logo

Lazarus hacked Bybit via breached Safe{Wallet} developer machine

ID: 9200458f-cb98-5b5a-821e-96f93bc64b80

STIX ID: report--9200458f-cb98-5b5a-821e-96f93bc64b80

Feed Name: Bleeping Computer

Threat Score
95/100

Date Published: 2025-02-26

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Forensic investigations by Sygnia, Verichains and the Safe Ecosystem Foundation attribute a February 21, 2025 attack on Bybit to North Korean Lazarus actors who first compromised a Safe{Wallet} developer machine, used leaked/compromised AWS S3/CloudFront credentials to serve targeted malicious JavaScript that altered multisig signing logic, and diverted over 400,000 ETH (≈$1.5B) to attacker-controlled addresses; the compromise was selective, quickly patched on the Safe{Wallet} infrastructure, and confirmed by multiple blockchain intelligence firms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.