Lazarus hacked Bybit via breached Safe{Wallet} developer machine

Lazarus hacked Bybit via breached Safe{Wallet} developer machine
Summary: Forensic investigations revealed that North Korean Lazarus hackers stole .5 billion from Bybit by exploiting vulnerabilities in the Safe{Wallet} multisig wallet platform. The attack involved injecting malicious JavaScript into the platform, targeting Bybitโ€™s Ethereum cold wallet during a routine transaction. Following the heist, Safe{Wallet} has reconfigured its infrastructure and implemented enhanced security measures to prevent future breaches.

Affected: Bybit, Safe{Wallet}

Keypoints :

  • North Korean Lazarus hackers executed a sophisticated attack to siphon over .5 billion from Bybit.
  • Investigation concluded that a compromised Safe{Wallet} developer machine facilitated the attack.
  • Safe{Wallet} has restored services and increased security measures following the breach.
  • Previously stolen funds are linked to other North Korean thefts, highlighting the groupโ€™s ongoing cybercriminal activities.

Source: https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/

Views: 4