Skip to content

Commit f036667

Browse files
authored
Update software-supply-chain-attacks-crypto.md
1 parent dc01619 commit f036667

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

software-supply-chain-attacks-crypto.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -158,9 +158,9 @@ References:
158158
* <https://github.com/advisories/GHSA-66c6-q6m3-5pmx>
159159
* <https://security.snyk.io/vuln/SNYK-JS-WEB3PARSER-8660797>
160160

161-
### 18. Bybit attack 8/ Safe Javascript compromised Feb 2025
161+
### 18. Bybit attack / Safe Javascript compromised - Feb 2025
162162

163-
The AWS account of a Safe developer was compromise.r, the attacked uploaded m alicious Javascript targeting a single wallet. The multisig signers signed a compromised transaction involving an [exploit contract](https://etherscan.io/address/0xbdd077f651ebe7f7b3ce16fe5f2b025be2969516) called with DELEGATE_CALL. This resulted in a $1.5B (billion!) theft on the cold wallet of the Bybit crypto exchange.
163+
The AWS account of a Safe developer was first compromised, the attacked uploaded malicious Javascript targeting a single wallet. The multisig signers signed a compromised transaction involving an [exploit contract](https://etherscan.io/address/0xbdd077f651ebe7f7b3ce16fe5f2b025be2969516) called with DELEGATE_CALL. This resulted in a $1.5B (billion!) theft on the cold wallet of the Bybit crypto exchange.
164164

165165
Notes:
166166
- This hack exploits a multisig cold wallet **without exploiting any smart contract vulnerability**.

0 commit comments

Comments
 (0)