Lazarus hacked Bybit via breached Safe{Wallet} developer machine
ID: 9200458f-cb98-5b5a-821e-96f93bc64b80
STIX ID: report--9200458f-cb98-5b5a-821e-96f93bc64b80
Feed Name: Bleeping Computer
Forensic investigations by Sygnia, Verichains and the Safe Ecosystem Foundation attribute a February 21, 2025 attack on Bybit to North Korean Lazarus actors who first compromised a Safe{Wallet} developer machine, used leaked/compromised AWS S3/CloudFront credentials to serve targeted malicious JavaScript that altered multisig signing logic, and diverted over 400,000 ETH (≈$1.5B) to attacker-controlled addresses; the compromise was selective, quickly patched on the Safe{Wallet} infrastructure, and confirmed by multiple blockchain intelligence firms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
