Monday, November 24, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack

by DigestWire member
March 6, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Safe published a preliminary report on Mar. 6 attributing the breach that led to the Bybit hack to a compromised developer laptop. The vulnerability resulted in the injection of malware, which allowed the hack.

The perpetrators circumvented multi-factor authentication (MFA) by exploiting active Amazon Web Services (AWS) tokens, enabling unauthorized access.

This allowed hackers to modify Bybit’s Safe multi-signature wallet interface, changing the address to which the exchange was supposed to send roughly $1.5 billion worth of Ethereum (ETH), resulting in the largest hack in history.

Compromise of developer workstation

The breach originated from a compromised macOS workstation belonging to a Safe developer, referred to in the report as “Developer1.”

On Feb. 4, a contaminated Docker project communicated with a malicious domain named “getstockprice[.]com,” suggesting social engineering tactics. Developer 1 added files from the compromised Docker project, compromising their laptop.

The domain was registered via Namecheap on Feb. 2. SlowMist later identified getstockprice[.]info, a domain registered on Jan. 7, as a known indicator of compromise (IOC) attributed to the Democratic People’s Republic of Korea (DPRK). 

Attackers accessed Developer 1’s AWS account using a User-Agent string titled “distrib#kali.2024.” Cybersecurity firm Mandiant, tracking UNC4899, noted that this identifier corresponds to Kali Linux usage, a toolset commonly used by offensive security practitioners. 

Additionally, the report revealed that the attackers used ExpressVPN to mask their origins while conducting operations. It also highlighted that the attack resembles previous incidents involving UNC4899, a threat actor associated with TraderTraitor, a criminal collective allegedly tied to DPRK. 

In a prior case from September 2024, UNC4899 leveraged Telegram to manipulate a crypto exchange developer into troubleshooting a Docker project, deploying PLOTTWIST, a second-stage macOS malware that enabled persistent access.

Exploitation of AWS security controls

Safe’s AWS configuration required MFA re-authentication for Security Token Service (STS) sessions every 12 hours. Attackers attempted but failed to register their own MFA device. 

To bypass this restriction, they hijacked active AWS user session tokens through malware planted on Developer1’s workstation. This allowed unauthorized access while AWS sessions remained active.

Mandiant identified three additional UNC4899-linked domains used in the Safe attack. These domains, also registered via Namecheap, appeared in AWS network logs and Developer1’s workstation logs, indicating broader infrastructure exploitation.

Safe said it has implemented significant security reinforcements following the breach. The team has restructured infrastructure and bolstered security far beyond pre-incident levels. Despite the attack, Safe’s smart contracts remain unaffected.

Safe’s security program included measures such as restricting privileged infrastructure access to a few developers, enforcing separation between development source code and infrastructure management, and requiring multiple peer reviews before production changes.

Moreover, Safe vowed to maintain monitoring systems to detect external threats, conduct independent security audits, and utilize third-party services to identify malicious transactions.

The post Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
David Sacks laments US government’s sale of Bitcoin

David Sacks laments US government’s sale of Bitcoin

Whale Pressure Drops as Ethereum Faces Sharp Decline: Here’s the Impact on ETH Price

Whale Pressure Drops as Ethereum Faces Sharp Decline: Here’s the Impact on ETH Price

Mt. Gox Stirs The Market With $1 Billion Bitcoin Transfer—What’s Going On?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Marseille v Newcastle: Line-ups, stats and preview

Taylor Swift Wore The lululemon Leggings That Have Over 3K Five-Star Reviews

If You Have to Watch 1 Prime Video Show in November 2025, Stream This 1 Now

RHOC’s Meghan King Shares Post About ‘Human Rights’ Amid Custody Drama

‘Fortnite Festival’ Sets LISA as Season 12 Icon

Hugh Jackman on Wolverine Return: ‘I Am Never Saying Never Again’

Trending

Jake Paul vs Anthony Joshua: Fight date, TV channel, live online stream, boxing tickets and venue
Football

Jake Paul vs Anthony Joshua: Fight date, TV channel, live online stream, boxing tickets and venue

by DigestWire member
November 24, 2025
0

Jake Paul will fight Anthony Joshua

TV Premier League fixtures: December 2025 and early January 2026 full schedule including channels, live online streams, kick-off times over Christmas and New Year

TV Premier League fixtures: December 2025 and early January 2026 full schedule including channels, live online streams, kick-off times over Christmas and New Year

November 24, 2025
TV Premier League fixtures: November 2025 full schedule including channels, live online streams, kick-off times

TV Premier League fixtures: November 2025 full schedule including channels, live online streams, kick-off times

November 24, 2025
Marseille v Newcastle: Line-ups, stats and preview

Marseille v Newcastle: Line-ups, stats and preview

November 24, 2025
Taylor Swift Wore The lululemon Leggings That Have Over 3K Five-Star Reviews

Taylor Swift Wore The lululemon Leggings That Have Over 3K Five-Star Reviews

November 24, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Jake Paul vs Anthony Joshua: Fight date, TV channel, live online stream, boxing tickets and venue November 24, 2025
  • TV Premier League fixtures: December 2025 and early January 2026 full schedule including channels, live online streams, kick-off times over Christmas and New Year November 24, 2025
  • TV Premier League fixtures: November 2025 full schedule including channels, live online streams, kick-off times November 24, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.