Close Menu
    Facebook X (Twitter) Instagram
    Thursday, July 3
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Bybit’s $1.4b breach started with stock invest malware, investigation reveals
    Crypto

    Bybit’s $1.4b breach started with stock invest malware, investigation reveals

    James WilsonBy James WilsonMarch 7, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    North Korean hackers stole $1.4 billion from Bybit after breaching Safe’s Mac laptop through a fake stock investment project that helped them bypass AWS security, Mandiant reveals.

    Bybit‘s $1.4 billion cyberattack, now the largest crypto theft in history, is believed to have started with malware from a fake stock investment project that compromised Safe’s Mac laptop and bypassed Amazon Web Services security, according to Mandiant’s investigation.

    In a March 6 article on X, Safe revealed that the North Korean hacking group known as TraderTraitor compromised a Safe{Wallet} developer’s laptop, “Developer1,” and used stolen AWS session tokens to bypass multi-factor authentication.

    According to Mandiant’s investigation, the breach occurred on Feb. 4, when a Docker project — posing as a “stock investment simulator” — was downloaded onto Developer1’s Mac. The project communicated with a suspicious domain (getstockprice[.]com), leading to the malware’s installation.

    It’s unclear what forced Developer1 to download the malware through workstation, but the investigation notes that similar social engineering tactics have already been used in previous attacks by the hacking group.

    Mandiant’s report also found that the attackers bypassed AWS MFA by hijacking active user session tokens, likely through malware on Developer1’s workstation. These hijacked tokens allowed the hackers to access AWS services without needing to pass MFA checks. The attack was conducted from IP addresses linked to a VPN service and security tools designed for offensive hacking, per the report.

    “Certain gaps in fully recovering certain aspects of the attack remain because the attacker removed their malware and cleared Bash history in an effort to thwart investigative efforts.”

    Safe

    As a precautious measure, Safe{Wallet} has reset its infrastructure, restricting external access. It also claims to have enhanced the detection of malicious transactions with Blockaid, a blockchain security firm. According to Safe, its smart contracts were not affected by the breach.

    Cryptocurrency exchange Bybit revealed in early March that nearly 20% of the stolen funds are now untraceable, just less than two weeks after the exchange lost $1.46 billion in a highly sophisticated attack. In an X post, Bybit CEO Ben Zhou revealed that around 77% of the stolen funds remain traceable, but nearly 20% has “gone dark” through mixing services.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleLake Binance? How naming rights can fund the Bitcoin reserve
    Next Article ETH, LINK surge as BitLemons emerges as new hidden opportunity
    James Wilson

    Related Posts

    here’s why Dogwifhat has a 155% upside

    July 3, 2025

    Rising Cardano price has formed a risky pattern

    July 3, 2025

    Move over Dogecoin — 7 picks under $0.50 to watch

    July 3, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    Top US Crypto Exchange by Trading Volume Coinbase Adds Support for Leading Cross-Chain Messaging Protocol Wormhole (W)

    here’s why Dogwifhat has a 155% upside

    Rising Cardano price has formed a risky pattern

    Move over Dogecoin — 7 picks under $0.50 to watch

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    Top US Crypto Exchange by Trading Volume Coinbase Adds Support for Leading Cross-Chain Messaging Protocol Wormhole (W)

    July 3, 2025

    here’s why Dogwifhat has a 155% upside

    July 3, 2025

    Rising Cardano price has formed a risky pattern

    July 3, 2025
    Lithosphere News Releases

    Imagen AI (IMAGE) Developer to Enable Ripple Labs Stablecoin RLUSD for Service Payments

    July 3, 2025

    Imagen Network Begins Strategic Expansion with Bitcoin-Funded AI Infrastructure Rollout

    July 2, 2025

    AGII Enhances Real-Time Protocol Safety With Predictive Automation Models

    July 2, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.