🚨 Bybit $1.5B Stolen Event—Where’s the Real Vulnerability?
Many people’s first reaction is: “Is Safe multisig insecure?” “Did the cold wallet fail?” “Was the hardware wallet compromised?”
But OneKey’s founder revealed in an interview on Binance: the core issue in this incident may not be the on-chain contract itself, but rather the security risks in the frontend interaction layer.
According to his account:
🔹 The Safe multisig contract itself was not breached
🔹 Cold wallets, Ledger, and other hardware devices were not the direct source of the vulnerability
🔹 The attacker’s target was the Safe official frontend environment
It’s said that after Safe frontend engineers were hit by a social engineering attack, malicious code was injected into the official website frontend.
The most dangerous part:
What users see is a “normal transfer interface”👇
But in reality, the signed transaction hides an operation that uses delegatecall to modify the Safe contract’s permissions.
In the end, the attacker gains control and moves massive assets.
This once again reminds the whole industry:
🔐 Web3 security is not just about protecting private keys
More importantly:
✅ Are the transactions you sign actually real?
✅ Is the wallet interface trustworthy?
✅ Has the frontend code been tampered with?
✅ Has the multisig process been independently verified?
The core of future wallet competition won’t be only “decentralization,” but:
Trusted interaction + risk identification + a user-safe experience.
In the AI × Web3 era, the importance of security infrastructure is being redefined.
Where do you think the biggest security challenges for future wallets will come from?
#比特币两度受阻87300美元
$BTC
$ETH
$BNB
Many people’s first reaction is: “Is Safe multisig insecure?” “Did the cold wallet fail?” “Was the hardware wallet compromised?”
But OneKey’s founder revealed in an interview on Binance: the core issue in this incident may not be the on-chain contract itself, but rather the security risks in the frontend interaction layer.
According to his account:
🔹 The Safe multisig contract itself was not breached
🔹 Cold wallets, Ledger, and other hardware devices were not the direct source of the vulnerability
🔹 The attacker’s target was the Safe official frontend environment
It’s said that after Safe frontend engineers were hit by a social engineering attack, malicious code was injected into the official website frontend.
The most dangerous part:
What users see is a “normal transfer interface”👇
But in reality, the signed transaction hides an operation that uses delegatecall to modify the Safe contract’s permissions.
In the end, the attacker gains control and moves massive assets.
This once again reminds the whole industry:
🔐 Web3 security is not just about protecting private keys
More importantly:
✅ Are the transactions you sign actually real?
✅ Is the wallet interface trustworthy?
✅ Has the frontend code been tampered with?
✅ Has the multisig process been independently verified?
The core of future wallet competition won’t be only “decentralization,” but:
Trusted interaction + risk identification + a user-safe experience.
In the AI × Web3 era, the importance of security infrastructure is being redefined.
Where do you think the biggest security challenges for future wallets will come from?
#比特币两度受阻87300美元
$BTC
$ETH
$BNB

