Separate a valid signature from the transaction the signers believed they approved.
A targeted modification to the Safe signing interface caused Bybit signers to authorize a delegatecall that changed the Safe proxy implementation. The transaction is strong evidence of the state-changing action; it is not, by itself, evidence of who altered the interface or controlled every downstream wallet.
01
INVESTIGATOR BRIEF
Research question
Prove what executed on-chain, then keep the signing-interface compromise and actor attribution in separately sourced layers.
The FBI attributed the theft to DPRK TraderTraitor actors and published laundering indicators.
02
PROVENANCE BEFORE CONCLUSION
Evidence ladder
Read these layers in order. A later layer may explain an observation, but it does not change what kind of evidence the underlying transaction is.
01 · on-chain fact
A successful Safe transaction changed contract state
The hash, target contract, calldata, receipt status, block time, and resulting state are observable on Ethereum.
02 · source-reported context
The signers were shown a different operation
NCC Group ties the transaction to targeted malicious JavaScript; the FBI separately attributes the theft to DPRK TraderTraitor actors.
03 · bounded inference
The signing display was not a trustworthy verification boundary
The evidence supports independently reviewing operation type, target, and nested calldata. It does not prove that every downstream recipient shares common control.
NCC Group identifies this as the execTransaction call that used a delegatecall to the attacker contract and changed storage slot 0 of the Bybit Safe proxy.
A ChainRadar result is one observation. Compare it with an independent ledger, official record, or technical source and record both agreement and discrepancy.
01
The seed transaction executed successfully against the Bybit Safe.
ChainRadar check
Transaction Observation Report and EVM decoder
Independent check
Etherscan transaction record
Expected agreement
Hash, block, status, sender, target, and receipt identifiers agree.
02
The call changed the Safe implementation through the reported delegatecall path.
ChainRadar check
Decoder target, calldata context, receipt logs, and technical-address facts
Independent check
NCC Group technical analysis
Expected agreement
The exact Safe and delegatecall target match; the off-chain UI compromise remains sourced only to NCC Group.
03
DPRK TraderTraitor actors were responsible.
ChainRadar check
Address Intelligence displays only a source-qualified claim when available
Independent check
FBI IC3 public service announcement
Expected agreement
Attribution wording and published indicators match the FBI source, not a model score.
07
REPORTING STANDARD
Calibrated findings
Supported conclusions
The transaction-level evidence supports the reported Safe implementation change.
NCC Group supplies the interface-compromise explanation; the FBI supplies the DPRK attribution.
Independent transaction policy checks are necessary even when a familiar signing interface is used.
Required limitations
A valid multisig transaction proves authorization under contract rules, not informed human intent.
A downstream transfer or shared service exposure does not prove common ownership or control.
Actor attribution depends on the cited FBI assessment, not on ChainRadar's ledger observation.