{"id":467300,"date":"2025-02-26T19:45:59","date_gmt":"2025-02-26T19:45:59","guid":{"rendered":"https:\/\/cryptoslate.com\/?p=467300"},"modified":"2025-12-13T00:59:55","modified_gmt":"2025-12-13T00:59:55","slug":"bybit-exploit-tied-to-safe-developer-machine-vulnerability","status":"publish","type":"post","link":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/","title":{"rendered":"Bybit exploit tied to Safe developer machine vulnerability"},"content":{"rendered":"<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/cryptoslate.com\/companies\/bybit\/\">Bybit<\/a> revealed that the recent $1.4 billion hack did not compromise its infrastructure and was caused by a vulnerability in a <a href=\"https:\/\/cryptoslate.com\/companies\/safe\/\">Safe<\/a> developer machine.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to the exchange's initial <a href=\"https:\/\/x.com\/benbybit\/status\/1894768736084885929\">forensic report<\/a>, the attack was executed through Safe\u2019s AWS S3 bucket, allowing bad actors to manipulate the wallet front end.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Meanwhile, Safe said in a separate Feb. 26<\/span>\u00a0<span style=\"font-weight: 400;\"><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\"><a href=\"https:\/\/x.com\/safe\/status\/1894768522720350673\" target=\"_blank\" rel=\"noopener\"><strong>report<\/strong><\/a> that<\/span>\u00a0the hackers used a compromised machine to submit a disguised malicious transaction proposal. This proposal injected harmful JavaScript into key resources, enabling the attackers to manipulate transactions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The forensic investigation conducted by Bybit and blockchain security firms Sygnia and Verichains reached the same conclusion as Safe.<\/span><\/p>\n<h2><strong>Attack execution and forensic findings<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">The Safe report highlighted that the attackers designed the injected code to modify transaction contents during the signing process, effectively altering the intended execution. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Publicly available web history archives and timestamp analysis indicate that the injection occurred directly into the S3 bucket \u2014<\/span><span style=\"font-weight: 400;\">\u00a0an <a href=\"https:\/\/cryptoslate.com\/companies\/amazon\/\">Amazon<\/a> Web Services (AWS) public cloud storage resource that stores data for objects in distinct units.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The malicious JavaScript code analysis revealed an activation condition tied to specific contract addresses, including Bybit\u2019s contract address and an unidentified contract address suspected to be controlled by the threat actor.\u00a0<\/span><span style=\"font-weight: 400;\">This suggests the hackers employed a targeted approach rather than a widespread attack.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Shortly after the malicious transaction was executed and published, Safe uploaded updated versions of the JavaScript resources to its AWS infrastructure. These versions removed the injected code, indicating an effort to erase traces of the compromise.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Despite this, forensic investigators identified the attack vector and linked it to the broader tactics used by the North Korean hacker group Lazarus. The group is allegedly state-sponsored and notorious for leveraging social engineering and zero-day exploits to target developer credentials.<\/span><\/p>\n<h2><strong>A small security detail<\/strong><\/h2>\n<p>SlowMist founder Yu Xian<strong><a href=\"https:\/\/x.com\/evilcos\/status\/1894785161692369048\"> said<\/a><\/strong><span style=\"font-weight: 400;\"> it's still unclear how the hackers tampered with the front end. He added that, in theory, anyone who uses Safe\u2019s multi-signature services could suffer the same exploit.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to Xian:<\/span><\/p>\n<blockquote><p><strong>&#8220;What is terrifying is that all other user-interactive services with front-ends, APIs, etc. may be at risk. This is also a classic supply chain attack. The security management model for huge\/large assets needs a major upgrade.&#8221;<\/strong><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\">Additionally, he<\/span> <strong><a href=\"https:\/\/x.com\/evilcos\/status\/1894794067403513876\">assessed<\/a><\/strong><span style=\"font-weight: 400;\"> that if the Safe front-end had performed basic subresource integrity (SRI) verification, the attack would not have been possible even if a malicious actor modified the JavaScript file, which is a &#8220;small security detail.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">SRI verification is a security feature that enables browsers to verify that the resources they fetch are not unexpectedly manipulated based on a cryptographic hash that the fetched resource must match.<\/span><\/p>\n<h2><strong>Safe response and remediation measures<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">Safe said it had initiated a comprehensive investigation to assess the extent of the compromise. The forensic review found no vulnerabilities in its smart contracts, front-end source code, or back-end services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Safe has fully rebuilt and reconfigured its infrastructure to mitigate future risks while rotating all credentials. The platform has been restored on the Ethereum mainnet with a phased rollout, incorporating enhanced security measures.