Crypto Audits: A False Sense of Security
In February 2025, Bybit moved funds from an Ethereum cold wallet to a warm wallet as part of routine transfer. Authorized signers reviewed the destination and approved it, unaware that their screens were manipulated to show a false address. The exchange lost $1.46 billion, with attackers taking around 401,347 ETH and several staked Ethereum assets.
The incident highlights the issue with crypto 'audited' badges, which give investors a false sense of security. These badges often appear on protocol websites alongside a security firm's logo and a link to a PDF. However, they may not cover all aspects of the project's code or operations.
A study by Oak Security found that 23,818 public findings from 22 security firms showed a significant gap between audit findings and actual vulnerabilities. The study also discovered that private-key compromise and phishing were among the leading causes of losses, accounting for 43.9% of stolen value.