Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack

Share This Post

Safe published a preliminary report on Mar. 6 attributing the breach that led to the Bybit hack to a compromised developer laptop. The vulnerability resulted in the injection of malware, which allowed the hack.

The perpetrators circumvented multi-factor authentication (MFA) by exploiting active Amazon Web Services (AWS) tokens, enabling unauthorized access.

This allowed hackers to modify Bybit’s Safe multi-signature wallet interface, changing the address to which the exchange was supposed to send roughly $1.5 billion worth of Ethereum (ETH), resulting in the largest hack in history.

Compromise of developer workstation

The breach originated from a compromised macOS workstation belonging to a Safe developer, referred to in the report as “Developer1.”

On Feb. 4, a contaminated Docker project communicated with a malicious domain named “getstockprice[.]com,” suggesting social engineering tactics. Developer 1 added files from the compromised Docker project, compromising their laptop.

The domain was registered via Namecheap on Feb. 2. SlowMist later identified getstockprice[.]info, a domain registered on Jan. 7, as a known indicator of compromise (IOC) attributed to the Democratic People’s Republic of Korea (DPRK). 

Attackers accessed Developer 1’s AWS account using a User-Agent string titled “distrib#kali.2024.” Cybersecurity firm Mandiant, tracking UNC4899, noted that this identifier corresponds to Kali Linux usage, a toolset commonly used by offensive security practitioners. 

Additionally, the report revealed that the attackers used ExpressVPN to mask their origins while conducting operations. It also highlighted that the attack resembles previous incidents involving UNC4899, a threat actor associated with TraderTraitor, a criminal collective allegedly tied to DPRK. 

In a prior case from September 2024, UNC4899 leveraged Telegram to manipulate a crypto exchange developer into troubleshooting a Docker project, deploying PLOTTWIST, a second-stage macOS malware that enabled persistent access.

Exploitation of AWS security controls

Safe’s AWS configuration required MFA re-authentication for Security Token Service (STS) sessions every 12 hours. Attackers attempted but failed to register their own MFA device. 

To bypass this restriction, they hijacked active AWS user session tokens through malware planted on Developer1’s workstation. This allowed unauthorized access while AWS sessions remained active.

Mandiant identified three additional UNC4899-linked domains used in the Safe attack. These domains, also registered via Namecheap, appeared in AWS network logs and Developer1’s workstation logs, indicating broader infrastructure exploitation.

Safe said it has implemented significant security reinforcements following the breach. The team has restructured infrastructure and bolstered security far beyond pre-incident levels. Despite the attack, Safe’s smart contracts remain unaffected.

Safe’s security program included measures such as restricting privileged infrastructure access to a few developers, enforcing separation between development source code and infrastructure management, and requiring multiple peer reviews before production changes.

Moreover, Safe vowed to maintain monitoring systems to detect external threats, conduct independent security audits, and utilize third-party services to identify malicious transactions.

The post Safe’s internal investigation reveals developer’s laptop breach led to Bybit hack appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

XRP Price Ready To Bounce Back Above $3 If Bulls Can Hold This Level

The XRP price is getting ready to surge to new highs as bulls attempt to hold a critical resistance level Recently, the cryptocurrency experienced a major breakdown as market downside pressure

Report: Belarus Eyes Cryptocurrency Mining to Harness Nuclear Surplus

Belarus is reportedly exploring cryptocurrency mining using surplus nuclear energy, following economic strategies pioneered by nations like Bhutan, according to a report by the Belarusian Telegraph

Bitcoin Adoption Growing Despite Volatility, But This Key Group Is Cashing Out

On-chain data shows the Bitcoin network is continuing to see adoption amid the volatility, except for one investor group that’s seeing a decline Bitcoin Addresses With 100+ BTC Are Shrinking In

Texas senate passes bill enabling Bitcoin investments with public funds

Texas has moved a step closer to holding Bitcoin (BTC) as a reserve asset, with the state senate passing a bill on March 6 that would allow public funds to be allocated to digital assets The decision

Brazilian Soccer Legend Ronaldinho Launches STAR10 Token

Ronaldinho states that STAR10, a token named after his jersey number in soccer, is his new and official token, set to be launched on the BNB Chain He has been involved in several crypto endeavors

Méliuz becomes first publicly-traded Brazilian company to invest in Bitcoin, allocates 10% of cash reserves

Méliuz, a publicly traded Brazilian company, has announced the acquisition of Bitcoin (BTC) equivalent to 10% of its cash holdings, local media reported on AMarch 6 The company purchased 4572 BTC