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While the Safe front-end remains operational, the report urged users to exercise heightened caution when signing transactions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, Safe said it is committed to leading an industry-wide initiative to increase transaction verifiability. This initiative addresses an ecosystem-wide challenge, emphasizing security, transparency, and self-custody within DeFi applications.<\/span><\/p>\n<h2><strong>Lessons from the incident<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">Despite Safe and Bybit\u2019s reports concluding that the exchange was not compromised, Hasu, the strategy lead at Flashbots, believes they still need to be held accountable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">He<\/span> <strong><a href=\"https:\/\/x.com\/hasufl\/status\/1894772256179405158\">said<\/a><\/strong><span style=\"font-weight: 400;\"> that Bybit infra was insufficient to catch \u201ca pretty simple hack\u201d and that there is no excuse for not verifying message integrity when moving over $1 billion of funds.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Hasu added:<\/span><\/p>\n<blockquote><p><strong>&#8220;I'm afraid if we put the blame on SAFE instead of Bybit here, we are learning entirely the wrong lesson from this as a space. Frontends should _always_ be assumed compromised. If your signing process doesn't accommodate that, you're ultimately still at fault.&#8221;<\/strong><\/p><\/blockquote>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/cryptoslate.com\/people\/jameson-lopp\/\">Jameson Lopp<\/a>, co-founder and chief security officer at <a href=\"https:\/\/cryptoslate.com\/companies\/casa\/\">Casa<\/a>,<\/span> <strong><a href=\"https:\/\/x.com\/lopp\/status\/1894787891466842312\">pointed out<\/a><\/strong><span style=\"font-weight: 400;\"> that &#8220;a major lesson&#8221; from the Safe security incident is that no developer should have production keys on their machines. He recommended that production code deployments undergo peer review and involve multiple employees to enhance security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Mudit Gupta, the chief information security officer at <a href=\"https:\/\/cryptoslate.com\/companies\/polygon-labs\/\">Polygon Labs<\/a>, also criticized the fact that only one developer had the system authority to submit changes to Safe\u2019s production website and questioned why changes in the objects were not monitored.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bybit revealed that the recent $1.4 billion hack did not compromise its infrastructure and was caused by a vulnerability in a Safe developer machine. According to the exchange&#8217;s initial forensic report, the attack was executed through Safe\u2019s AWS S3 bucket, allowing bad actors to manipulate the wallet front end. Meanwhile, Safe said in a separate [&hellip;]<\/p>\n","protected":false},"author":1511,"featured_media":467345,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,39,77968,16041],"tags":[],"prediction_market_topic":[],"post_folder":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.9 (Yoast SEO v21.9.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Bybit exploit tied to Safe developer machine vulnerability<\/title>\n<meta name=\"description\" content=\"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Bybit exploit tied to Safe developer machine vulnerability\" \/>\n<meta property=\"og:description\" content=\"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"CryptoSlate\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-26T19:45:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-13T00:59:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/02\/ethereum-bybit-hack.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Gino Matos\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cryptoslate\" \/>\n<meta name=\"twitter:site\" content=\"@cryptoslate\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gino Matos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\"},\"author\":{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptoslate.com\/author\/gino-matos\/#person\",\"name\":\"Gino Matos\",\"url\":\"https:\/\/cryptoslate.com\/author\/gino-matos\/\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cryptoslate.com\/author\/gino-matos\/\"},\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/cryptoslate.com\/author\/gino-matos\/#authorimage\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-300x300.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-300x300.jpg\",\"caption\":\"Gino Matos\"},\"jobTitle\":\"Reporter\",\"description\":\"Gino Matos is a seasoned crypto journalist and law graduate covering Brazil\u2019s blockchain ecosystem and DeFi developments.