{"id":376780,"date":"2025-02-28T20:57:36","date_gmt":"2025-02-28T15:27:36","guid":{"rendered":"https:\/\/dripp.zone\/news\/solana-multisig-provider-conducting-comprehensive-review-after-safe-exploit-crypto-news\/"},"modified":"2025-02-28T21:01:13","modified_gmt":"2025-02-28T15:31:13","slug":"solana-multisig-provider-conducting-comprehensive-review-after-safe-exploit-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/solana-multisig-provider-conducting-comprehensive-review-after-safe-exploit-crypto-news\/","title":{"rendered":"Solana multisig provider conducting \u2018comprehensive review\u2019 after Safe exploit &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div>\n<p><em>This is a segment from the Lightspeed newsletter. To read full editions, <\/em><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/lightspeed\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><em>subscribe<\/em><\/a><em>.<\/em><\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p>Yesterday, Bybit CEO Ben Zhou posted on X that the platform\u2019s $1.4 billion hack had been caused by \u201cmalicious code originating from Safe{Wallet}\u2019s infrastructure.\u201d Solana CEOs had many words, including \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/0xMert_\/status\/1894778195120894054\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">nightmare<\/a> season,\u201d \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/Austin_Federa\/status\/1894773418010034411\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">holy<\/a> hell,\u201d and \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/buffalu__\/status\/1894771203480400020\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">holy<\/a> shit.\u201d<\/p>\n<p>Preliminary reports indicate Safe\u2019s frontend was exploited to trick Bybit into signing a malicious transaction, and Safe\u2019s actual smart contracts appeared to perform as intended. Still, the foul language likely stemmed from the fact that wallets being exploitable gives hackers access to a whole lot of assets \u2014 Safe\u2019s smart accounts <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/news\/bybit-hack-raises-security-questions\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">secure over $100 billion<\/a> in digital assets.\u00a0<\/p>\n<p>In other words, hackers could go further than Bybit.<\/p>\n<p>Squads, a multisig wallet used by a number of prominent Solana teams including Helium, Kamino, Pyth, Helius, Drift, Jupiter and Ellipsis, is \u201cconducting a comprehensive review of our infrastructure to mitigate the possibility of such an attack,\u201d CEO Stepan Simkin told me.\u00a0<\/p>\n<p>Simkin emphasized that \u201chigh value accounts\u201d need purpose-built wallet solutions because sophisticated hackers can \u201cpotentially compromise any frontend.\u201d<\/p>\n<p>The Bybit hackers \u2014 whom the FBI has now <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/fbi-says-north-korea-was-responsible-15-billion-bybit-hack-2025-02-27\/\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">accused<\/a> of being linked to North Korea \u2014 injected malicious code into Safe\u2019s JavaScript files to alter Bybit\u2019s multisig transactions and send the funds to the attacker\u2019s address, according to a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/slowmist.medium.com\/bybits-1-5-billion-theft-unveiled-safe-wallet-front-end-code-tampered-84b78f0fa9c2\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">report<\/a> from blockchain security firm Slowmist. While the crypto industry puts a lot of effort into auditing smart contracts, it focuses less than it should on \u201cconventional infrastructure\u201d \u2014 like leaked Amazon Web Services credentials, which was the culprit in this case, Simkin said.\u00a0<\/p>\n<p>\u201cJavaScript side hacks are the easiest to execute due to lack of audits,\u201d Cube Exchange CEO Bartosz Lipinski said. \u201cSolana is not immune to that.\u201d<\/p>\n<p>Lipinski said Cube chose multi-party computation over multi-signature for wallet security in part because it prevents \u201cblind signing \u201c \u2014 which Bybit <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/prasincs\/status\/1893486874091532432\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">apparently<\/a> did.<\/p>\n<p>Simkin said Squads is working on a \u201cdecentralized frontend\u201d that would allow users to interact with the protocol without having to rely much on its infrastructure.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p><strong>Get the news in your inbox. Explore Blockworks newsletters:<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/daily\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><strong>Blockworks Daily<\/strong><\/a>: The newsletter that helps thousands of investors understand crypto and the markets, by Byron Gilliam.<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/empire\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><strong>Empire<\/strong><\/a>: Start your day with top crypto insights from David Canellis and Katherine Ross.<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/onthemargin\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><strong>Forward Guidance<\/strong><\/a>: Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin.<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/research\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\">0xResearch<\/a><\/strong>: Get alpha directly in your inbox<strong> <\/strong>\u2014 market highlights, charts, degen trade ideas, governance updates, and more.<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/lightspeed\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><strong>Lightspeed<\/strong><\/a>: All things Solana, in your inbox, every day from Jack Kubinec and Jeff Albus.<\/li>\n<li><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blockworks.co\/newsletter\/thedrop\" rel=\"nofollow\" target=\"_blank\" node=\"[object Object]\"><strong>The Drop<\/strong><\/a>: The newsletter for crypto collectors and traders, covering games, tokens, apps, memes and more.<\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>This is a segment from the Lightspeed newsletter. To read full editions, subscribe. Yesterday, Bybit CEO Ben Zhou posted on X that the platform\u2019s $1.4 billion hack had been caused by \u201cmalicious code originating from Safe{Wallet}\u2019s infrastructure.\u201d Solana CEOs had many words, including \u201cnightmare season,\u201d \u201choly hell,\u201d and \u201choly shit.\u201d Preliminary reports indicate Safe\u2019s frontend [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":376784,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-376780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/376780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=376780"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/376780\/revisions"}],"predecessor-version":[{"id":376786,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/376780\/revisions\/376786"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/376784"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=376780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=376780"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=376780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}