The $1.5B Bybit Hack Explained: A Technical Breakdown

2025-02-22 Blockaid

https://blockaid.io/blog/the-15b-bybit-hack-explained-a-technical-breakdown

Thumbnail for The $1.5B Bybit Hack Explained: A Technical Breakdown

Attackers drained approximately $1.5 billion from Bybit after a signed Safe multisig transaction used `delegatecall` to overwrite the wallet proxy's `masterCopy` storage slot. The change redirected the proxy from the legitimate Gnosis Safe implementation to malicious code without altering the wallet's visible address. The attackers then invoked functions that swept the wallet's ETH and ERC-20 holdings, highlighting the need to simulate transactions and monitor critical storage and proxy implementation changes.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0x96221423681A6d52E184D440a8eFC… 2025-02-22 2025-02-22
WALLET 0xbdd077f651ebe7f7b3ce16fe5f2b0… 2025-02-22 2025-02-22

Related Reports

« Back