mimile
Back to feed

Bybit's $1.46 billion exploit shows 'audited' audits fail against interface deception

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Bybit's $1.46 billion exploit shows 'audited' audits fail against interface deception

A $1.46 billion exploit at Bybit in February 2025 exposed the limits of smart-contract audits, showing that code-level reviews cannot prevent losses when signing interfaces are manipulated. The FBI attributed the theft to North Korea, and the exchange said signers were tricked by a compromised transaction display.

The Bybit Exploit

On February 21, 2025, Bybit lost $1.46 billion when attackers manipulated the signing interface during a routine Ethereum transfer. Authorized signers approved the transaction, unaware that the displayed addresses were falsified. The FBI attributed the theft to North Korea, and the exchange confirmed 401,347 ETH and staked assets were taken. Safe, the wallet provider, found no vulnerability in its smart contracts—the attack exploited the gap between code security and human trust.

Audit Scope Illusion

A typical smart-contract audit inspects a specific snapshot of code, often for only days, and does not evaluate front-end interfaces, key management, or signing procedures. Yet projects market the "audited" badge as proof of full security. OpenZeppelin, for example, identifies precise commit hashes and review periods, but users rarely see these limits. The Bybit incident shows that even audited systems fail when signers act on deceptive information.

What's Next

Audit firms are increasingly adding scope disclaimers, but no industry-wide standard forces protocols to communicate what was not checked. Whether investors will adjust their perception of the "audited" label remains an open question.

1 source

Bybit's $1.46 billion exploit shows 'audited' audits fail against interface deception