Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Bitcoin realized cap surges, bullish trend likely to hold

    May 14, 2025

    Building the new backbone of finance

    May 14, 2025

    Bitget Wallet launches new crypto in-app marketplace with access to over 300 brands

    May 14, 2025
    Facebook X (Twitter) Instagram
    Wednesday, May 14
    • About
    • Contact us
    • Privacy Policy
    Facebook X (Twitter) LinkedIn YouTube
    Blockchain Echo
    Banner
    • Lithosphere News Releases
    • Bitcoin
    • Crypto
    • Ethereum
    • Litecoin
    • Altcoins
    • Blockchain
    Blockchain Echo
    Home » Bybit’s $1.4b breach started with stock invest malware, investigation reveals
    Crypto

    Bybit’s $1.4b breach started with stock invest malware, investigation reveals

    John SmithBy John SmithMarch 7, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    North Korean hackers stole $1.4 billion from Bybit after breaching Safe’s Mac laptop through a fake stock investment project that helped them bypass AWS security, Mandiant reveals.

    Bybit‘s $1.4 billion cyberattack, now the largest crypto theft in history, is believed to have started with malware from a fake stock investment project that compromised Safe’s Mac laptop and bypassed Amazon Web Services security, according to Mandiant’s investigation.

    In a March 6 article on X, Safe revealed that the North Korean hacking group known as TraderTraitor compromised a Safe{Wallet} developer’s laptop, “Developer1,” and used stolen AWS session tokens to bypass multi-factor authentication.

    According to Mandiant’s investigation, the breach occurred on Feb. 4, when a Docker project — posing as a “stock investment simulator” — was downloaded onto Developer1’s Mac. The project communicated with a suspicious domain (getstockprice[.]com), leading to the malware’s installation.

    It’s unclear what forced Developer1 to download the malware through workstation, but the investigation notes that similar social engineering tactics have already been used in previous attacks by the hacking group.

    Mandiant’s report also found that the attackers bypassed AWS MFA by hijacking active user session tokens, likely through malware on Developer1’s workstation. These hijacked tokens allowed the hackers to access AWS services without needing to pass MFA checks. The attack was conducted from IP addresses linked to a VPN service and security tools designed for offensive hacking, per the report.

    “Certain gaps in fully recovering certain aspects of the attack remain because the attacker removed their malware and cleared Bash history in an effort to thwart investigative efforts.”

    Safe

    As a precautious measure, Safe{Wallet} has reset its infrastructure, restricting external access. It also claims to have enhanced the detection of malicious transactions with Blockaid, a blockchain security firm. According to Safe, its smart contracts were not affected by the breach.

    Cryptocurrency exchange Bybit revealed in early March that nearly 20% of the stolen funds are now untraceable, just less than two weeks after the exchange lost $1.46 billion in a highly sophisticated attack. In an X post, Bybit CEO Ben Zhou revealed that around 77% of the stolen funds remain traceable, but nearly 20% has “gone dark” through mixing services.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleETH, LINK surge as BitLemons emerges as new hidden opportunity
    Next Article Analyst outlines strategies for the U.S. to buy more Bitcoin
    John Smith

    Related Posts

    Bitcoin realized cap surges, bullish trend likely to hold

    May 14, 2025

    Building the new backbone of finance

    May 14, 2025

    Bitget Wallet launches new crypto in-app marketplace with access to over 300 brands

    May 14, 2025
    Leave A Reply Cancel Reply

    Top Posts

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    About Us

    Stay updated on the world of cryptocurrency
    Your one-stop source for daily crypto news and insights
    Blockchainecho.info: Your trusted daily crypto companion

    Most Popular

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Copyright © 2025
    • Home
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.