|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Nachrichtenartikel zu Kryptowährungen
Bybit hack serves as a wake-up call for complacent crypto exchanges
May 01, 2025 at 11:17 pm

The Bybit hack, which saw cyber hackers walk away with the largest loss of funds from a cryptocurrency exchange in history, has served as a wake-up call for those who had grown complacent about the state of security threats in the digital assets space.
As we learn the lesson of this heist — that enterprise-grade custody solutions require tech to be accompanied by transparency — we must also recall how this incident unfolded.
Unlike many previous instances, this loss of funds was not due to a faulty smart contract, lost/mismanaged keys or deliberate mismanagement or rehypothecation of user funds, but rather a sophisticated social engineering attack that exploited vulnerabilities in operational security.
This hack differs from earlier eras because it befell a major global exchange that takes security and compliance seriously. It’s a reminder that, in crypto, there’s no such thing as “good enough” security.
The anatomy of a heist
A technical overview of the Bybit attack is key for understanding how companies can proactively strengthen their security against such incidents. Initially, a developer machine belonging to Safe, an asset management platform offering multisig Ethereum wallets used by Bybit, was compromised. This initial breach granted the attackers unauthorized access to Safe’s Amazon Web Services (AWS) environment, including its S3 storage bucket.
The attackers then pushed a malicious JavaScript file into this bucket, which was subsequently distributed to users via access to the Safe UI. The JS code manipulated the transaction content displayed to the user during the signing process, effectively tricking them into authorizing transfers to the attackers’ wallets while believing they were confirming legitimate transactions.
Recent: CertiK exec explains how to keep crypto safe after Bybit hack
This highlights how even highly robust security at the technical level, like multisig, can be vulnerable if not implemented correctly. They can lull users into a false sense of security that can be fatal.
Layered security
While multisignature security setups have long been considered the gold standard in digital asset security, the Bybit hack underscores the need for further analysis and transparency on the implementation of these systems, including the layers of security that exist to mitigate attacks that exploit operational security and the human layer in addition to verification of the smart contracts themselves.
A robust security framework for safeguarding digital assets should prioritize multi-layered verification and restrict the scope of potential interactions. Such a framework demonstrably enhances protection against attacks.
A well-designed system implements a thorough verification process for all transactions. For example, a triple-check verification system involves the mobile application verifying the server’s data, the server checking the mobile application’s data, and the hardware wallet verifying the server’s data. If any of these checks fail, the transaction will not be signed. This multi-layered approach contrasts with systems that directly interface with onchain contracts, potentially lacking critical server-side checks. These checks are essential for fault tolerance, especially if the user’s interface is compromised.
A secure framework should also limit the scope of possible interactions with digital asset vaults. Restricting actions to a minimal set, like sending, receiving and managing signers, reduces potential attack vectors associated with complex smart contract modifications.
Using a dedicated mobile application for sensitive operations, like transaction creation and display, adds another security layer. Mobile platforms often offer better resistance to compromise and spoofing compared to browser-based wallets or multisig interfaces. This reliance on a dedicated application enhances the overall security posture.
Transparency upgrades
To bolster transparency, businesses can leverage the capabilities of proof-of-reserve software. These can defend multisignature custody setups from UI-targeted attacks by providing an independent, self-auditable view of chain state/ownership and verifying that the correct set of keys is available to spend funds in a given address/contract (akin to a health check).
As institutional adoption of Bitcoin (BTC) and digital assets continues, custody providers must transparently communicate such details on the security models of their systems in addition to the design decisions behind them: This is the true “gold standard” of crypto security.
Transparency should extend to how the nature of the underlying protocols alters the attack surface of custody setups, including multisignature wallets. Bitcoin has prioritized human-verifiable transfers where signers confirm destination addresses directly rather than confirm engagement in complex smart contracts, which require additional steps/dependencies to reveal the flow of funds.
In the case of the Bybit hack, this would enable the human signer to detect more easily that the address shown by the hardware wallet did not match the spoofed UI.
While expressive smart contracts expand the application design space, they increase the attack surface and make formal security audits more challenging. Bitcoin’s well-established multisignature standards, including a native multisig opcode, create additional security barriers against such attacks. The Bitcoin protocol has historically favored simplicity in its design, which reduces the attack surface not just at the smart contracting layer but also at the UX/human layer, including hardware wallet users.
Increasing regulatory acceptance shows how far Bitcoin has come since its early era of widespread hacks and frauds, but Bybit
Haftungsausschluss:info@kdj.com
Die bereitgestellten Informationen stellen keine Handelsberatung dar. kdj.com übernimmt keine Verantwortung für Investitionen, die auf der Grundlage der in diesem Artikel bereitgestellten Informationen getätigt werden. Kryptowährungen sind sehr volatil und es wird dringend empfohlen, nach gründlicher Recherche mit Vorsicht zu investieren!
Wenn Sie glauben, dass der auf dieser Website verwendete Inhalt Ihr Urheberrecht verletzt, kontaktieren Sie uns bitte umgehend (info@kdj.com) und wir werden ihn umgehend löschen.
