Hackers have once again managed to infiltrate crypto exchanges, exposing vulnerabilities in multi-signature cold storage solutions. The latest wave of attacks has left industry leaders debating the best approach to counter such security breaches. Changpeng Zhao, the former CEO of Binance, and Dominic Williams, the founder of DFINITY, have shared their insights on the attacks and possible solutions.
A pattern has emerged in these incidents, with ByBit, Phemex, WazirX, and potentially others being targeted in similar ways. The recent ByBit hack demonstrated a particularly concerning technique—hackers manipulated the front-end user interface to display legitimate transactions while signing off on entirely different ones. This level of sophistication points to a highly organised group, and Zhao suggests that the Lazarus Group is likely behind these breaches. What remains unclear is whether the attackers gained access to multiple signing devices, compromised the server side, or both.
Zhao’s response to the crisis was to propose an immediate halt to withdrawals following any security breach. He cited Binance’s own experience in 2019 when the platform paused withdrawals for a week after a $40 million hack. While such measures can cause panic, Zhao argued that ensuring complete security before resuming operations is a safer approach. However, he acknowledged that this is ultimately a judgement call for exchange operators. He also took the opportunity to highlight the contrast between ByBit’s transparent communication and the lack of openness from other firms like WazirX and the now-defunct FTX.
The ongoing threat has raised serious concerns about the effectiveness of multi-signature security, with many questioning how different solutions could be compromised simultaneously. The issue goes beyond exchange security; it raises fundamental questions about how blockchain-based financial systems should be structured to prevent similar breaches in the future.
Dominic Williams has long argued that traditional smart contracts are inadequate when it comes to securing user interfaces. He pointed out that the Safe web experience, which was targeted in this case, is not fully secured by blockchain technology. The hackers exploited this weakness, altering the web experience to mislead users and trick multiple signers into approving fraudulent transactions.
Williams has been advocating for a shift towards fully on-chain web3 applications, where web experiences are served directly from the blockchain rather than external servers. The Internet Computer blockchain, launched in 2021, was designed with this capability in mind. Williams claims that if Safe’s web experience had been hosted on the Internet Computer, this attack could not have occurred in the same way. The key difference, he explains, is that smart contracts on the Internet Computer can serve web experiences directly, eliminating the possibility of an external server being compromised.
The need for greater security in crypto asset management has been a persistent concern, and Williams believes that the industry must embrace end-to-end blockchain security. He sees the Internet Computer as a way to offer trustless security solutions that other blockchains can integrate with, reducing the risk of attacks like the ones seen recently.
Williams also provided links to projects that demonstrate the potential of fully on-chain applications. He highlighted Oisy, a multi-chain wallet that uses Internet Identity passkey technology, and OC, a social network and chat service that allows users to send Bitcoin transactions instantly. He also referenced an open-source project designed to create a decentralised version of Fireblocks, aimed at institutions looking for a more secure way to manage multi-chain assets.
The debate over security measures will continue as the industry seeks better ways to protect users. Zhao and Williams represent two different schools of thought—one advocating for stricter operational security and the other pushing for technological advancements that eliminate vulnerabilities at their core. What remains clear is that crypto security cannot be taken for granted, and a proactive approach is essential to prevent further losses.
As hackers become more sophisticated, crypto firms must adapt and find new ways to secure their assets. Whether through immediate response strategies like Zhao’s or fundamental technological shifts like Williams’ vision, the industry needs to address these vulnerabilities before the next major breach occurs. The conversation about security is far from over, and the next steps taken by exchanges and developers will shape the future of digital asset protection.





Community Discussion