“What if someone forced you to unlock your hardware wallet?”
That’s where COLDCARD Trick PINs come in.
Different PINs.
Different outcomes.
We’re giving away a COLDCARD Q 👇
To enter:
• Like
• Repost
• Comment how COLDCARD would level up your Bitcoin security
The COLDCARD Q is built for Bitcoiners.
Clean QR signing, airgapped security, and a focus on simplicity.
We’re giving one away.
To enter:
• Like 👍
• Repost 🔁
• Comment why you want a Q 👇
¿Quieres mejorar la seguridad de tu bitcoin? Sorteamos nuestra hardware wallet favorita: COLDCARD Q
1) Retweetea este tweet
2) Sigue a @COLDCARDwallet
3) Comenta tu color favorito de COLDCARD para tener una oportunidad de ganar
El ganador será seleccionado el jueves 07 de mayo
📣 SORTEO GORRA ALPINE DEL GP DE AUSTIN 🇺🇸
REQUISITOS‼️
- Seguirnos en Twitter
- Darle LIKE y RT a este post.
- Comentar
IMPORTANTE: SI NOS SEGUIS EN INSTAGRAM Y COMENTAS LA CAPTURA TENES CHANCES DOBLES!
Anunciamos el ganador el día: 31/01
Mucha suerte 💪🏻🩷
@JJChagerben357 Maduro es un refugiado en EEUU, le debe 60 palos a los chinos, más a salvo que ahí no va a estar. Y EEUU se asegura de que no se le venda más petróleo barato a China. Compren y guarden como dice el inge, todo lo demás es decorado.
Theta World Tour's next stop is #TOKEN2049 Dubai! Theta will host an exclusive VIP dinner for key stakeholders & potential partners in the Theta ecosystem, focused on driving adoption of Theta blockchain and EdgeCloud platform. Apply to attend here:
https://t.co/LU5bvpn3b2
🚨 Inside the $1.5B @Bybit_Official Hack 🚨
The biggest crypto heist in history. Lazarus strikes again.
Not a smart contract flaw - attackers injected malicious JS into Safe{Wallet}'s AWS S3, corrupting the multisig signing UI. Signers blindly approved a malicious delegatecall that hijacked the proxy.
We’ve been following Bybit’s crisis comms, and their transparency stands out as a strong industry example. While they haven’t released a post-mortem yet, here’s what we know so far.
👇 Read on for key insights.
🔍 For the full investigation, head to our blog: https://t.co/sEgKiLLCai
1️⃣ How the Hack Happened
Hackers tricked Bybit’s multisig signers into approving a malicious proxy upgrade by masking it as a routine cold-to-hot wallet transfer.
• Step 1: Lazarus deployed a malicious Gnosis Proxy’s implementation contract.
• Step 2: The attacker created three Gnosis Proxy contracts for testing, including 0x19…cd141, which was later injected as the target contract in the malicious JS code (along with Bybit Cold wallet).
• Step 3: Safe’s codebase was modified with malicious code injected into resources served by Safe{Wallet}’s AWS S3 bucket.
• Step 4: 30 minutes after injecting the malicious code, the hackers executed a test transaction against 0x19…cd141, likely testing the exploit via Safe’s front-end.
• Step 5: 2 days later, malicious transaction appeared legitimate but rewrote the multisig’s logic, giving the attacker full control over Bybit’s cold wallet.
• Step 6: With control secured, Lazarus drained Bybit’s ETH holdings.
2️⃣ Laundering: 7.6K+ Wallets, Bridges & Mixers
Once they had control, Lazarus started a carefully structured laundering strategy to cover their tracks:
• Systematic transfers from EOAs to new wallets (~7,600 identified)
• ~20% of initial 50 EOAs’ funds already redistributed
• 2-3 tx per minute, pausing every 45 minutes
• Cross-chain transfers via DEXs, bridges & mixers
• ~$100M converted to BTC via Chainflip
This isn’t just funds moving fast—it’s strategic obfuscation, designed to make tracking and freezing assets nearly impossible (only 3% so far)
3️⃣ Could This Have Been Prevented?
Multi-Layered Security Model could have prevented the malicious upgrade
• Automated Monitoring – Detecting anomalies in multisig transactions before execution.
• Human Verification – AI-powered, human-readable alerts to all signers, ensuring transparency.
• Safe Lock – Ultimate safeguard to pause & block the malicious transaction.
#HackenExtractor combines these layers, ensuring instant response against threats like this.
4️⃣ The Lazarus Hack Bounty Program
Following the attack, Bybit launched the Lazarus Hack Bounty Program, offering a $140M bounty to track and freeze stolen funds.
• 10% of recovered funds will be distributed to those who assist in freezing and tracing the assets.
• Exchanges, mixers, and bridges are urged to cooperate in stopping further laundering.
• So far, only 3.03% have been frozen, while 90.23% remain under active tracking.
Want to get involved? Learn more: https://t.co/SUeiT7EixR
This exploit proves one thing: Multisig isn’t enough.
Without real-time oversight, human verification, and circuit breakers, even the most secure setups can be bypassed.