{"id":48223,"date":"2025-02-27T05:41:14","date_gmt":"2025-02-27T05:41:14","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/forensic-report-links-bybits-1-48b-loss-to-safe-wallet-security-flaw\/"},"modified":"2025-02-27T05:41:14","modified_gmt":"2025-02-27T05:41:14","slug":"forensic-report-links-bybits-1-48b-loss-to-safe-wallet-security-flaw","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/forensic-report-links-bybits-1-48b-loss-to-safe-wallet-security-flaw\/","title":{"rendered":"Forensic Report Links Bybit\u2019s $1.48B Loss to Safe Wallet Security Flaw"},"content":{"rendered":"<p><b>(Originally posted on : Crypto News &#8211; iGaming.org )<\/b><br \/>\n<\/p>\n<div>\n<p>According to a recent investigation into the Bybit incident, hackers took advantage of a security hole in Safe, the exchange\u2019s cryptocurrency wallet. In what is now regarded as one of the biggest cryptocurrency heists in history, hackers affiliated with North Korea\u2019s Lazarus Group <a href=\"https:\/\/igaming.org\/crypto\/bybit-cold-wallet-breached-as-hackers-steal-1-5-billion\/\">stole $1.48 billion in Ethereum (ETH)<\/a> from Bybit\u2019s wallet late last week.<\/p>\n<p>After a combined investigation by cybersecurity specialists Sygnia and financial security firm Verichains, Bybit CEO Ben Zhou revealed that Lazarus most likely gained access to Bybit\u2019s Ethereum wallet via breaking into Safe\u2019s Amazon Web Services (AWS) infrastructure.<\/p>\n<p data-start=\"704\" data-end=\"1046\"><em>\u201cThe benign Javascript file of app.safe.global appears to have been replaced with malicious code on February 19, 2025, at 15:29:25 UTC, specifically targeting Ethereum Multisig Cold Wallet of Bybit. The attack was designed to activate during the next Bybit transaction, which occurred on February 21, 2025, at 14:13:35 UTC\u2026\u201d<\/em> Zhou explained.<\/p>\n<p data-start=\"1048\" data-end=\"1190\">The investigation suggests that hackers gained access to Safe.Global\u2019s AWS S3 or CloudFront account, enabling them to inject malicious code.<\/p>\n<h2 data-start=\"1192\" data-end=\"1237\">Safe Wallet Responds to Security Breach<\/h2>\n<p data-start=\"1239\" data-end=\"1373\">Safe acknowledged the findings and confirmed that Lazarus Group targeted Bybit through a compromised Safe{Wallet} developer machine.<\/p>\n<div class=\"main-org-3-item-ins box-100 relative mb-4\">\n<div class=\"space-org-3-items box-100 relative\">\n<div class=\"box-100 space-org-3-item relative border-tb mt-1 \">\n<div class=\"space-org-3-item-ins box-100 relative\">\n<div class=\"space-org-3-item-terms box-25 relative\">\n<div class=\"space-org-3-item-terms-ins box-100 text-center relative\"> <strong>177% up to 5BTC + 77 <strong> Free Spins<\/strong>!<\/strong> <\/p>\n<p>New players only. Exclusive Welcome Bonus of 177% + 77 Free Spins <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p data-start=\"1375\" data-end=\"1803\"><em>\u201cThe forensic review into the targeted attack by the Lazarus Group on Bybit concluded that this attack targeted to the Bybit Safe was achieved through a compromised Safe{Wallet} developer machine resulting in the proposal of a disguised malicious transaction\u2026 Following the recent incident, the Safe{Wallet} team conducted a thorough investigation and have now restored Safe{Wallet} on Ethereum mainnet with a phased rollout.\u201d<\/em><\/p>\n<p>Since then, Safe has redesigned its architecture, changing credentials and resetting systems to stop such attacks. The business intends to publish a thorough report outlining the hack.<\/p>\n<p>Zhou reassured users that Bybit had restored a 1:1 asset backup in spite of the big attack. The exchange has reserves more than 100% of its obligations, according to a proof-of-reserves audit conducted by blockchain security company Hacken.<\/p>\n<p data-start=\"2275\" data-end=\"2451\"><em>\u201cThe Hacken team\u2019s Proof of Reserves audit, conducted on Sunday, February 23, 2025, demonstrates that Bybit maintains an in-scope reserve ratio of &gt; 100%,\u201d<\/em> the report stated.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/igaming.org\/crypto\/forensic-report-links-bybits-1-48b-loss-to-safe-wallet-security-flaw\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Crypto News &#8211; iGaming.org ) According to a recent investigation into the Bybit incident, hackers took advantage of a security hole in Safe, the exchange\u2019s cryptocurrency wallet. In what is now regarded as one of the biggest cryptocurrency heists in history, hackers affiliated with North Korea\u2019s Lazarus Group stole $1.48 billion [&hellip;]<\/p>\n","protected":false},"author":35,"featured_media":48224,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[34],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/48223"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/35"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=48223"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/48223\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/48224"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=48223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=48223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=48223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}