According to PANews, the security team at SlowMist has reported that on February 21, Bybit's multisignature wallet was compromised, resulting in the theft of nearly $1.5 billion through a 'legitimate signature' transaction. The attackers employed social engineering tactics to gain multisignature access and used the delegatecall function of the Safe contract to insert malicious logic, bypassing the multisignature verification process to transfer the funds.
The Safe wallet introduced a Safe Guard mechanism in version 1.3.0, which allows for detailed security checks on transactions, such as whitelist verification and restrictions on high-risk operations. However, Bybit was using version 1.1.1, which did not include this critical feature. The SlowMist team suggested that if Bybit had upgraded to version 1.3.0 and properly configured the Guard mechanism, the loss might have been prevented.