• News/
  • https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/

Lazarus hacked Bybit via breached Safe{Wallet} developer machine

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 26, 2025
·
Updated

​Forensic investigators have found that North Korean Lazarus hackers stole $1.5 billion from Bybit after hacking a developer's device at the multisig wallet platform Safe{Wallet}. Bybit CEO Ben Zhou shared the conclusions of two investigations by Sygnia and Verichains, which both found that the attack originated from Safe{Wallet}'s infrastructure. "The attack specifically targeted Bybit by injecting malicious JavaScript into app.safe.global, which was accessed by Bybit's signers. The payload was designed to activate only when certain conditions were met. This selective execution ensured that the backdoor remained undetected by regular users while compromising high-value targets," Verichains said. "Based on the investigation results from the machines of Bybit's Signers and the cached malicious JavaScript payload found on the Wayback Archive, we strongly conclude that AWS S3 or CloudFront account/API Key of Safe. Global was likely leaked or compromised." "Two minutes after the malicious transaction was executed and published, new versions of the JavaScript resources were uploaded to Safe{Wallet}’s AWS S3 bucket. These updated versions had the malicious code removed," Sygnia added. Sygnia also found that the malicious JavaScript code (targeting Bybit's Ethereum Multisig Cold Wallet) served from Safe{Wallet}'s AWS S3 bucket and used to redirect Bybit's crypto assets to an attacker-controlled wallet had been modified two days before the February 21 attack. Following the incident,...

Read full article

Affected Software

5 affected components
Safe{Wallet} app.safe.global
Ethereum Multisig Cold Wallet
Safe{Wallet} AWS S3 bucket
Safe{Wallet} Safe{Wallet}
Bybit Bybit

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203