BPOI Banner
US Government Crypto Wallet Drained of $20 Million in Suspicious Transfers US Government Crypto Wallet Drained of $20 Million in Suspicious Transfers

What Caused Bybit’s $1.4 Billion Ethereum Hack? New Details Revealed

Multi-signature wallet provider Safe said Thursday that last month’s $1.4 billion Ethereum heist from Dubai-based centralized exchange Bybit stemmed from a compromised developer laptop. 

After multiple independent reports pointed to a malicious code injection to Safe’s infrastructure, the firm, alongside security experts at Mandiant, released more details Thursday, saying that the investigation had reached a “critical checkpoint.” 

“We present these findings in the spirit of transparency and to highlight key lessons learned, along with calls to action for the broader community to learn from this incident and strengthen defenses,” it posted on X (formerly Twitter). “We wish to stress that despite hundreds of hours of analysis already conducted, there is more work to be done.”

The investigation’s key findings highlighted a high-level Safe developer’s workstation being compromised on February 4 when it interacted with a malicious docker project, or lightweight application. 

From there, the hackers—which on-chain sleuths and the FBI have said hailed from North Korea’s state-sponsored Lazarus hacking group—were able to bypass multi-factor authentication on Safe’s Amazon Web Services account, “hijacking” active AWS session tokens to do so. 

A Wayback Machine snapshot shows that two weeks after the initial compromise, malicious JavaScript was inserted on the Safe website, leading to the Bybit exploit on February 21. 

Since the exploit, Safe has put in place more rigorous security measures, including a full infrastructure reset, improved UI for verifying transaction hashes, and enhanced malicious transaction detection. 

Nevertheless, the investigation is still ongoing, and Safe’s concluding call to action is that users must better be able to verify that the transactions they sign and approve ultimately have the intended outcome.

“The act of signing the transaction itself currently is the last line of defense, and it can only be effective if the user can understand what they are signing,” the firm said. “To support users in securing their transactions, Safe has published a comprehensive guide on how to verify transactions before signing and will take further steps to make this process a frictionless part of using the Safe in the near-term.” 

The Bybit hack was the largest crypto hack of all time. The exchange is actively monitoring the stolen funds, offering up to $140 million in bounties for those that help track and freeze them.

