Telegram (AI) YouTube Facebook X
Ру
Safe Infrastructure Vulnerability Blamed for Bybit Breach

Safe Infrastructure Vulnerability Blamed for Bybit Breach

The attack on Bybit was executed through the Safe (Wallet) infrastructure, rather than the trading platform’s own systems, according to a preliminary incident report.

According to an investigation by analysts at Sygnia, the perpetrator injected malicious JavaScript code into Safe (Wallet) resources stored in the AWS S3 cloud.

The criminals’ script was activated only during transactions involving Bybit’s contract addresses and an unknown test address, indicating the targeted nature of the attack.

Snimok-ekrana-2025-02-26-v-18.51.38
Fragment of the malicious code. Source: Sygnia report.

Two minutes after the asset theft, the hacker replaced the modified files with the original versions to cover their tracks.

Cached files with changes made on February 19 were found on the devices of three participants who signed the fake transaction. The code manipulated data at the time of approval, substituting the recipient’s address.

Snimok-ekrana-2025-02-26-v-18.45.59
Malicious files in the Chrome browser cache of signatories. Source: Sygnia report.

Web archives like WaybackMachine also recorded changes to the Safe (Wallet) infrastructure code.

Snimok-ekrana-2025-02-26-v-18.54.43
Fragment of the malicious code captured in a WaybackMachine snapshot from February 19. Source: Sygnia report.

“The forensic investigation results from the hosts of the three signatories indicate that the root cause of the attack is the malicious code originating from the Safe (Wallet) infrastructure. No signs of compromise were found in Bybit’s infrastructure. The investigation continues for final confirmation of the findings,” the conclusion states.

Previously, cypherpunk Adam Back cited the “flawed EVM design” as the reason for the incident.

By February 26, hackers had laundered 135,000 ETH (~$335 million). Responsibility for the attack was attributed to the North Korean group Lazarus.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK