Chanpen Zhao: SAFE report on BYBIT hacks leaves a lot of questions

The SAFE report on the results of the BYBIT hacking investigation of $ 1.46 billion is written in vague and leaves more questions than answers. This was stated by the founder of Binance Chanpeng Zhao (CZ).

“Usually I try not to criticize other representatives of the industry, but from time to time I still do it,” he wrote.

According to the conclusions of the wallet team, Lazarus Group attacked Bybit using the compromised engineer of the developer Safe {Wallet}. The result was a proposal of disguised malicious transaction. The incident occurred during the transfer of funds from the cold storage.

“Lazarus is the North Korean hacker group sponsored by the state, which is well known to the sophisticated attacks of social engineering on the accounting data of the developers, sometimes combined with exploits of zero day,” the authors of the report said.

The examination did not reveal any vulnerabilities in the smart contracts of the wallet or the source code of the front-end and services. The Safe {Wallet} team took additional measures to eliminate the attack vector, they added.

According to CZ, the conclusions presented did not answer a number of important questions:

  1. What does the “hacking of the developer machine” mean and how was it implemented?
  2. How did this device gain access to the “BYBIT account”?
  3. How did the hackers deceive the Ledger check stage from several signatures?
  4. Was BYBIT address with $ 1.46 billion the largest under SAFE and why the attackers did not aim at others?
  5. What lessons can other providers of multisig-wallets for independent storage and users learn?

The co -founder of GNOSS SAFE, Martin Coppelman, presented CZ some explanations.

In general, he repeated the theses from the report regarding the attack vector and could not explain the methods of deceit of the signatories. According to Coppelman, the BYBIT storage was really one of the largest and, apparently, was the first to attack a similar attack-that is why hackers tried to hide its traces.

The entrepreneur also spoke about the measures developed to strengthen transaction safety.

Regarding the third question, CZ was given the answer by the technical director of Ledger Charles Guyme. According to him, the hardware wallet provider provides a number of solutions to ensure the safety of transactions, but it is difficult to integrate them into SAFE due to technical features.

“For me, the most important conclusion from BYBIT hacking is as follows: companies and financial institutions should use solutions for storing corporate level data. The placement of $ 1.46 billion in a free SAFE {Wallet} smart contract with a group of signatures developed for retail users should become a relic of the past, ”the programmer said.

Earlier, the co -founder of Blockstream and Cipheropank Adam Beck came to the conclusion that the cause of hacking the Exchange was the “wrong EVM design”.

Be in the know! Subscribe to Telegram.


Source: Cryptocurrency

You may also like

WAZIRX exchange is preparing to restart
Top News
David

WAZIRX exchange is preparing to restart

The Wazir Indian cryptocurrency exchange, which has suffered from hacking by $ 235 million, will resume work in April-May 2025.