North Korean Hacker Group's Attack on Top Coin Circle Infrastructure Safe: How Important Is Security in Crypto? In this translation, I aimed to maintain the original meaning while ensuring the terminology related to finance and blockchain was accurately
The next hacker-themed movie may be inspired by the recent $1.5 billion Bybit and Safe hack. The hacker's technique was near-perfect, and so far, no traces have been found.
After a week of multi-party investigations, updates have been provided by Safe's team, Bybit's team, and the security company. Blockbeats has summarized the investigation results in the most concise language, revealing the first-hand situation:
1. Code is fine: Safe's front-end code is open source, with no issues at the code level. It was Safe's server security that was compromised.
2. Inside job: Specifically, the code deployed in the production environment was not consistent with what was shown in the open-source repository. This means that at some point, someone replaced or inserted malicious code during the deployment process.
3. Unknown insider: Not all developers have the permission to deploy production code. The individual capable of conducting such a deep operation must have a high level of trust. This insider could be a long-trusted developer or a team member with sufficient permissions. The attacker concealed their tracks for a considerable period. Safe has examined the transaction history, found no anomalies, and has not identified the insider. The community and users are requested to assist in the investigation.
In addition, Safe has not mentioned any plans for compensation but has discussed some follow-up upgrade plans. They also remind everyone to stay rational and to not trust those who are marketing so-called "advanced multisig," "semi-custodial," "MPC," and similar products leveraging this hack event, as these products may instead expand the attack surface.
Indeed, this is not the first theft involving Safe's multisig. The technique used this time is very similar to the October incident involving Radiant Capital. During the Radiant Capital hack, the hacker infected the core developer's device and implanted malicious software, causing the developer to mistakenly believe they were signing a legitimate transaction when, in reality, a malicious transaction was being executed in the background.
Safe's Impact on the Crypto Space
Why is this event so attention-grabbing? The reason is that Safe is the most popular multisig wallet in the Ethereum ecosystem.
When Safe was launched last year, the top 100 airdrop addresses were mainly project teams, institutions, and large holders. This means that Safe's security can impact a significant part of the crypto space.
As shown in the image, well-known names include Metamask, PleasrDao, AAVE, 1inch, Lido, and more.

During this cycle, traditional finance, traditional institutions, family funds, and old money have accelerated their entry. However, due to the high entry barrier of crypto, many people have chosen a relatively safer way to protect their funds while engaging in on-chain activities, which is through a multi-signature wallet like Safe.
For example, the most representative is former President Trump's DeFi team.

According to Safe's guardians speaking to Doozer BlockBeats, the simplest way to determine if an on-chain address is a Safe wallet address is through two methods: first is the "MultiSig" displayed on ARKHAM, and second is the "MultiSig: Safe" directly displayed below the address on the debank page. As seen in the image above, former President Trump's DeFi project World Liberity Fi indeed uses a multi-signature wallet.
This means that any security vulnerability within Safe could potentially trigger a huge chain reaction and butterfly effect.
Even Top Coin Security Infrastructure Can Encounter Issues
The Safe project is basically a blue-chip project in the Ethereum ecosystem, with its incubation team being Gnosis.
Gnosis Chain, which was a well-known Ethereum sidechain in the previous cycle, focuses on efficient and secure decentralized application development. According to DefiLlama data, as of the time of writing this article, Gnosis Chain's total value locked (TVL) is $200 million, with a peak of $350 million.

In fact, the story of the Gnosis ecosystem and incubator can be traced back to 2015.
Compared to the now well-known Polymarket, Gnosis co-founder Martin Koeppelmann began researching decentralized prediction markets much earlier. In 2015, he posted his thoughts on the combination of MarketMaker and OrderBook on his forum, which was one of the earliest concepts of a decentralized prediction market in the industry.
Martin Koeppelmann is also one of the earliest Ethereum developers, having joined before TheDAO era and being based in Berlin, he had close interactions with Vitalik, who had an office in Berlin at the time.

Over the years, he has been actively involved in many discussions in the Ethereum development community, often engaging with Vitalik on topics such as L2, ZK, and the Ethereum roadmap. Martin's integration into the community can also be seen from his social media presence.
Based on this technical expertise, Gnosis has gradually developed a complete ecosystem. Evolving from Gnosis Protocol to CowSwap, Martin and his team have further expanded to create products such as Gnosis Chain, Safe, and Gnosis Pay.
Has the Bear Market Signal Been Triggered?
The extensive impact of this Safe security incident has indeed caused a significant amount of panic and pessimism in the crypto community. According to Alternative.me data, today's cryptocurrency fear and greed index has dropped to 10, hitting a new low since July 2022, with the market remaining in extreme fear.
Many community members are now questioning whether multi-signature is merely a "fig leaf" decoration.?
Simultaneously, many industry practitioners are expressing reflection and concerns about the industry: "If multi-signature wallets are not secure, then who will take this industry seriously and trust it? Has the crypto industry turned into a hacker haven?"
A historical perspective shows that the end of each crypto bull market is often accompanied by major security and trust crises.
For example, the early Mt.Gox event led to a large amount of crypto assets being stolen, becoming one of the most famous hacking incidents in crypto industry history; the end of the last bull market started with a trust crisis stemming from FTX's run on the bank and Terra's collapse, severely affecting investor confidence in the entire industry.
So, what will mark the end of this bull market? Pessimistically, the Safe security incident is very likely to be one of the "signals" marking the end of this bull run.
You may also like

Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?

