{
  "slug": "blind-signing-wysiwys",
  "title": "Bybit's signers signed what the screen showed. The screen was lying.",
  "summary": "A compromised interface showed three signers a routine transfer and took roughly $1.5B. Blind signing was not the failure. Display and signer sharing a machine was.",
  "lede": "On 21 February 2025 three people approved what their screens described as a routine transfer, and roughly 1.5 billion dollars left the building. They were not careless and they were not blind signing. They were reading a display that had been rewritten by someone else. This is a lesson about the difference between what you see and what you sign, and why that gap exists in almost every approval screen in finance.",
  "date": "2026-09-03",
  "reading_time": "17 min read",
  "category": "Security",
  "tags": [
    "blind signing",
    "WYSIWYS",
    "Bybit hack",
    "UI injection",
    "transaction signing",
    "canonicalization",
    "treasury security"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Blind%20Signing%20WYSIWYS/1200_630/blog.jpg",
  "url": "/blog/blind-signing-wysiwys.html",
  "wordcount": 4486,
  "related": [
    "crypto-withdrawal-authorization",
    "deepfake-cfo-wire-fraud",
    "kill-switch-design"
  ],
  "schema": "Article"
}
