Forensic investigators have found that North Korean Lazarus hackers stole $1.5 billion from Bybit after hacking a developer's device at the multisig wallet platform Safe{Wallet}. Bybit CEO Ben Zhou shared the conclusions of two investigations by Sygnia and Verichains, which both found that the attack originated from Safe{Wallet}'s infrastructure. "The attack specifically targeted Bybit by injecting malicious JavaScript into app.safe.global, which was accessed by Bybit's signers. The payload was designed to activate only when certain conditions were met. This selective execution ensured that the backdoor remained undetected by regular users while compromising high-value targets," Verichains said. "Based on the investigation results from the machines of Bybit's Signers and the cached malicious JavaScript payload found on the Wayback Archive, we strongly conclude that AWS S3 or CloudFront account/API Key of Safe. Global was likely leaked or compromised." "Two minutes after the malicious transaction was executed and published, new versions of the JavaScript resources were uploaded to Safe{Wallet}’s AWS S3 bucket. These updated versions had the malicious code removed," Sygnia added. Sygnia also found that the malicious JavaScript code (targeting Bybit's Ethereum Multisig Cold Wallet) served from Safe{Wallet}'s AWS S3 bucket and used to redirect Bybit's crypto assets to an attacker-controlled wallet had been modified two days before the February 21 attack. Following the incident,...
Lazarus hacked Bybit via breached Safe{Wallet} developer machine
BleepingComputer
·Sergiu Gatlan
·Published Feb 26, 2025
·Updated
Affected Software
5 affected components
Safe{Wallet} app.safe.global
Ethereum Multisig Cold Wallet
Safe{Wallet} AWS S3 bucket
Safe{Wallet} Safe{Wallet}
Bybit Bybit