I'm regularly asked about the Bybit hack, and how it happened. I went and loaded up a 2/3 multisig wallet using SAFE in ETH and the UX is ATROCIOUS.
Discussion
This is what it looks like to send ETH.
When you sign, it shows it coming from the key on your HWW, to the Multisig Contract.
It does NOT show how much ETH you’re spending, or to which addresses 🥴
The entire transaction data is in the message hash you sign, which means nothing for readability!
Did you immediately throw that device away?
bybit would have been better off using a bitkey 😂
Most people would be better off with a bitkey
Why bother!!
But also good to trial.
The main with ETH that I always like to ask people, “have you mined ETH”
If they have: they all agree it’s not actually decentralised
If they haven’t: they haven’t understood under the hood
Saying that, an exchange getting hacked is another thing, “not your keys, not your coins!”