Skip to content
Back to Guavy Wire
Crypto

$1.5B Bybit Hack Exposes Multisig Interface Vulnerabilities

Instruments
ETH
Share

The $1.5 billion Bybit hack in February 2025 was not just a smart-contract bug, but an operational security failure that highlighted the importance of multisig setup and interface integrity.

Bybit's engineers used Safe-based multisig cold wallets to move ETH from cold storage to a warm wallet, a routine operation they had performed many times before. However, attackers hijacked AWS session tokens and swapped a JavaScript bundle served from Safe's own frontend, rewriting the pending transaction without touching the Safe smart contract.

The signers used Ledger hardware wallets, but a hardware wallet can only show what the software feeding it chooses to display. This 'blind signing' was the crux of the problem: the interface, not the cryptography, was the attack surface.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc