KOSUNI CRYPTO
Korea's Crypto Pulse, in English
$BTC $ETH $XRP $SOL $DOGE
News
Neutral

Bybit Hack Highlights Shift from Code Vulnerabilities to User Interface Attacks

Published September 18, 2026 3:46 PM · 0 views $BTC
Bybit Hack Highlights Shift from Code Vulnerabilities to User Interface Attacks

Security analysis shows virtual asset attack vectors are shifting from code vulnerabilities to web interfaces and user signing processes. The 2025 Bybit hack, where approximately $1.5 billion in digital assets were stolen on February 21, serves as a case study illustrating risks connected to developer accounts, supply chains, trading screens, and signature procedures.

Wang Yiseok, founder of Onkey, stated in an interview published at 00:38 KST on March 18 that 'security battles have entered the AI era.' The interview explained AI has shortened time needed for vulnerability exploration and attack setup. U.S. Federal Bureau of Investigation (FBI) identified North Korean-linked group 'TraderTraitor' as the perpetrator, though this does not constitute a court ruling.

Bybit revealed attackers stole Safe developers' authentication information to access Safe infrastructure and tricked signers into approving malicious transactions. Bybit also stated no evidence was found of compromised infrastructure. Wang emphasized attacks targeting Safe frontend and users are more critical than multi-signature contracts, cold wallets, or hardware devices themselves.

Multi-signature transactions require multiple approvals, but if the screen shown to signers differs from the actual transaction target, malicious transactions can be approved even within normal security procedures. Ledger also analyzed the Bybit attack, noting Safe web interfaces were altered and transactions approving modified contract addresses were signed.

Wang claimed Onkey's security team replicated supply chain attacks in two weeks with one engineer, compared to previous efforts requiring 2-3 skilled researchers for about two months. However, this claim was made during his interview without supporting technical reports or public verification. The original text mentioned the research was presented at Black Hat, but no specific presentation details were provided on Black Hat's official schedule.

Ledger Security Bulletin 023 addressed a command injection vulnerability where displayed transaction content differed from actual targets in Ethereum app versions 1.22.2 and Secure SDK 26.6.1, while Bulletin 025 fixed swap verification issues in Ethereum app 1.22.3. Ledger stated no evidence shows this vulnerability was exploited against real users. The Bybit hack and outdated app vulnerabilities are separate incidents, so the hack should not be interpreted as compromising Ledger devices themselves.

Safe later introduced Safe Shield, offering readable transaction explanations, pre-execution checks, and a trusted list feature to flag untrusted wallets and detect address similarities. This case demonstrates virtual asset wallet security cannot be fully achieved by just securing keys and contracts; web interfaces, developer accounts, software supply chains, and user verification processes must all be managed together.

Korean Source

This article is an English localization of a Korean-language crypto news report. Original headline: 바이비트 해킹, 코드보다 사람·화면 노렸다