{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:18:52.937Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI","date":"2025-02-21","date_precision":"day","victim_org":"Bybit","sector":"Cryptocurrency","country":"United Arab Emirates","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":1500000000,"loss_note":"Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.","records_affected":null,"threat_actor":"Lazarus Group / TraderTraitor (DPRK)","summary":"On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.","how_it_worked":"The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.","lessons":"Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.","confidence":"Confirmed","sources":[{"title":"Lazarus hacked Bybit via breached Safe{Wallet} developer machine","url":"https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/","publisher":"BleepingComputer"},{"title":"In-Depth Technical Analysis of the Bybit Hack","url":"https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/","publisher":"NCC Group"},{"title":"Sygnia's Investigation into the Bybit Hack: What We Know So Far","url":"https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/","publisher":"Sygnia"},{"title":"Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack","url":"https://www.coindesk.com/business/2025/02/26/bybit-and-safe-custody-blame-each-other-over-usd1-5b-hack","publisher":"CoinDesk"},{"title":"How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist","url":"https://www.securityweek.com/how-social-engineering-sparked-a-billion-dollar-supply-chain-cryptocurrency-heist/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa","year":2025,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-bybit-s-1-5b-loss-signers-approved-a-masked-transaction-on-a-poisoned-sa"}]}