Skip to content
← Back to newsSafeWallet Unveils Detailed Report on Bybit Hack After $1.4 Billion Breach
Security

SafeWallet Unveils Detailed Report on Bybit Hack After $1.4 Billion Breach

By ToTo BugelmanNewcomer0 rep· 3/7/2025

In a significant development following the $1.4 billion hack of cryptocurrency exchange Bybit, SafeWallet has released a comprehensive post-mortem report. The report outlines the cybersecurity breach that occurred in February, revealing the methods used by the hackers and the subsequent actions taken by SafeWallet to enhance security measures.

 

Key Takeaways

  • The hack was executed by a North Korean state-sponsored group.

  • Hackers exploited a developer's Amazon Web Services (AWS) session tokens.

  • Multi-factor authentication (MFA) was bypassed through compromised credentials.

  • SafeWallet has implemented additional security measures post-incident.

 

Overview of the Hack

According to the forensic analysis conducted by SafeWallet in collaboration with cybersecurity firm Mandiant, the breach was meticulously planned over a span of 19 days. The attackers hijacked AWS session tokens belonging to a SafeWallet developer, allowing them to circumvent the MFA protections that were in place.

The report indicates that the AWS settings required developers to reauthenticate their session tokens every 12 hours. This requirement prompted the hackers to attempt to register a new MFA device. After several unsuccessful attempts, they compromised the developer's MacOS system, likely through malware, and utilized the active AWS session tokens to gain access.

 

A timeline of the Safe developer security exploit: Safe

 

Attack Execution

Once inside the AWS environment, the hackers set up the infrastructure necessary for the attack. The breach not only highlights vulnerabilities in the security protocols of SafeWallet but also raises concerns about the broader implications for the cryptocurrency industry.

 

Response and Recovery

In the aftermath of the hack, the FBI issued an alert to node operators, advising them to block transactions from wallet addresses associated with the North Korean hackers. This proactive measure aims to prevent the laundering of the stolen funds, which included nearly 500,000 Ether-related tokens.

 

FBI warning about North Korean hackers behind Bybit hack: FBI

 

Bybit's CEO, Ben Zhou, reported that approximately 77% of the stolen funds, valued at around $1.07 billion, remain traceable on-chain, while about $280 million have become untraceable. Cybersecurity experts, including Deddy Lavid from Cyvers, believe that there may still be opportunities to trace and potentially freeze some of the stolen assets.

 

Enhanced Security Measures

In light of the breach, SafeWallet has taken significant steps to bolster its security framework. The development team has implemented additional safeguards to protect against similar attacks in the future. The incident serves as a stark reminder of the vulnerabilities that exist within the cryptocurrency ecosystem and the need for continuous improvement in security practices.

As the cryptocurrency landscape evolves, the lessons learned from the Bybit hack will likely influence security protocols across the industry, emphasizing the importance of robust cybersecurity measures to protect digital assets.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

SafeWallet Unveils Detailed Report on Bybit Hack After $1.4 Billion Breach | BlockzHub