Bybit Hack – Sophisticated Multi-Stage Attack Details Revealed
ID: 3c20ff4f-c3da-532f-847c-3af59fec56f8
STIX ID: report--3c20ff4f-c3da-532f-847c-3af59fec56f8
Feed Name: cybersecurityNews.com
Threat Score
**Bybit ETH cold wallet compromise (Feb 2025):** Attackers attributed to the Lazarus group compromised a Safe{Wallet} developer via a malicious Docker project, stole AWS credentials, modified JavaScript on Safe{Wallet}’s S3 to inject transaction-manipulating code, and used a delegatecall-based malicious smart contract to drain over 400,000 ETH from Bybit cold storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
