Why crypto ‘audited’ badges are giving investors a dangerous false sense of security

At 1:30 p.m. UTC on Feb. 21, 2025, Bybit began moving funds from an Ethereum cold wallet to a warm wallet, the sort of routine transfer designed to make custody look boring. Authorized signers reviewed the destination on their screens and approved it, unaware that their screens were actually lying.
Bybit later said the signing interface had been manipulated so that the signers saw the address they expected while the transaction underneath gave an attacker control of the wallet. The exchange's account of the incident put the loss at $1.46 billion, and the FBI attributed the theft to North Korea.
CryptoSlate reported at the time that the attackers took roughly 401,347 ETH along with several staked Ethereum assets.
Safe said a compromised developer machine enabled a disguised malicious transaction and that external researchers found no vulnerability in Safe's smart contracts or the source code for its front end and services. The private keys didn't need to leave their devices because valid signatures were enough once the humans producing them had been shown a false description of what they were authorizing, the same separation between key security and transaction intent that CryptoSlate examined earlier this year.
… Continue reading the full article at the original source below.