-
- Ausschuss des Repräsentantenhauses bringt 20-jähriges Bitcoin-Reservegesetz voran: Ein Blick in die Zukunft digitaler Vermögenswerte Amerikas
- Sep 21, 2026 at 12:05 pm
- Ein Ausschuss des US-Repräsentantenhauses hat beschlossen, eine 20-jährige Bitcoin-Reserve und einen größeren Vorrat an digitalen Vermögenswerten einzurichten, was einen langfristigen Wandel in der Kryptopolitik des Bundes signalisiert.
-
- Das US-Finanzministerium verurteilt die iranische Börse BitBank mit Sanktionen wegen angeblicher Bitcoin-Transfers der IRGC
- Sep 21, 2026 at 04:05 am
- Das US-Finanzministerium hat die iranische Krypto-Börse BitBank sanktioniert und behauptet, sie sei an der Weiterleitung von Bitcoin an die IRGC beteiligt gewesen. Diese Maßnahme zieht die Schlinge um die digitale Asset-Infrastruktur Irans enger.
-
- Krypto-Kreuzung: Beste Krypto zum Kauf inmitten der SEC-Regulierung und dem Aufstieg von Pepeto
- Sep 21, 2026 at 04:05 am
- Inmitten der sich weiterentwickelnden SEC-Vorschriften erweist sich ein neuer Player, Pepeto, als potenziell „beste Kryptowährung zum Kaufen“, der innovative Tools und Frühbuchermöglichkeiten bietet und im Gegensatz zu etablierten Giganten und schwindenden Meme-Coins steht.
-
- Bitcoin-Preis: Der spektakuläre Aufschwung und sein Scheideweg
- Sep 21, 2026 at 03:55 am
- Bitcoin erlebte einen spektakulären Aufschwung und stieg auf über 80.000 US-Dollar, stößt jedoch aufgrund geopolitischer Gegenwinde und eines sich abkühlenden technischen Signals auf einen kritischen Widerstand bei 82.000 US-Dollar. Kann es sich behaupten?
-
- Ein Angreifer, mehrere Token: Einblick in die Fetch.ai-Sicherheitslücke – Eine New Yorker Minute
- Sep 20, 2026 at 08:05 pm
- Der Verstoß gegen Fetch.ai, bei dem es sich zunächst um einen FET-Token-Diebstahl im Wert von 1,5 Millionen US-Dollar handelte, hat sich zu einer Multi-Token-Saga mit NTX, AGIX und WMTX ausgeweitet, wobei die Gesamtbestände der Angreifer mittlerweile 17 Millionen US-Dollar übersteigen. Dieser Vorfall verdeutlicht den entscheidenden Unterschied zwischen gestohlenen und neu geprägten Token und offenbart tiefere Auswirkungen auf die Sicherheit, die über die anfänglichen finanziellen Verluste hinausgehen.
-
- MultiversX stoppt Mainnet: Aufklärung des Vorfalls „Invalid State“.
- Sep 20, 2026 at 08:05 pm
- MultiversX hat kürzlich sein Mainnet angehalten, weil ein Angreifer einen Atomizitätsfehler ausnutzte, der zu einem „ungültigen Zustand“ führte und einen komplexen Wiederherstellungsaufwand auslöste, um die Netzwerkintegrität und das Vertrauen der Benutzer sicherzustellen.
-
- Bitcoin, Altcoins und Kryptowährung: Ein Marktschub, der durch Regulierung und Innovation angetrieben wird, nicht nur durch Memes
- Sep 20, 2026 at 08:05 pm
- Der unerwartete Sprung von Bitcoin über 80.000 US-Dollar löste eine breitere Krypto-Rallye aus, die durch kluge Regulierungsmaßnahmen und eine deutliche Verlagerung hin zu Altcoins mit echten Nutzen- und Einnahmequellen angeheizt wurde. Dies ist nicht mehr der Kryptomarkt Ihrer Oma.
-
- Dash-Preisvorhersage: Wird die DASH-Kryptowährung bald 100 US-Dollar erreichen?
- Sep 20, 2026 at 08:05 pm
- Dash (DASH) zeigt eine bullische technische Struktur und legte diese Woche um 10 % zu. Da wichtige Widerstandsniveaus in Sicht sind, erscheint ein Weg bis zur 100-Dollar-Marke plausibel, gestützt durch starke Fundamentaldaten.
-
- Experten äußern sich: Die zukünftige Rolle von XRP als Infrastruktur für digitale Währungen und potenzielle Preisanstiege
- Sep 20, 2026 at 08:05 pm
- Jüngste Analysen und Diskussionen unter Krypto-Experten unterstreichen das Potenzial von XRP als grundlegende digitale Währungsinfrastruktur und spekulieren über erhebliche Preiserhöhungen, was eine Debatte unter XRP-Inhabern auslöst.

































