BTC PULSE
No Result
View All Result
Play Now
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

SafeWallet Releases Bybit Hack Post-Mortem Report, Calls for UI/UX Security Improvements

by Dan K
Mar 6, 2025 - 10:47 pm
in Blockchain
Bank building with closed sign symbolizing continued crypto debanking in the US

SafeWallet Bybit Hack Post-Mortem Report

SafeWallet has published a post-mortem report analyzing the $1.4 billion Bybit hack, calling for enhanced security measures in UI/UX to protect against future attacks.

How the Attack Unfolded

SafeWallet and cybersecurity company Mandiant outline how the attackers compromised Bybit’s systems by taking over a Safe developer’s Amazon Web Services (AWS) session tokens, which allowed them to compromise the company’s multifactor authentication (MFA) security controls.

SafeWallet’s AWS policies were set to reauthenticate every 12 hours. The attackers attempted to register an MFA device multiple times but failed. They then breached a developer’s MacOS system—likely through malware—enabling them to use AWS session tokens as long as the developer’s sessions remained active.

Once inside AWS, the hackers methodically mounted their attack, leveraging cloud-based security weaknesses to gain unauthorized access.

North Korean Hackers Behind the Attack

Mandiant’s forensic analysis confirmed that the attackers were state-sponsored North Korean hackers. They spent 19 days planning the attack before executing the breach.

Despite the scale of the exploit, SafeWallet assured that its smart contracts remained intact. The company has since incorporated additional security protocols to prevent such an occurrence.

FBI Issues Warning as Hackers Launder Stolen Funds

The US Federal Bureau of Investigation (FBI) issued a public advisory, requesting node operators to halt transactions from wallet addresses linked to the North Korean hackers. The government agency cautioned that the stolen coins would be laundered and exchanged for fiat.

Bybit hackers successfully laundered 100% of the stolen crypto within 10 days—nearly 500,000 Ether-based tokens. Bybit CEO Ben Zhou noted that 77% of the funds worth about $1.07 billion are yet to be tracked on-chain, and some $280 million have disappeared into untouchable transactions.

Security experts like Cyvers CEO Deddy Lavid are of the view that a possibility still remains to track and freeze some of the stolen funds despite the fast pace of the laundering process.

As the crypto sector faces growing cyber attacks, SafeWallet’s report brings into focus the need to tighten security measures, especially within cloud-based systems.

Tags: BlockchainRegulation
Dan K

Dan K

Dan K, the chief editor, is a visionary wordsmith, shaping narratives with finesse. His discerning eye for detail creates literary masterpieces.

Related Posts

Arthur Hayes speaking about Bitcoin as Japan’s new Prime Minister announces economic stimulus measures

Arthur Hayes Predicts $1M Bitcoin as Japan’s New PM Unveils Economic Stimulus

October 22, 2025

Arthur Hayes predicts Bitcoin could hit $1M as Japan’s new PM Sanae Takaichi launches economic stimulus, signaling potential...

blockchain

Bolivia’s President-Elect Rodrigo Paz Turns to Blockchain to Fight Corruption

October 20, 2025

Bolivia’s new president Rodrigo Paz plans to use blockchain in public procurement and crypto asset declarations as part...

Metaplanet and Bitcoin Magazine logos, symbolizing their new partnership to expand operations in Japan.

Japan Moves Toward Allowing Banks to Buy Bitcoin Under New Regulatory Framework

October 19, 2025

Japan’s regulators are reviewing changes that could let banks buy and hold Bitcoin, signaling a major shift in...

24H HOLD token price chart showing 35% surge despite market pullback

Crypto markets surge as Trump confirms October 31 summit with Xi Jinping

October 19, 2025

Crypto markets rebound after Trump confirms October 31 summit with Xi Jinping, easing US-China tensions and sparking optimism...

View All
BTC-Pulse LogoTransparent

© 2024 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

©2024 BTC-PULSE – All right Reserved.

No Result
View All Result
  • About Us
  • Advertise
  • BTC-PULSE
  • Contact Us
  • Events
  • Privacy Policy
  • Sitemap
  • Terms of Service