BPOI Banner
Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder Developers Linked to North Korea Helped Develop Cosmos Staking Module, Says Co-Founder

We Now Know How Bybit Was Hacked for $1.4 Billion in Ethereum

Multiple independent audits have now pointed the finger at the cause of last week’s historic $1.4 billion Bybit hack—billed as the largest crypto hack of all time based on the value of the assets—and it wasn’t the crypto exchange at fault.

Rather, analysts at Verichains and Sygnia Labs, two top cybersecurity firms, have determined that North Korean hackers managed to pull off the biggest hack in history by planting malicious code into the infrastructure of Safe—a crypto wallet provider used by Bybit, and one that has long marketed itself as impenetrable.

According to reports from both security firms, North Korean hackers injected malicious JavaScript code directly into Safe’s online infrastructure, which was hosted on Amazon Web Services. It is as of yet unclear how the hackers managed to infiltrate Safe’s code.

Perhaps to avoid detection, the code was also specially tailored: it was designed to only activate once it interacted with Bybit’s contract address. Once Bybit did indeed interact with Safe, two days later, the code worked its magic—and $1.4 billion worth of Ethereum and related tokens were drained from the crypto exchange. 

Just two minutes after the hack, North Korean hackers then updated Safe’s infrastructure to remove the malicious lines of code—and disappeared without a trace. 

In a statement shared with Decrypt, Bybit emphasized that initial forensics reports show the exchange’s infrastructure “was not compromised” by North Korean hackers. 

Bybit is and remains 100% secure,” the company said.

The statement added that Bybit moved “the majority of funds” out of its Safe-administered wallets in the hours following Friday’s attack. The company declined to comment, though, when asked by Decrypt whether it intends to permanently sever ties with the wallet provider. 

As for Safe itself—it’s been a rough day for public relations so far. In a statement posted to X on Wednesday, the company acknowledged Verichains’ and Sygnia’s findings, saying the hack did stem from a “compromised Safe Wallet developer machine.” 

The company claimed, though, that the reports did not indicate any vulnerabilities in Safe’s smart contracts or front-end source code. Safe added that it has fully rebuilt and reconfigured its infrastructure and changed all its credentials, “ensuring the attack vector is fully eliminated.”

Safe did not immediately respond to Decrypt’s request for comment for this story. 

On Crypto Twitter, industry players reeled at the news and its potential implications for the numerous crypto users and projects that depend on Safe. 

“If it’s Safe, then we’re in a very bad spot,” Aurora co-founder Alex Shevcheko wrote in a now-deleted tweet.

“This… is scary,” pseudonymous crypto gaming founder Loopify added.

MetaMask’s Taylor Monahan, an on-chain sleuth and noted expert on North Korean crypto hacks, advised caution with regards to playing the blame game.

“I think it’s been presumptuous for us to assume it was Bybit the first five days,” she told Decrypt. “I think it’s presumptuous to flip 180 degrees and say it’s Safe’s fault on day six.”

Regardless of who, exactly, is to blame for the exploit, the Bybit hack only confirmed Monahan’s fear—which she has been vocal about, for years—that the crypto industry has not taken the threat of bad actors like North Korea nearly seriously enough.

“I have been screaming about this forever,” Monahan said. “It’s time to get really fucking serious about security. Bad guys will do insane things to get inside you because the reward for doing so is millions—billions!—of dollars.”