\",\"worksFor\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"sameAs\":[\"https:\/\/x.com\/pelicamatos\",\"https:\/\/www.linkedin.com\/in\/ginomatos\",\"https:\/\/muckrack.com\/gino-matos\"]},\"headline\":\"Bybit exploit tied to Safe developer machine vulnerability\",\"datePublished\":\"2025-02-26T19:45:59+00:00\",\"dateModified\":\"2025-12-13T00:59:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\"},\"wordCount\":756,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"articleSection\":[\"Crypto\",\"Exchanges\",\"Featured\",\"Hacks\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\",\"url\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\",\"name\":\"Bybit exploit tied to Safe developer machine vulnerability\",\"isPartOf\":{\"@id\":\"https:\/\/cryptoslate.com\/#website\"},\"datePublished\":\"2025-02-26T19:45:59+00:00\",\"dateModified\":\"2025-12-13T00:59:55+00:00\",\"description\":\"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.\",\"breadcrumb\":{\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptoslate.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Bybit exploit tied to Safe developer machine vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptoslate.com\/#website\",\"url\":\"https:\/\/cryptoslate.com\/\",\"name\":\"CryptoSlate\",\"description\":\"Cryptocurrency News and Real-time Coin Data\",\"publisher\":{\"@id\":\"https:\/\/cryptoslate.com\/#organization\"},\"inLanguage\":\"en-US\"},{\"@type\":\"NewsMediaOrganization\",\"@id\":\"https:\/\/cryptoslate.com\/#organization\",\"name\":\"CryptoSlate\",\"url\":\"https:\/\/cryptoslate.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"CryptoSlate\"},\"image\":{\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/twitter.com\/cryptoslate\",\"https:\/\/www.instagram.com\/cryptoslate\",\"https:\/\/www.linkedin.com\/company\/cryptoslate\",\"https:\/\/www.youtube.com\/c\/cryptoslate\",\"https:\/\/cryptoslate.substack.com\",\"https:\/\/t.me\/cryptoslatenews\",\"https:\/\/www.crunchbase.com\/organization\/cryptoslate\",\"https:\/\/iq.wiki\/wiki\/cryptoslate\",\"https:\/\/news.google.com\/publications\/CAAqKggKIiRDQklTRlFnTWFoRUtEMk55ZVhCMGIzTnNZWFJsTG1OdmJTZ0FQAQ\",\"https:\/\/muckrack.com\/media-outlet\/cryptoslate\",\"https:\/\/www.tiktok.com\/@cryptoslatenews\"],\"publishingPrinciples\":\"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles\",\"ownershipFundingInfo\":\"https:\/\/cryptoslate.com\/disclaimers\/how-cryptoslate-makes-and-spends-money\/\",\"correctionsPolicy\":\"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback\",\"ethicsPolicy\":\"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles\",\"foundingDate\":\"2017-08-04\",\"founder\":[{\"@type\":\"Person\",\"name\":\"Nate Whitehill\"},{\"@type\":\"Person\",\"name\":\"Matthew Blancarte\"}],\"contactPoint\":[{\"@type\":\"ContactPoint\",\"contactType\":\"customer support\",\"url\":\"https:\/\/cryptoslate.com\/contact\/\",\"availableLanguage\":\"en-US\"},{\"@type\":\"ContactPoint\",\"contactType\":\"sales\",\"url\":\"https:\/\/cryptoslate.com\/advertising\/\",\"availableLanguage\":\"en-US\"},{\"@type\":\"ContactPoint\",\"contactType\":\"newsroom\",\"url\":\"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback\",\"email\":\"tips@cryptoslate.com\",\"availableLanguage\":\"en-US\"}],\"masthead\":\"https:\/\/cryptoslate.com\/about\/#masthead\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/person\/f03754c9e579651795caf77a2b00c49c\",\"name\":\"Gino Matos\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptoslate.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-150x150.jpg\",\"contentUrl\":\"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-150x150.jpg\",\"caption\":\"Gino Matos\"},\"description\":\"Gino Matos is a law school graduate and a seasoned journalist with six years of experience in the crypto industry. His expertise primarily focuses on the Brazilian blockchain ecosystem and developments in decentralized finance (DeFi).\",\"url\":\"https:\/\/cryptoslate.com\/author\/gino-matos\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Bybit exploit tied to Safe developer machine vulnerability","description":"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Bybit exploit tied to Safe developer machine vulnerability","og_description":"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.","og_url":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/","og_site_name":"CryptoSlate","article_published_time":"2025-02-26T19:45:59+00:00","article_modified_time":"2025-12-13T00:59:55+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/02\/ethereum-bybit-hack.jpg","type":"image\/jpeg"}],"author":"Gino Matos","twitter_card":"summary_large_image","twitter_creator":"@cryptoslate","twitter_site":"@cryptoslate","twitter_misc":{"Written by":"Gino Matos","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#article","isPartOf":{"@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/"},"author":{"@type":"Person","@id":"https:\/\/cryptoslate.com\/author\/gino-matos\/#person","name":"Gino Matos","url":"https:\/\/cryptoslate.com\/author\/gino-matos\/","mainEntityOfPage":{"@id":"https:\/\/cryptoslate.com\/author\/gino-matos\/"},"image":{"@type":"ImageObject","@id":"https:\/\/cryptoslate.com\/author\/gino-matos\/#authorimage","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-300x300.