# Safe{Wallet} statement on targeted attack on Bybit Source: https://x.com/safe/status/1894768522720350673?s=09&t=qPfzflWYA23hZ7nD9d1v5A Tl;dr: Forensic findings confirm targeted attack on ByBit by Lazarus Safe smart contracts unaffected, an attack was conducted by compromising a Safe {Wallet} developer machine which affected an account operated by Bybit Safe{Wallet} has added security measures to eliminate the attack vector. Full Statement: The forensic review into the targeted attack by the Lazarus Group on Bybit concluded that this attack targeted to the Bybit Safe was achieved through a compromised machine of a Safe{Wallet} developer resulting in the proposal of a disguised malicious transaction. Lazarus is a state-sponsored North Korean hacker group that is well known for sophisticated social engineering attacks on developer credentials, sometimes combined with zero-day exploits. Important! The forensic review of external security researchers did NOT indicate any vulnerabilities in the Safe smart contracts or source code of the frontend and services. Following the recent incident, the Safe{Wallet} team conducted a thorough investigation and have now restored Safe{Wallet} on Ethereum mainnet with a phased rollout. The Safe{Wallet} team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated. Pending the final results of the investigation, the Safe{Wallet} team will publish a full post-mortem. The Safe{Wallet} frontend remains operational with additional security measures in place. However, users need to exercise extreme caution and remain vigilant when signing transactions. Safe commits to lead an industry-wide initiative to increase verifiability of transactions, which is an ecosystem-wide challenge. Safe remains committed to security, transparency, self-custody, and pushing the industry forward. ## Comments **macbudkowski.eth**: Here's an interesting point from Hasu: https://xcancel.com/hasufl/status/1894779698699465124?t=kUXkVePEW24Qz0jblkt--A&s=19 **tomw1808.eth**: This is the only right answer, its zero fault for safe (albeit also not positive), is really just ByBit to blame here. Were they drunk or what where they even thinking? Why send 1.4B in one go anyways - how reckless and unresponsible can you be?! I mean, just look at the god damn display before hitting confirm, or simulate it first. And don't send a billion dollars in a single tx. **macbudkowski.eth**: @tomw1808.eth I wouldn't go as far as to say that Safe had zero fault, but agree that if ByBit had followed the best security practices, it wouldn't have happened. I think the problem with display was that they used Ledger Nano S, and from what I learned by following a conversation on X, it just doesn't show all the data. But I imagine that the wallet they used - like MetaMask or whatever - does the simulation. BTW have they even sent a $1 test tx? I don't do it most of the time, but if I were to send so much money I'd do it for sure. **macbudkowski.eth**: BTW, seems like OpenZeppelin just launched some solution for verifying these transactions: https://x.com/OpenZeppelin/status/1894870509608935791 **naomiii.eth**: Cassie (who used to be at Coinbase and hence has some idea of how to create CEX wallets) also wrote a quite comprehensive article on it on X. TLDR no one is completely not guilty in this - although clearly, Lazarus is the most guilty :'D https://news.kiwistand.com/stories/Bybit-Gnosis-and-Cold-Storage?index=0x67c084f97c4a34535ff54d8ef6e923ea896b432f697201d95f68a22d671c8bd8acbe7c8d