OneKey founder Wang said the $1.5 billion theft from Bybit in February 2025 exposed a weak point that hardware wallets alone cannot solve: users can securely hold private keys while still being tricked into approving malicious transactions through a compromised web interface.
In Wang’s account of the breach, the Safe multisignature contract, the cold wallets and the Ledger devices used by Bybit personnel were not directly exploited. Instead, attackers linked to North Korea’s Lazarus Group allegedly compromised the computer of a Safe front-end engineer through social engineering, inserted malicious code into Safe’s official web interface and configured it to activate only when Bybit’s wallet address was involved.
The episode places greater weight on transaction decoding and on-device warnings as institutions use hardware wallets for increasingly complex operations. A device that shows only an opaque approval request can leave a signer unable to distinguish a routine transfer from a transaction that changes control of a wallet contract.
Wang said four Bybit signers, including a person he identified as Ben and three members of finance and audit teams, were shown what appeared in their browsers to be a normal cold-to-hot wallet transfer. The transaction they approved instead used a proxy mechanism that transferred control over the Safe contract, he said.
Blind signing remains a weak link in complex wallet workflows
According to Wang, the Ledger devices involved did not parse the Safe contract action in a way that displayed the use of delegatecall, a contract operation that allows one contract to execute code from another. The signers were asked to approve a transaction without a clear on-device explanation of its ultimate effect, a process generally known as blind signing.
Blind signing has long been a practical compromise for wallets interacting with smart contracts that a device cannot fully decode. It allows users to access DeFi applications and other complex on-chain services, but shifts a large part of the security decision back to whatever interface prepares the transaction.
That trade-off became more visible as crypto users moved assets on-chain during the 2020 DeFi Summer, Wang said. MetaMask became the common browser-based entry point for decentralized applications, while users with larger balances increasingly added hardware wallets to reduce the risk from malware, compromised browser extensions and exposed private keys.
Wang said OneKey built its early product strategy around reducing the friction of that setup. Using a Ledger device with DeFi services often required installing Ledger Live, adding the Ethereum application to the device and connecting through MetaMask. Competing desktop clients could also create USB connection conflicts, he said.
OneKey chose to focus on localized features and a simpler workflow, Wang said, while adopting an open-source model that he contrasted with Ledger’s closed-source approach. Open code can make external review easier, although public visibility does not guarantee that a flaw will be found quickly. Wang pointed to a mnemonic-generation issue involving Coldcard that he said remained visible in public code between 2021 and 2025 before being addressed.
Faster research cuts both ways
The growth of artificial intelligence tools is compressing the time required to find and combine security weaknesses, Wang said. He estimated that an attack chain once requiring two or three senior researchers working for about two months could now be assembled by one security engineer in roughly two weeks.
Wang said OneKey’s security group, Anzen Labs, used AI tools during research into a USB vulnerability presented at the Black Hat security conference. The tools assisted with finding the flaw, reproducing it and connecting separate weaknesses into a working attack chain, he said.
The same automation could give manufacturers more chances to test their own products before an update reaches users. Wang said firms that previously conducted one or two firmware audits each year can use automated workflows to audit software with every weekly release.
OneKey has also moved some physical device testing from repetitive manual work to an automated system using four or five robotic arms, Wang said. The setup combines mechanical actuators, high-definition cameras and machine-learning models to run test cases across each software release. Hardware testing remains difficult to scale because a software change can interact with a device screen, button, USB connection, firmware component or manufacturing variation.
Wang said OneKey experienced that complexity first-hand during its early expansion. The company spent nearly a year facing hardware shortages after making new tooling decisions, attempting to rebuild firmware from end to end and underestimating supply-chain dependencies. He said the team also over-designed parts of its early technical architecture before proving demand and refining the product through rapid releases.
Ledger issue focused on what users see before approval
Wang also described a Ledger “transaction replacement” vulnerability that OneKey disclosed after a fix had been released. He said the affected Ledger firmware version was 1.2.1 and that version 1.2.3 included the repair.
He characterized the flaw as a time-of-check to time-of-use, or TOCTOU, issue. In such a vulnerability, information examined by a user or device can change before the final action is executed. Applied to a hardware wallet, that gap can create a mismatch between the transaction details shown on a device and the transaction ultimately signed and broadcast.
The issue reinforces the operational challenge facing wallet makers: a hardware device can protect a private key without necessarily understanding every application-specific transaction placed in front of it. Support for clear contract parsing, address verification, simulation tools and transaction-policy controls becomes more valuable as institutional treasury activity moves through multisignature systems and browser-based dashboards.
From Taobao Bitcoin purchases to hardware wallets
Wang said his own path into the sector began in 2013, when he was studying civil engineering and bought Bitcoin through Taobao for more than $100, or about 700 yuan. Bitcoin later climbed to nearly 8,000 yuan during that year’s fourth-quarter market run, he said. He added that XRP was then available through straightforward payment links, illustrating how lightly structured some early retail access routes were.
Before working full-time in crypto, Wang joined ByteDance when the company had about 400 employees. He said its product culture centered on launching multiple applications each month, using traffic from tabs in its main product to test demand, and relying on A/B test results to decide which projects continued.
That model shaped OneKey’s preference for paid practical tasks in hiring, Wang said. Candidates complete assignments lasting two or three days, followed by a paid trial period. The process is designed to show how people communicate, solve problems and deliver work, rather than rewarding only conventional interview performance.
For wallet users and institutional signers, the Bybit breach offers a narrower operational lesson than a general warning about cold storage. Hardware wallets remain designed to keep private keys offline, but their protection can be undermined when a signer cannot independently understand the transaction displayed for approval. Clear on-device decoding, cautious handling of blind-sign prompts and tightly controlled access to transaction-preparation systems would reduce the scope for a compromised website to turn a legitimate signing ceremony into a fraudulent transfer.
To better understand wallet safety and blind-signing risks, explore crypto wallet mistakes to avoid before your next transaction.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
