The Bybit Hack And Its Fallout. Cold wallets that are hot. - 0 views
-
John Kiff on 07 Mar 25"I cannot figure out why the Safe cold wallet, even though it is a web based application connecting to the internet, qualifies as a cold wallet. Bybit used a Safe wallet. Safe is an Orwellian term, like Liberty, Patriot, Truth. The wallet UI was hosted on a AWS S3 bucket a database in the Amazon cloud. All the postmortems point to the hacking of this UI with stolen Safe S3 credentials, leaked many months ago. Cold wallets are not for timely transactions as it takes a while for such multisig wallets to bridge between a disconnected wallet and the internet. Cold wallets can be as simple as a piece of paper with your private key or hardware cold wallets. Of course the bridging point is where it is most vulnerable. Maybe Safe was used because for people on the move like the Bybit CEO and his two co-signers, a wallet such as Safe is convenient. Calling it cold is a stretch."