BTC $63,129.14 +0.13%
ETH $1,891.97 +0.52%
BNB $602.17 -0.77%
XRP $0.9990 -0.22%
SOL $75.05 -0.60%
TRX $0.3322 +0.36%
DOGE $0.0698 +0.31%
ADA $0.1757 -0.53%
BCH $204.26 +0.32%
LINK $9.47 -0.20%
HYPE $58.41 +2.26%
AAVE $86.32 +0.09%
SUI $0.6731 -0.44%
XLM $0.1568 +0.05%
ZEC $490.91 +0.87%
BTC $63,129.14 +0.13%
ETH $1,891.97 +0.52%
BNB $602.17 -0.77%
XRP $0.9990 -0.22%
SOL $75.05 -0.60%
TRX $0.3322 +0.36%
DOGE $0.0698 +0.31%
ADA $0.1757 -0.53%
BCH $204.26 +0.32%
LINK $9.47 -0.20%
HYPE $58.41 +2.26%
AAVE $86.32 +0.09%
SUI $0.6731 -0.44%
XLM $0.1568 +0.05%
ZEC $490.91 +0.87%

Security Community: Bybit attackers use "social engineering" techniques to mislead reviewers into mistaking contract changes for transfers

2025-02-22 12:46:10

ChainCatcher message, according to a post by the security community Dilation Effect on platform X: "Compared to previous similar incidents, in the Bybit incident, only one signer needed to be compromised to complete the attack, as the attacker used a 'social engineering' technique.

Analyzing on-chain transactions reveals that the attacker executed a malicious contract's transfer function through delegatecall. The transfer code modifies the value of slot 0 using the SSTORE instruction, thereby changing the implementation address of Bybit's cold wallet multi-signature contract to the attacker's address. The transfer here is very clever; it only requires dealing with the person/device initiating this multi-signature transaction, and the subsequent reviewers will significantly lower their guard when they see this transfer. Because a normal person seeing a transfer would think it's just a transfer, who would know it's actually changing the contract? The attacker's methods have evolved again."

app_icon
ChainCatcher Building the Web3 world with innovations.