DeFi Daily News
Saturday, December 13, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Cryptocurrency Ethereum

rewrite this title Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack

Gino Matos by Gino Matos
March 6, 2025
in Ethereum
0 0
0
rewrite this title Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

Safe published a preliminary report on Mar. 6 attributing the breach that led to the Bybit hack to a compromised developer laptop. The vulnerability resulted in the injection of malware, which allowed the hack.

The perpetrators circumvented multi-factor authentication (MFA) by exploiting active Amazon Web Services (AWS) tokens, enabling unauthorized access.

This allowed hackers to modify Bybit’s Safe multi-signature wallet interface, changing the address to which the exchange was supposed to send roughly $1.5 billion worth of Ethereum (ETH), resulting in the largest hack in history.

Compromise of developer workstation

The breach originated from a compromised macOS workstation belonging to a Safe developer, referred to in the report as “Developer1.”

On Feb. 4, a contaminated Docker project communicated with a malicious domain named “getstockprice[.]com,” suggesting social engineering tactics. Developer 1 added files from the compromised Docker project, compromising their laptop.

The domain was registered via Namecheap on Feb. 2. SlowMist later identified getstockprice[.]info, a domain registered on Jan. 7, as a known indicator of compromise (IOC) attributed to the Democratic People’s Republic of Korea (DPRK). 

Attackers accessed Developer 1’s AWS account using a User-Agent string titled “distrib#kali.2024.” Cybersecurity firm Mandiant, tracking UNC4899, noted that this identifier corresponds to Kali Linux usage, a toolset commonly used by offensive security practitioners. 

Additionally, the report revealed that the attackers used ExpressVPN to mask their origins while conducting operations. It also highlighted that the attack resembles previous incidents involving UNC4899, a threat actor associated with TraderTraitor, a criminal collective allegedly tied to DPRK. 

In a prior case from September 2024, UNC4899 leveraged Telegram to manipulate a crypto exchange developer into troubleshooting a Docker project, deploying PLOTTWIST, a second-stage macOS malware that enabled persistent access.

Exploitation of AWS security controls

Safe’s AWS configuration required MFA re-authentication for Security Token Service (STS) sessions every 12 hours. Attackers attempted but failed to register their own MFA device. 

To bypass this restriction, they hijacked active AWS user session tokens through malware planted on Developer1’s workstation. This allowed unauthorized access while AWS sessions remained active.

Mandiant identified three additional UNC4899-linked domains used in the Safe attack. These domains, also registered via Namecheap, appeared in AWS network logs and Developer1’s workstation logs, indicating broader infrastructure exploitation.

Safe said it has implemented significant security reinforcements following the breach. The team has restructured infrastructure and bolstered security far beyond pre-incident levels. Despite the attack, Safe’s smart contracts remain unaffected.

Safe’s security program included measures such as restricting privileged infrastructure access to a few developers, enforcing separation between development source code and infrastructure management, and requiring multiple peer reviews before production changes.

Moreover, Safe vowed to maintain monitoring systems to detect external threats, conduct independent security audits, and utilize third-party services to identify malicious transactions.

Mentioned in this article

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website [http://defi-daily.com] and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: BreachBybitDevelopershackInternalInvestigationlaptopledRevealsrewriteSafestitle
ShareTweetShare
Previous Post

Why Google is urging the DOJ to slow break up efforts

Next Post

In 24 Hours… Crypto Changes FOREVER!!!

Next Post
In 24 Hours… Crypto Changes FOREVER!!!

In 24 Hours… Crypto Changes FOREVER!!!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
New Law Requires Large Retailers in New York State to Install Panic Buttons

New Law Requires Large Retailers in New York State to Install Panic Buttons

September 5, 2024
Lionel Messi and the Clear Feeling of an Approaching Closure

Lionel Messi and the Clear Feeling of an Approaching Closure

July 15, 2024
AI to Boost ‘So Much’ of Human Investing, Bridgewater’s Jensen Says

AI to Boost ‘So Much’ of Human Investing, Bridgewater’s Jensen Says

July 8, 2024
rewrite this title Asics' 'Life Changing' Running Shoe With the 'Perfect Blend' of Cushion and Energy Return Is Now Nearly 40% Off

rewrite this title Asics' 'Life Changing' Running Shoe With the 'Perfect Blend' of Cushion and Energy Return Is Now Nearly 40% Off

January 21, 2025
What Does the AI Boom Really Mean for Humanity? | The Future With Hannah Fry

What Does the AI Boom Really Mean for Humanity? | The Future With Hannah Fry

September 12, 2024
rewrite this title Bitcoin Miner Phoenix Group Posts 4 Million Loss and 54% Revenue Decline in Q1 2025

rewrite this title Bitcoin Miner Phoenix Group Posts $154 Million Loss and 54% Revenue Decline in Q1 2025

May 8, 2025
rewrite this title and make it good for SEO2026 S&P 500 Outlook: The Party Is Not Over (NYSEARCA:SPY)

rewrite this title and make it good for SEO2026 S&P 500 Outlook: The Party Is Not Over (NYSEARCA:SPY)

December 13, 2025
rewrite this title Barack Obama Surprises Chicago Choir Boys With Joyful Visit And Dance Moves | Celebrity Insider

rewrite this title Barack Obama Surprises Chicago Choir Boys With Joyful Visit And Dance Moves | Celebrity Insider

December 13, 2025
rewrite this title When Tiger Woods named MLB’s “Big Three” as the best celebrity golfers he has played with

rewrite this title When Tiger Woods named MLB’s “Big Three” as the best celebrity golfers he has played with

December 13, 2025
rewrite this title with good SEO Dogecoin Triangle Support Test Maps Out Recovery Roadmap And When To Sell

rewrite this title with good SEO Dogecoin Triangle Support Test Maps Out Recovery Roadmap And When To Sell

December 13, 2025
rewrite this title Ethereum Price Falls To ,000 As Taker Volume Spikes To New High — What’s Happening? | Bitcoinist.com

rewrite this title Ethereum Price Falls To $3,000 As Taker Volume Spikes To New High — What’s Happening? | Bitcoinist.com

December 13, 2025
rewrite this title Rivian wants your truck to talk back, and it’s happening in 2026

rewrite this title Rivian wants your truck to talk back, and it’s happening in 2026

December 13, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.