How important is Safe, the top infrastructure in the cryptocurrency space, to the North Korean hacker attacks?
Author: BlockBeats
The next hacker-themed movie may be based on the recent $1.5 billion hack incident involving Bybit and Safe. The hacker's methods are considered perfect, and no traces have been found so far.
After a week of extensive investigation, the Safe team, Bybit, and security companies have provided the latest updates. Rhythm Blockbeats summarizes the investigation results in the simplest terms, revealing the first-hand situation of the incident:
Code is fine: The front-end code of Safe is open-source, and there are no issues at the code level; it was the security of Safe's server that was attacked.
There is an "insider": Specifically, the code that was actually deployed in the production environment does not match what is shown in the open-source repository. This means that at some point, someone replaced the code or inserted malicious code during the deployment process.
Insider's identity unknown: Not all developers have the permission to deploy production environment code. Those who can perform such deep operations must have a high level of trust. This "insider" could be a long-trusted developer or a team member who has gained sufficient permissions. The attacker hid their tracks for a long time, and Safe has checked historical transactions but found no anomalies or traces of the "insider," calling on the community and users to assist in the investigation.
In addition, Safe has not mentioned any plans to assist with compensation, only discussing some follow-up upgrade plans, while reminding everyone to remain rational and not to believe those marketing their so-called "advanced multi-signature," "semi-custodial," "MPC," and other products in light of this hacking incident, as these products may actually expand the attack surface.
In fact, this is not the first theft incident involving Safe's multi-signature. The method used this time is very similar to the Radiant Capital hack incident in October last year. In that incident, the hacker also infected the devices of core developers, implanting malware that caused the developers to mistakenly believe they were performing legitimate operations while actually executing malicious transactions in the background.
Safe Can Influence a Large Portion of the Crypto Space
Why is this incident attracting so much attention? The reason is that Safe is the most popular multi-signature wallet in the Ethereum ecosystem.
When Safe launched its token last year, the top 100 airdrop addresses were almost entirely composed of project parties, institutions, and large holders. This means that the security of Safe can influence a large portion of the crypto space.
As shown in the image, well-known names include Metamask, PleasrDao, AAVE, 1inch, Lido, and so on.
At the same time, in this cycle, traditional finance, traditional institutions, family funds, and old money have accelerated their entry into the market. However, due to the high barriers to entry in crypto, many have chosen relatively safer methods to protect their funds, such as multi-signature wallets like Safe.
For example, the most representative case is Trump's DeFi team.
According to Safe guardians who spoke to Rhythm BlockBeats, the simplest ways to determine whether an on-chain address is a Safe wallet address are: first, it shows "MultiSig" on ARKHAM; second, the address on the debank page will directly display "MultiSig:Safe" below it. As seen in the image, Trump's DeFi project World Liberty Fi indeed uses a multi-signature wallet.
This means that any security vulnerability in Safe could trigger a massive chain reaction and butterfly effect.
Even Top Security Infrastructure in Crypto Can Have Issues
The Safe project is essentially a top-tier project in the Ethereum ecosystem, incubated by the Gnosis team.
Gnosis Chain, which gained prominence in the last cycle, focuses on building efficient and secure decentralized applications. According to DefiLlama data, as of the writing of this article, Gnosis Chain's total value locked (TVL) is $200 million, with a peak of $350 million.
In fact, the story of the Gnosis ecosystem and incubator can be traced back to 2015.
Compared to the now well-known Polymarket, Gnosis co-founder Martin Koeppelmann began researching decentralized prediction markets much earlier. In 2015, he published his thoughts on the combination of MarketMaker and OrderBook on his forum, which was one of the earliest concepts for decentralized prediction markets in the industry.
Martin Koeppelmann was also one of the earliest Ethereum developers, having joined before the DAO period. Living in Berlin, he had close interactions with Vitalik, who was also in the Berlin office at that time.
Over the years, he has participated in many discussions within the Ethereum development community and frequently discussed issues related to L2, ZK, and the Ethereum roadmap with Vitalik. From Martin's comments on social media, one can see his level of integration into the community.
Based on this technological accumulation, Gnosis has gradually developed a complete ecosystem. From Gnosis Protocol evolving into CowSwap, Martin and his team further derived products like Gnosis Chain, Safe, and Gnosis Pay.
Has the Signal for a Bear Market Been Triggered?
The extensive impact of this Safe security incident has indeed caused a lot of panic and pessimism in the crypto space. According to Alternative.me data, today's cryptocurrency fear index has dropped to 10, the lowest since July 2022, with the market remaining in a state of extreme fear.
This has led many community members to question whether multi-signature is just a "cover-up" decoration?
At the same time, many industry practitioners have expressed reflections and concerns about the industry: "If multi-signature wallets are not safe, then who will take this industry seriously and trust it? Has the crypto industry really become a hacker's blood bag?"
Looking back at history, the end of each crypto bull market is often accompanied by significant security and trust crises.
For example, the early Mt. Gox incident led to a large amount of crypto assets being stolen, becoming one of the most famous hacking incidents in the history of the crypto industry; the end of the last bull market began with the trust crisis triggered by the collapse of FTX and the Terra crash, severely impacting investor confidence across the industry.
So, what will cause this bull market to end? Pessimistically speaking, the Safe security incident could very well be one of the "signals" marking the end of this bull market.