Edited by Andrew Hayward

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

Logan Hitchcock

https://decrypt.co/309018/what-caused-bybit-ethereum-hack-new-details

2025-03-06 22:51:02

bitcoin
Bitcoin (BTC) $ 92,967.91 5.46%
ethereum
Ethereum (ETH) $ 1,792.64 13.72%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.21 6.10%
bnb
BNB (BNB) $ 614.77 2.44%
solana
Solana (SOL) $ 148.38 6.82%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.181245 12.80%
cardano
Cardano (ADA) $ 0.68588 9.83%
tron
TRON (TRX) $ 0.247494 0.63%
staked-ether
Lido Staked Ether (STETH) $ 1,791.85 13.73%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 93,024.92 5.46%
avalanche-2
Avalanche (AVAX) $ 22.41 12.31%
chainlink
Chainlink (LINK) $ 14.30 8.60%
sui
Sui (SUI) $ 2.75 22.67%
leo-token
LEO Token (LEO) $ 9.08 0.56%
stellar
Stellar (XLM) $ 0.266347 6.85%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 9.99%
the-open-network
Toncoin (TON) $ 3.13 7.38%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,149.94 13.07%
hedera-hashgraph
Hedera (HBAR) $ 0.180238 5.98%
usds
USDS (USDS) $ 1.00 0.01%
bitcoin-cash
Bitcoin Cash (BCH) $ 357.05 3.63%
litecoin
Litecoin (LTC) $ 84.43 7.34%
hyperliquid
Hyperliquid (HYPE) $ 18.91 2.62%
polkadot
Polkadot (DOT) $ 4.04 7.09%
bitget-token
Bitget Token (BGB) $ 4.64 4.17%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.09%
weth
WETH (WETH) $ 1,792.16 12.99%
ethena-usde
Ethena USDe (USDE) $ 0.99943 0.03%
pi-network
Pi Network (PI) $ 0.646982 2.37%
monero
Monero (XMR) $ 227.10 5.39%
whitebit
WhiteBIT Coin (WBT) $ 28.41 0.51%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,908.31 12.96%
pepe
Pepe (PEPE) $ 0.000009 13.76%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 92,895.89 5.46%
uniswap
Uniswap (UNI) $ 5.92 12.27%
aptos
Aptos (APT) $ 5.28 7.62%
dai
Dai (DAI) $ 1.00 0.01%
okb
OKB (OKB) $ 52.34 2.97%
gatechain-token
Gate (GT) $ 23.95 3.96%
near
NEAR Protocol (NEAR) $ 2.43 10.15%
ondo-finance
Ondo (ONDO) $ 0.918898 6.62%
bittensor
Bittensor (TAO) $ 334.88 5.89%
internet-computer
Internet Computer (ICP) $ 5.15 8.09%
tokenize-xchange
Tokenize Xchange (TKX) $ 32.75 0.52%
ethereum-classic
Ethereum Classic (ETC) $ 16.82 7.71%
kaspa
Kaspa (KAS) $ 0.097485 11.26%
crypto-com-chain
Cronos (CRO) $ 0.090933 10.53%
susds
sUSDS (SUSDS) $ 1.05 0.02%
bitcoin
Bitcoin (BTC) $ 92,967.91 5.46%
ethereum
Ethereum (ETH) $ 1,792.64 13.72%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.21 6.10%
bnb
BNB (BNB) $ 614.77 2.44%
solana
Solana (SOL) $ 148.38 6.82%
usd-coin
USDC (USDC) $ 1.00 0.01%
dogecoin
Dogecoin (DOGE) $ 0.181245 12.80%
cardano
Cardano (ADA) $ 0.68588 9.83%
tron
TRON (TRX) $ 0.247494 0.63%
staked-ether
Lido Staked Ether (STETH) $ 1,791.85 13.73%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 93,024.92 5.46%
avalanche-2
Avalanche (AVAX) $ 22.41 12.31%
chainlink
Chainlink (LINK) $ 14.30 8.60%
sui
Sui (SUI) $ 2.75 22.67%
leo-token
LEO Token (LEO) $ 9.08 0.56%
stellar
Stellar (XLM) $ 0.266347 6.85%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 9.99%
the-open-network
Toncoin (TON) $ 3.13 7.38%
wrapped-steth
Wrapped stETH (WSTETH) $ 2,149.94 13.07%
hedera-hashgraph
Hedera (HBAR) $ 0.180238 5.98%
usds
USDS (USDS) $ 1.00 0.01%
bitcoin-cash
Bitcoin Cash (BCH) $ 357.05 3.63%
litecoin
Litecoin (LTC) $ 84.43 7.34%
hyperliquid
Hyperliquid (HYPE) $ 18.91 2.62%
polkadot
Polkadot (DOT) $ 4.04 7.09%
bitget-token
Bitget Token (BGB) $ 4.64 4.17%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00 0.09%
weth
WETH (WETH) $ 1,792.16 12.99%
ethena-usde
Ethena USDe (USDE) $ 0.99943 0.03%
pi-network
Pi Network (PI) $ 0.646982 2.37%
monero
Monero (XMR) $ 227.10 5.39%
whitebit
WhiteBIT Coin (WBT) $ 28.41 0.51%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,908.31 12.96%
pepe
Pepe (PEPE) $ 0.000009 13.76%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 92,895.89 5.46%
uniswap
Uniswap (UNI) $ 5.92 12.27%
aptos
Aptos (APT) $ 5.28 7.62%
dai
Dai (DAI) $ 1.00 0.01%
okb
OKB (OKB) $ 52.34 2.97%
gatechain-token
Gate (GT) $ 23.95 3.96%
near
NEAR Protocol (NEAR) $ 2.43 10.15%
ondo-finance
Ondo (ONDO) $ 0.918898 6.62%
bittensor
Bittensor (TAO) $ 334.88 5.89%
internet-computer
Internet Computer (ICP) $ 5.15 8.09%
tokenize-xchange
Tokenize Xchange (TKX) $ 32.75 0.52%
ethereum-classic
Ethereum Classic (ETC) $ 16.82 7.71%
kaspa
Kaspa (KAS) $ 0.097485 11.26%
crypto-com-chain
Cronos (CRO) $ 0.090933 10.53%
susds
sUSDS (SUSDS) $ 1.05 0.02%