PANews reported on February 27 that according to the analysis of the SlowMist team, the Safe developer's device was hacked, resulting in malicious code being implanted in the front end. This code can intercept and modify transaction parameters, thereby hijacking user assets.
After verification, the JS file on the front end of Safe did contain malicious code, and hackers used the vulnerability to steal $1.5 billion in assets from Bybit. SlowMist pointed out that the malicious contract address used by the attacker was 0xbdd077f651ebe7f7b3ce16fe5f2b025be2969516.
