@nicrypto S3 and CloudFront are services offered by AWS. S3 is storage, and CloudFront is CDN(content distribution network). CloudFront is just one service from AWS' offerings, the phrase "(AWS or Cloudfront)" doesn't really make sense. Just FYI.
Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold wallet we signed and transfered all ETH in the cold wallet to this unidentified address. Please rest assured that all other cold wallets are secure.
All withdraws are NORMAL.
I will keep you guys posted as more develops, If any team can help us to track the stolen fund will be appreciated.
https://t.co/ckwZgma8Lf
Now that we know who's behind the @Bybit_Official attack. Let's look at how the hack actually worked.
At a high level, the hack involved the 4 broad group of events:
1. Attacker deployed a trojan contract and a backdoor contract.
2. Attacker tricked signers of the upgradeable multisig "cold" wallet to authorize a malicious ERC-20 transfer to a trojan contract
3. Instead of transferring tokens, trojan contract replaces the master copy of the actual Safe multisig implementation contract with the backdoor contract, which is solely controlled by the attacker.
4. The attacker called sweepETH and sweepERC20 to drain the wallet of all its native ETH, mETH, stETH, and cmETH tokens.
I had the opportunity to work on one of my favorite video game franchises this year and I’m excited to finally share this with you! The official debut trailer for the new @assassinscreed will drop worldwide tomorrow, don’t miss it! @Ubisoft#AssassinsCreed
Thank you for watching