On hindsight and risk assessment

2025-02-28 Privy

https://privy.io/blog/bybit-lookback

Thumbnail for On hindsight and risk assessment

Privy's analysis reviews the Bybit incident as a web3 risk-assessment case centered on a cold-wallet transfer using a SAFE multisig wallet. The excerpt states that attackers compromised SAFE developer access, presented signers with what appeared to be a valid fund-movement transaction, and caused the actual transaction to upgrade the SAFE contract to attacker control through a delegate call. The article emphasizes single points of failure, broad signer privilege, reliance on user-level bytecode validation, and developer access to production S3 assets as risk areas. Recommended mitigations include splitting cold wallets, using intermediary wallets with destination and amount limits, diversifying SAFE and hardware/software interfaces, enforcing least privilege, protecting CI/CD and S3 deployment paths, and using EDR for visibility into process, file, and network activity.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://code.cash.app/encryptio… 2025-02-28 2025-02-28
URL https://clientdiversity.org/#why 2025-02-28 2025-02-28
URL https://safehashpreview.com 2025-02-28 2025-02-28
DOMAIN safeutils.openzeppelin.com 2025-02-28 2025-02-28
DOMAIN safehashpreview.com 2025-02-28 2025-02-28
DOMAIN clientdiversity.org 2025-02-28 2025-02-28

Related Reports

« Back