By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist
Tech News

Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 07, 2025Ravie LakshmananSecurity Breach / Cryptocurrency

Hackers Stole $1.5 Billion in Bybit Heist

Safe{Wallet} has revealed that the cybersecurity incident that led to the Bybit $1.5 billion crypto heist is a “highly sophisticated, state-sponsored attack,” stating the North Korean threat actors behind the hack took steps to erase traces of the malicious activity in an effort to hamper investigation efforts.

The multi-signature (multisig) platform, which has roped in Google Cloud Mandiant to perform a forensic investigation, said the attack is the work of a hacking group dubbed TraderTraitor, which is also known as Jade Sleet, PUKCHONG, and UNC4899.

“The attack involved the compromise of a Safe{Wallet} developer’s laptop (‘Developer1’) and the hijacking of AWS session tokens to bypass multi-factor authentication (‘MFA’) controls,” it said. “This developer was one of the very few personnel that had higher access in order to perform their duties.”

Cybersecurity

Further analysis has determined that the threat actors broke into the developer’s Apple macOS machine on February 4, 2025, when the individual downloaded a Docker project named “MC-Based-Stock-Invest-Simulator-main” likely via a social engineering attack. The project communicated with a domain “getstockprice[.]com” that was registered on Namecheap two days before.

This is prior evidence indicating that the TraderTraitor actors have tricked cryptocurrency exchange developers into helping troubleshoot a Docker project after approaching them via Telegram. The Docker project is configured to drop a next-stage payload named PLOTTWIST that enables persistent remote access.

It’s not clear if the same modus operandi was employed in the latest attacks, as Safe{Wallet} said “the attacker removed their malware and cleared Bash history in an effort to thwart investigative efforts.”

Ultimately, the malware deployed to the workstation is said to have been utilized to conduct reconnaissance of the company’s Amazon Web Services (AWS) environment and hijack active AWS user sessions to perform their own actions aligning with the developer’s schedule in an attempt to fly under the radar.

“The attacker use of Developer1’s AWS account originated from ExpressVPN IP addresses with User-Agent strings containing distrib#kali.2024,” it said. “This User-Agent string indicates use of Kali Linux which is designed for offensive security practitioners.”

The attackers have also been observed deploying the open-source Mythic framework, as well as injecting malicious JavaScript code to the Safe{Wallet} website for a two-day period between February 19 and 21, 2025.

Bybit CEO Ben Zhou, in an update shared earlier this week, said over 77% of the stolen funds remain traceable, and that 20% have gone dark and 3% have been frozen. It credited 11 parties, including Mantle, Paraswap, and ZachXBT, for helping it freeze the assets. About 83% (417,348 ETH) has been converted into bitcoin, distributing it across 6,954 wallets.

Cybersecurity

In the wake of the hack, 2025 is on track for a record year for cryptocurrency heists, with Web3 projects already losing a staggering $1.6 billion in the first two months alone, an 8x increase from the $200 million this time last year, according to data from blockchain security platform Immunefi.

“The recent attack underscores the evolving sophistication of threat actors and highlights critical vulnerabilities in Web3 security,” the company said.

“Verifying that the transaction you are signing will result in the intended outcome remains one of the biggest security challenges in Web3, and this is not just a user and education problem — it is an industry-wide issue that demands collective action.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Phomemo PM64D: The New Generation Touchscreen Shipping Label Printer Balancing Speed and Portability

OnePlus 15 vs Pixel 10 Pro Review: Which Phone is Better?

Enterprise Ireland leads Irish Tech Delegation Targets Nordic Growth and VC Funding at Slush 2025

Gemini 3 Is Here—and Google Says It Will Make Search Smarter

Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale

TAGGED: AWS security, Blockchain, cryptocurrency, Cyber Security, Cybersecurity, data breach, hacking, Internet, Malware, North Korea, web3
Share This Article
Facebook Twitter Copy Link
Previous Article The Truth About ChatGPT-4.5: Features, Flaws and What’s Coming
Next Article QR supermarket price revolution: Will new label rules slash shopping bills?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Hyperliquid price soars on buybacks and BLP launch, but bearish patterns flash a warning
Crypto
Halo Infinite’s Final Content Update is Now Live As New Trailer Outlines Every “Infinite” Moment
Gaming News
Infosys' Rs 18,000 crore share buyback window to open on Nov 20. 5 things to know
Business
Buy Bitcoin Now? Not Yet, Says Blackbay Capital President
Crypto
Lebanon says Israeli strike killed 13 people near Palestinian refugee camp
World News
Key Epstein files vote passes US House in overwhelming 427–1 majority
World News
Phomemo PM64D: The New Generation Touchscreen Shipping Label Printer Balancing Speed and Portability
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Hyperliquid price soars on buybacks and BLP launch, but bearish patterns flash a warning

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Hyperliquid price soars on buybacks and BLP launch, but bearish patterns flash a warning
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?