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-300x300.jpg","caption":"Gino Matos"},"jobTitle":"Reporter","description":"Gino Matos is a seasoned crypto journalist and law graduate covering Brazil\u2019s blockchain ecosystem and DeFi developments.","worksFor":{"@id":"https:\/\/cryptoslate.com\/#organization"},"sameAs":["https:\/\/x.com\/pelicamatos","https:\/\/www.linkedin.com\/in\/ginomatos","https:\/\/muckrack.com\/gino-matos"]},"headline":"Bybit exploit tied to Safe developer machine vulnerability","datePublished":"2025-02-26T19:45:59+00:00","dateModified":"2025-12-13T00:59:55+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/"},"wordCount":756,"commentCount":0,"publisher":{"@id":"https:\/\/cryptoslate.com\/#organization"},"articleSection":["Crypto","Exchanges","Featured","Hacks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cryptoslate.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/","url":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/","name":"Bybit exploit tied to Safe developer machine vulnerability","isPartOf":{"@id":"https:\/\/cryptoslate.com\/#website"},"datePublished":"2025-02-26T19:45:59+00:00","dateModified":"2025-12-13T00:59:55+00:00","description":"Yu Xian, founder of SlowMist, said anyone using Safe\u2019s multi-signature services may be exploited in theory.","breadcrumb":{"@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cryptoslate.com\/bybit-exploit-tied-to-safe-developer-machine-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptoslate.com\/"},{"@type":"ListItem","position":2,"name":"Bybit exploit tied to Safe developer machine vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/cryptoslate.com\/#website","url":"https:\/\/cryptoslate.com\/","name":"CryptoSlate","description":"Cryptocurrency News and Real-time Coin Data","publisher":{"@id":"https:\/\/cryptoslate.com\/#organization"},"inLanguage":"en-US"},{"@type":"NewsMediaOrganization","@id":"https:\/\/cryptoslate.com\/#organization","name":"CryptoSlate","url":"https:\/\/cryptoslate.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2018\/05\/c-logo.jpg","width":1000,"height":1000,"caption":"CryptoSlate"},"image":{"@id":"https:\/\/cryptoslate.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/twitter.com\/cryptoslate","https:\/\/www.instagram.com\/cryptoslate","https:\/\/www.linkedin.com\/company\/cryptoslate","https:\/\/www.youtube.com\/c\/cryptoslate","https:\/\/cryptoslate.substack.com","https:\/\/t.me\/cryptoslatenews","https:\/\/www.crunchbase.com\/organization\/cryptoslate","https:\/\/iq.wiki\/wiki\/cryptoslate","https:\/\/news.google.com\/publications\/CAAqKggKIiRDQklTRlFnTWFoRUtEMk55ZVhCMGIzTnNZWFJsTG1OdmJTZ0FQAQ","https:\/\/muckrack.com\/media-outlet\/cryptoslate","https:\/\/www.tiktok.com\/@cryptoslatenews"],"publishingPrinciples":"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles","ownershipFundingInfo":"https:\/\/cryptoslate.com\/disclaimers\/how-cryptoslate-makes-and-spends-money\/","correctionsPolicy":"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback","ethicsPolicy":"https:\/\/cryptoslate.com\/editorial-policy\/#editorial-principles","foundingDate":"2017-08-04","founder":[{"@type":"Person","name":"Nate Whitehill"},{"@type":"Person","name":"Matthew Blancarte"}],"contactPoint":[{"@type":"ContactPoint","contactType":"customer support","url":"https:\/\/cryptoslate.com\/contact\/","availableLanguage":"en-US"},{"@type":"ContactPoint","contactType":"sales","url":"https:\/\/cryptoslate.com\/advertising\/","availableLanguage":"en-US"},{"@type":"ContactPoint","contactType":"newsroom","url":"https:\/\/cryptoslate.com\/editorial-policy\/#corrections-feedback","email":"tips@cryptoslate.com","availableLanguage":"en-US"}],"masthead":"https:\/\/cryptoslate.com\/about\/#masthead"},{"@type":"Person","@id":"https:\/\/cryptoslate.com\/#\/schema\/person\/f03754c9e579651795caf77a2b00c49c","name":"Gino Matos","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptoslate.com\/#\/schema\/person\/image\/","url":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-150x150.jpg","contentUrl":"https:\/\/cryptoslate.com\/wp-content\/uploads\/2025\/12\/profile-photo-gino-150x150.jpg","caption":"Gino Matos"},"description":"Gino Matos is a law school graduate and a seasoned journalist with six years of experience in the crypto industry. His expertise primarily focuses on the Brazilian blockchain ecosystem and developments in decentralized finance (DeFi).","url":"https:\/\/cryptoslate.com\/author\/gino-matos\/"}]}},"_links":{"self":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/467300"}],"collection":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/users\/1511"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/comments?post=467300"}],"version-history":[{"count":3,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/467300\/revisions"}],"predecessor-version":[{"id":467307,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/posts\/467300\/revisions\/467307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/media\/467345"}],"wp:attachment":[{"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/media?parent=467300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/categories?post=467300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/tags?post=467300"},{"taxonomy":"prediction_market_topic","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/prediction_market_topic?post=467300"},{"taxonomy":"post_folder","embeddable":true,"href":"https:\/\/cryptoslate.com\/wp-json\/wp\/v2\/post_folder?post=467300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}