Edited by Andrew Hayward

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Sander Lutz

https://decrypt.co/307866/how-bybit-hacked-1-4-billion-ethereum

2025-02-26 18:25:58

bitcoin
Bitcoin (BTC) $ 85,312.86 1.48%
ethereum
Ethereum (ETH) $ 1,895.03 5.92%
tether
Tether (USDT) $ 0.99993 0.04%
xrp
XRP (XRP) $ 2.22 5.30%
bnb
BNB (BNB) $ 629.38 0.32%
solana
Solana (SOL) $ 131.43 4.54%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.18157 6.31%
cardano
Cardano (ADA) $ 0.7021 4.15%
tron
TRON (TRX) $ 0.230728 1.68%
staked-ether
Lido Staked Ether (STETH) $ 1,893.18 6.06%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 85,129.24 1.58%
the-open-network
Toncoin (TON) $ 3.99 3.58%
chainlink
Chainlink (LINK) $ 14.33 8.00%
leo-token
LEO Token (LEO) $ 9.70 0.58%
stellar
Stellar (XLM) $ 0.275857 3.50%
avalanche-2
Avalanche (AVAX) $ 20.43 6.98%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,264.46 6.29%
sui
Sui (SUI) $ 2.54 6.28%
usds
USDS (USDS) $ 1.00 0.01%
shiba-inu
Shiba Inu (SHIB) $ 0.000013 6.14%
hedera-hashgraph
Hedera (HBAR) $ 0.184025 3.51%
litecoin
Litecoin (LTC) $ 87.99 6.22%
polkadot
Polkadot (DOT) $ 4.30 5.90%
mantra-dao
MANTRA (OM) $ 6.36 2.69%
bitcoin-cash
Bitcoin Cash (BCH) $ 311.33 5.45%
bitget-token
Bitget Token (BGB) $ 4.76 4.33%
pi-network
Pi Network (PI) $ 0.82491 1.37%
weth
WETH (WETH) $ 1,893.27 6.17%
ethena-usde
Ethena USDe (USDE) $ 0.999083 0.03%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.99939 0.22%
hyperliquid
Hyperliquid (HYPE) $ 13.76 4.53%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,010.66 6.06%
whitebit
WhiteBIT Coin (WBT) $ 28.91 0.64%
monero
Monero (XMR) $ 220.95 1.12%
uniswap
Uniswap (UNI) $ 6.28 6.80%
dai
Dai (DAI) $ 0.999882 0.03%
near
NEAR Protocol (NEAR) $ 2.78 6.65%
aptos
Aptos (APT) $ 5.48 7.25%
pepe
Pepe (PEPE) $ 0.000008 6.81%
susds
sUSDS (SUSDS) $ 1.05 0.11%
tokenize-xchange
Tokenize Xchange (TKX) $ 36.77 2.05%
okb
OKB (OKB) $ 48.73 2.52%
crypto-com-chain
Cronos (CRO) $ 0.106482 8.17%
gatechain-token
Gate (GT) $ 22.81 2.76%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 85,227.83 1.60%
mantle
Mantle (MNT) $ 0.819759 2.80%
internet-computer
Internet Computer (ICP) $ 5.65 5.94%
ondo-finance
Ondo (ONDO) $ 0.855135 5.59%
aave
Aave (AAVE) $ 172.85 5.82%
bitcoin
Bitcoin (BTC) $ 85,312.86 1.48%
ethereum
Ethereum (ETH) $ 1,895.03 5.92%
tether
Tether (USDT) $ 0.99993 0.04%
xrp
XRP (XRP) $ 2.22 5.30%
bnb
BNB (BNB) $ 629.38 0.32%
solana
Solana (SOL) $ 131.43 4.54%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.18157 6.31%
cardano
Cardano (ADA) $ 0.7021 4.15%
tron
TRON (TRX) $ 0.230728 1.68%
staked-ether
Lido Staked Ether (STETH) $ 1,893.18 6.06%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 85,129.24 1.58%
the-open-network
Toncoin (TON) $ 3.99 3.58%
chainlink
Chainlink (LINK) $ 14.33 8.00%
leo-token
LEO Token (LEO) $ 9.70 0.58%
stellar
Stellar (XLM) $ 0.275857 3.50%
avalanche-2
Avalanche (AVAX) $ 20.43 6.98%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,264.46 6.29%
sui
Sui (SUI) $ 2.54 6.28%
usds
USDS (USDS) $ 1.00 0.01%
shiba-inu
Shiba Inu (SHIB) $ 0.000013 6.14%
hedera-hashgraph
Hedera (HBAR) $ 0.184025 3.51%
litecoin
Litecoin (LTC) $ 87.99 6.22%
polkadot
Polkadot (DOT) $ 4.30 5.90%
mantra-dao
MANTRA (OM) $ 6.36 2.69%
bitcoin-cash
Bitcoin Cash (BCH) $ 311.33 5.45%
bitget-token
Bitget Token (BGB) $ 4.76 4.33%
pi-network
Pi Network (PI) $ 0.82491 1.37%
weth
WETH (WETH) $ 1,893.27 6.17%
ethena-usde
Ethena USDe (USDE) $ 0.999083 0.03%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.99939 0.22%
hyperliquid
Hyperliquid (HYPE) $ 13.76 4.53%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,010.66 6.06%
whitebit
WhiteBIT Coin (WBT) $ 28.91 0.64%
monero
Monero (XMR) $ 220.95 1.12%
uniswap
Uniswap (UNI) $ 6.28 6.80%
dai
Dai (DAI) $ 0.999882 0.03%
near
NEAR Protocol (NEAR) $ 2.78 6.65%
aptos
Aptos (APT) $ 5.48 7.25%
pepe
Pepe (PEPE) $ 0.000008 6.81%
susds
sUSDS (SUSDS) $ 1.05 0.11%
tokenize-xchange
Tokenize Xchange (TKX) $ 36.77 2.05%
okb
OKB (OKB) $ 48.73 2.52%
crypto-com-chain
Cronos (CRO) $ 0.106482 8.17%
gatechain-token
Gate (GT) $ 22.81 2.76%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 85,227.83 1.60%
mantle
Mantle (MNT) $ 0.819759 2.80%
internet-computer
Internet Computer (ICP) $ 5.65 5.94%
ondo-finance
Ondo (ONDO) $ 0.855135 5.59%
aave
Aave (AAVE) $ 172.85 5.82%