Safe: The developer's machine was compromised, leading to the theft of Bybit; there are no vulnerabilities in the contract and frontend code

Feb 26, 2025 23:40:19

Share to

ChainCatcher news, Safe responded on platform X to Bybit's hacking forensic report, stating that the forensic review of the targeted attack by the Lazarus Group on Bybit concluded that the attack on Bybit Safe was executed through compromised Safe{Wallet} developer machines, leading to disguised malicious transactions.

Lazarus is a government-backed North Korean hacking organization known for its complex social engineering attacks on developer credentials, sometimes combined with zero-day vulnerabilities. The forensic review by external security researchers did not indicate any vulnerabilities in the Safe smart contracts or the source code of the front end and services.

Following the recent incident, the Safe{Wallet} team conducted a thorough investigation and has now phased the restoration of Safe{Wallet} on the Ethereum mainnet. The Safe{Wallet} team has completely rebuilt and reconfigured all infrastructure and rotated all credentials to ensure the complete elimination of the attack vector.

After the final results of the investigation are released, the Safe{Wallet} team will publish a complete post-mortem analysis. The Safe{Wallet} front end is still operational and has implemented additional security measures. However, users need to be extra cautious and vigilant when signing transactions.

Related Projects

Latest News

Data: BTC breaks through 92,000 USD

ChainCatcher

Jan 12, 2026 12:46:03

Data: BTC breaks through 92,000 USD

ChainCatcher

Jan 12, 2026 10:46:01

Data: BTC falls below 91,000 USD

ChainCatcher

Jan 12, 2026 08:34:41

Data: ETH breaks through 3100 USD

ChainCatcher

Jan 12, 2026 08:04:03

Data: ETH falls below 3100 USD

ChainCatcher

Jan 12, 2026 07:04:02

Recent Fundraising

More
$50M Dec 30, 2025
-- Dec 26, 2025

New Tokens

More
Dec 24, 2025
Dec 23, 2025
Dec 20, 2025

Latest Updates on 𝕏

More