

The Most Expensive Click in Crypto Was a Multisig Approval
In February 2025, someone at Bybit clicked "Approve" on what looked like a routine transfer. That click cost $1.5 billion: the largest theft in crypto history. No smart contract was exploited. The signers were.
And it keeps happening: over $2B has left "secure" multisigs in the last 18 months through hidden delegatecalls, silent config changes, thresholds quietly set to 1, lookalike addresses one character-pattern away from the real thing. Every one of these was visible on-chain before the money moved. Nobody looked.
In this live panel, we dig into crypto's most expensive blind spot:
Why audited, multisig-protected treasuries keep getting drained anyway
What Bybit's signers actually saw on their screens versus what they signed
Blind signing: a tooling failure or a process failure?
Whose job is verification: the signer, the wallet, or an independent layer?
The 60-second pre-signing check that catches this class of attack (live demo)
First look: early findings from our ongoing security scan of the largest DAO treasuries
Who should attend: multisig signers, DAO treasury operators, protocol founders, CFOs and ops leads in crypto, security researchers, anyone whose signature moves real money.
Speaker lineup announcing soon, expect security researchers and treasury operators who've lived this problem.
Free to attend.
Recording sent to every registrant. Hosted by QuillAudits, securing Web3 since 2018, builders of Multisig Inspector, the free pre-signing verification layer for Safe multisigs (multisiginspector.quillaudits.com : try it before the session).