
{"id":209540,"date":"2026-08-06T07:40:05","date_gmt":"2026-08-06T07:40:05","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=209540"},"modified":"2026-08-06T07:40:05","modified_gmt":"2026-08-06T07:40:05","slug":"why-a-perfect-hash-still-cost-bybit-1-5-billion","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=209540","title":{"rendered":"Why a Perfect Hash Still Cost Bybit $1.5 Billion"},"content":{"rendered":"<p>Most Safe signers treat the hash on their hardware wallet as the final check. <strong><em>It\u00a0isn\u2019t.<\/em><\/strong><\/p>\n<p>That single misunderstanding is how $1.5 billion left Bybit in February 2025 and it\u2019s still how most multisig transactions get approved\u00a0today.<\/p>\n<h3>The gap almost nobody talks\u00a0about<\/h3>\n<p>Your Ledger or Trezor shows you a hash before every signature.<br \/>That hash only answers one question: \u201cHas this transaction been altered since it was created?\u201d<\/p>\n<p>It does not answer the more important question:<br \/><strong><em>What does this transaction actually\u00a0do?<\/em><\/strong><\/p>\n<p>Those are two completely different checks.<br \/>Most people only perform the first\u00a0one.<\/p>\n<h3>What actually happened at\u00a0Bybit<\/h3>\n<p>The transaction that drained Bybit looked routine.<br \/>Signers saw a clean hash.<br \/>Their hardware wallets confirmed it\u00a0matched.<\/p>\n<p>What the hash did not reveal was that the transaction contained a delegatecall that rewrote the Safe\u2019s own implementation.<br \/>Once enough signatures were collected, control was gone and the funds followed.<\/p>\n<p>The hash was correct.<br \/>The intention was\u00a0not.<\/p>\n<p>This is the exact failure mode that keeps repeating across large multisigs.<\/p>\n<h3>How a Safe transaction hash is actually\u00a0built<\/h3>\n<p>A Safe transaction hash is not a simple fingerprint of <em>the whole thing<\/em>. It is the combination of two separate\u00a0hashes:<\/p>\n<p><strong>Domain hash<\/strong>\u200a\u2014\u200awhich Safe and which\u00a0chain<strong>Message hash<\/strong>\u200a\u2014\u200athe destination, the value, and the exact\u00a0calldata<\/p>\n<p>Your hardware wallet only shows you the final combined result.<br \/>If either half is wrong, the hash changes. That is why it works as an integrity check.<\/p>\n<p>But if the transaction is malicious by design, the hash will still be correct.<br \/>Integrity and safety are not the same\u00a0thing.<\/p>\n<h3>What proper verification looks\u00a0like<\/h3>\n<p>Before any signature, the transaction should be independently decoded.<\/p>\n<p>You need to\u00a0see:<\/p>\n<p>The exact destination contractThe native value being\u00a0sentThe decoded function call (or the selector if full decoding\u00a0fails)How many confirmations already\u00a0existWhether your signature will be the final one that executes the transaction<\/p>\n<p>Here is a real pending transaction examined during\u00a0testing:<\/p>\n<p><strong>Nonce 10<\/strong><br \/>Already collected 1 of 2 required signatures<br \/>Destination: a specific contract<br \/>Value: 0<br \/>Call: renounceOwnership<\/p>\n<p>In plain language, this transaction permanently removes ownership of that contract.<br \/>There is no undo. There is no recovery\u00a0path.<\/p>\n<p>The hash verified\u00a0cleanly.<\/p>\n<p>The risk was still flagged as Medium because the full arguments could not be decoded and required manual\u00a0review.<\/p>\n<p>A matching hash and an unclear call are two separate signals.<br \/>Either one is a valid reason to\u00a0stop.<\/p>\n<h3>The questions that actually\u00a0matter<\/h3>\n<p>Before you sign, these are the only questions worth\u00a0asking:<\/p>\n<p>What does this call actually\u00a0do?Am I the final signature required?Is this action permanent or reversible?Is the target contract the one I believe it\u00a0is?<\/p>\n<p>If any of those answers are unclear, the correct action is to\u00a0stop.<\/p>\n<h3>Why this has to become\u00a0routine<\/h3>\n<p>Most people only slow down for large or unusual transactions.<br \/>That is the wrong approach.<\/p>\n<p>The process should be identical whether the transaction moves ten dollars or ten million.<br \/>The day the check saves you is almost never the day you expected it\u00a0to.<\/p>\n<p>Especially dangerous are transactions that already have one confirmation out of two.<br \/>In that state, your signature does not just add to a pending list, it executes the transaction.<\/p>\n<p>That is the moment the verification actually\u00a0counts.<\/p>\n<h3>The quiet pattern behind most multisig\u00a0losses<\/h3>\n<p>Looking across major incidents, a consistent pattern\u00a0appears:<\/p>\n<p>The hash was\u00a0correctThe hardware wallet showed no\u00a0warningThe decoded intention was never independently checkedOne or more signers assumed \u201chash matches = safe to\u00a0sign\u201d<\/p>\n<p>That assumption is still widespread.<br \/>It is also still expensive.<\/p>\n<h3>Final note<\/h3>\n<p>A matching hash is necessary.<br \/>It is not sufficient.<\/p>\n<p>The difference between those two statements is the difference between a normal day and a permanent loss.<\/p>\n<p>Treat every signature as if it could be the final one, because one day it will\u00a0be.<\/p>\n<p><strong><em>Full breakdown with the exact verification steps here: <\/em><\/strong><a href=\"https:\/\/www.quillaudits.com\/blog\/web3-security\/how-to-verify-safe-transaction-before-signing\">how-to-verify-safe-transaction-before-signing<\/a><\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/why-a-perfect-hash-still-cost-bybit-1-5-billion-121e5728a15d\">Why a Perfect Hash Still Cost Bybit $1.5 Billion<\/a> was originally published in <a href=\"https:\/\/medium.com\/coinmonks\">Coinmonks<\/a> on Medium, where people are continuing the conversation by highlighting and responding to this story.<\/p>","protected":false},"excerpt":{"rendered":"<p>Most Safe signers treat the hash on their hardware wallet as the final check. It\u00a0isn\u2019t. That single misunderstanding is how $1.5 billion left Bybit in February 2025 and it\u2019s still how most multisig transactions get approved\u00a0today. The gap almost nobody talks\u00a0about Your Ledger or Trezor shows you a hash before every signature.That hash only answers [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":209541,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-209540","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interesting"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/209540"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=209540"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/209540\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/209541"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=209540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=209540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=209540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}