Metaplanet Buys More Bitcoins Worth $13.6 Million, Aims To hold 21,000 BTC By 2026
    FintechFetch
    • Website

    Related Posts

    Cryptocurrency

    Insider Selloff? Trump Wallets Offload TRUMP Tokens Hours Before US-Iran Clash

    June 22, 2025
    Cryptocurrency

    Trump announces US airstrikes on Iran’s nuclear sites, Bitcoin dumps, then pumps

    June 22, 2025
    Cryptocurrency

    Despite Stablecoin Boom, PayPal’s PYUSD and SocGen’s EURCV Struggle to Gain Traction

    June 22, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    This Week in Fintech: TFT Bi-Weekly News Roundup 15/04

    April 15, 2025

    Japan Moves To Reform Stablecoin Regulations And Crypto Brokerage Regulations

    February 20, 2025

    3 simple Warren Buffett wealth-building techniques you could use today

    June 8, 2025

    Why Is Ripple’s (XRP) Price Up Today?

    April 28, 2025

    Small Firms Benefit From Higher Interest on Savings as ClearBank Partners With Capital on Tap

    February 16, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    Most Popular

    GSK’s share price looks a steal to me anywhere below £43.29, and here’s why

    April 2, 2025

    Nium Expands Instant Payment Services to Australia

    February 24, 2025

    Bitcoin ETFs Get $2 Million Boost From National Bank of Canada

    February 14, 2025
    Our Picks

    Bitcoin Closes Daily Price Below 50MA

    June 22, 2025

    Etraveli Group Selects Mastercard to Improve Its Fintech Arm’s Product, PRECISION

    June 22, 2025

    Using AI in Customer Service? Don’t Make These 4 Mistakes

    June 22, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Fintechfetch.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.