New York Proposes Stricter Stablecoin Issuer Rules Aligned With Federal GENIUS Act
NYDFS proposed stricter stablecoin issuer rules aligned with the GENIUS Act, covering reserves, custody, redemption timelines, audits, and capital buffers.

Every exchange is a "Universal Exchange."

The counterattack of traditional finance: Alliance chains are quietly reviving

CryptoQuant Says Bitcoin Profitable Supply Is Near 45% Pressure Zone as On-Chain Data Points to Market Repricing
CryptoQuant said Bitcoin’s profitable supply is nearing the 45% pressure zone, signaling rising market stress, unrealized losses, and a possible on-chain repricing phase.

Bitcoin Falls Below 200-Week Moving Average as On-Chain Data Shows Over Half of Supply in Loss
Bitcoin dropped below its 200-week moving average as on-chain data showed over 50% of circulating supply is now in loss, signaling rising market stress.

CFTC Reportedly Plans New Prediction Market Rules Focused on Manipulation Risk and Public Interest Review
The CFTC is reportedly preparing new prediction market rules focused on manipulation risk, public interest review, and retail trader protections.

Meet the new WEEX trial fund—your gateway to greater profits

WEEX Labs Lands at Dutch Blockchain Week: A Disruptive Crypto × AI Conversation Sets Sail in Amsterdam

SK Hynix Reportedly Plans U.S. ADR Listing as Early as August, With SEC Approval Possible in Late June
SK Hynix may pursue a U.S. ADR listing as early as August, with SEC approval reportedly possible in late June amid strong AI chip supply chain demand.

SpaceX vs Tesla vs xAI: Which Elon Musk Trade Has the Biggest Upside in 2026?

OpenAI Reveals It Has Confidentially Submitted an S-1 to the SEC, Keeping the Door Open for a Future IPO
On June 9, according to an OpenAI announcement, the company recently confidentially submitted a draft S-1 registration statement to the U.S. Securities and Exchange Commission (SEC), beginning the preliminary compliance process for a potential initial public offering. OpenAI said it chose to disclose this proactively because it expected the news might leak; however, the company has not yet set a specific listing timeline, and related arrangements may still take some time.

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Apollo and Blackstone Reportedly Back $35 Billion Anthropic Chip Financing as Deal Details Remain Unclear
On June 9, according to currently available news alerts, Apollo and Blackstone Group participated in a $35 billion financing for an Anthropic “chip project.” Based on the original wording of the report, the funding has already been raised, but public information remains limited. The financing structure, use of proceeds, project entity, and whether Apollo and Blackstone participated through equity, debt, or project financing have not yet been disclosed.

Humanity Protocol Security Incident Escalates: More Than $31 Million Stolen From Related Addresses as Attacker Continues Selling H for ETH
On June 9, according to monitoring by Onchain Lens, more than $31 million has been stolen from addresses linked to Humanity Protocol, and the attack is still ongoing, with the hacker continuously swapping H tokens for ETH. Project founder Terence Kwok later confirmed the security incident on X, saying the issue involved a private key leak.

Bloomberg: As Bitcoin Weakens, Stablecoins and RWA Continue to Drive Expansion in Crypto Businesses
In June, Bloomberg reported that despite Bitcoin falling below $60,000 last week, wiping out about $235 billion in market value within seven days, and dropping close to 50% from last year’s peak, some core businesses in the crypto industry are still expanding, mainly in stablecoins, real-world asset tokenization (RWA), payments, and infrastructure. The report also noted that overall altcoin activity has contracted significantly: altcoin market capitalization has fallen from a peak of about $431 billion in November 2021 to around $170 billion, and among the tens of millions of tokens issued in recent years, fewer than 1,700 still maintain meaningful trading activity.

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?
Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?
New York Proposes Stricter Stablecoin Issuer Rules Aligned With Federal GENIUS Act
NYDFS proposed stricter stablecoin issuer rules aligned with the GENIUS Act, covering reserves, custody, redemption timelines, audits, and capital buffers.
Every exchange is a "Universal Exchange."
The counterattack of traditional finance: Alliance chains are quietly reviving
CryptoQuant Says Bitcoin Profitable Supply Is Near 45% Pressure Zone as On-Chain Data Points to Market Repricing
CryptoQuant said Bitcoin’s profitable supply is nearing the 45% pressure zone, signaling rising market stress, unrealized losses, and a possible on-chain repricing phase.
Bitcoin Falls Below 200-Week Moving Average as On-Chain Data Shows Over Half of Supply in Loss
Bitcoin dropped below its 200-week moving average as on-chain data showed over 50% of circulating supply is now in loss, signaling rising market stress.

