By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: $1.4 Billion Crypto Heist Traced To Hackers Breaching Safe{Wallet}
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > $1.4 Billion Crypto Heist Traced To Hackers Breaching Safe{Wallet}
News

$1.4 Billion Crypto Heist Traced To Hackers Breaching Safe{Wallet}

News Room
Last updated: 2025/02/27 at 2:13 AM
News Room Published 27 February 2025
Share
SHARE

The suspected North Korean hackers who stole $1.4 billion in cryptocurrency from Bybit pulled off the heist by infiltrating a digital wallet provider and tampering with its software. 

The hackers targeted Safe{Wallet}, a provider of secure cryptocurrency wallets, including for Bybit. The attackers did so by first compromising the credentials of a Safe Developer, and then injecting malicious Javascript code a Safe{Wallet} system, according to Bybit. 

“This allowed the attacker to gain unauthorized access to the Safe(Wallet) infrastructure and totally deceive signers into approving a malicious transaction,” the cryptocurrency exchange said in a statement. 


This Tweet is currently unavailable. It might be loading or has been removed.

The findings partly come from two cybersecurity agencies that Bybit hired to investigate the attack, which has been linked to the North Korean hacking group Lazarus. On Wednesday, Bybit’s CEO Ben Zhou published the two preliminary forensic reports after announcing $140 million in bounty rewards to help it trace and freeze the stolen funds.  

The hackers were able to steal the funds from an offline “cold wallet” carrying the cryptocurrency, even though the same wallet required multiple private keys to execute a transaction. The forensic investigation found traces of the hack by examining the computers for the three Bybit employees that signed the fraudulent transaction. A closer look at the Chrome browsers’ cache files indicated the existence of the malicious Javascript code coming from Safe{Wallet}’s IT infrastructure over the app.safe.global domain.

The hackers seem to have deployed their attack last Tuesday and Wednesday. The malicious Javascript code could secretly modify the “executeTransaction and signTransaction call” for a cryptocurrency transaction, sending the funds to the attacker’s desired address.   

“After the transaction has been executed or signed, the original transaction data is restored, either by updating the result (in the sign-transaction case) or the transaction object (in both cases), ensuring the tampering remains hidden from subsequent processing,” says the forensic report from Verichains, a financial security firm. 

“The payload was designed to activate only when certain conditions were met. This selective execution ensured that the backdoor remained undetected by regular users while compromising high-value targets,” Verichains added. 

The hackers were also quick to delete the malicious Javascript code from Safe{Wallet} system after stealing the cryptocurrency. “The investigation determined that the JavaScript resources were modified in the AWS S3 bucket on February 21, 2025, at 14:15:13 and 14:15:32 UTC – approximately two minutes after the malicious transaction was executed,” the forensic report from the cybersecurity provider Sygnia said.

Recommended by Our Editors

(CFOTO/Future Publishing via Getty Images)

 It’s unclear how the hackers breached Safe{Wallet}. For now, the cryptocurrency wallet provider reports the attackers were able to compromise a “Safe{Wallet} developer machine which affected an account operated by Bybit.” 

“The Safe{Wallet} team has fully rebuilt, reconfigured all infrastructure, and rotated all credentials, ensuring the attack vector is fully eliminated,” it added. “The forensic review of external security researchers did NOT indicate any vulnerabilities in the Safe smart contracts or source code of the frontend and services.” 

Meanwhile, Bybit said it “moved the majority of funds” out of its Safe{Wallet} administered addresses on the day of the hack. The company has also received a huge loan to help it recover from the $1.4 billion lost in Ethereum.

Newsletter Icon

Like What You’re Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links.
By clicking the button, you confirm you are 16+ and agree to our
Terms of Use and
Privacy Policy.
You may unsubscribe from the newsletters at any time.

Newsletter Pointer

About Michael Kan

Senior Reporter

Michael Kan

I’ve been working as a journalist for over 15 years—I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017.

Read Michael’s full bio

Read the latest from Michael Kan

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Chinese GPU firm MetaX plans to lay off 200 employees ahead of IPO launch · TechNode
Next Article Building a Community Around Your Brand on Social Media
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The HackerNoon Newsletter: Vue.js: Propagating Props Like a Pro (5/10/2025) | HackerNoon
Computing
N26 also sells mobile plans
Mobile
Apple’s latest iPad just dropped to its lowest-ever price — score it for under $280
News
Meituan’s KeeTa tops Hong Kong market by order numbers · TechNode
Computing

You Might also Like

News

Apple’s latest iPad just dropped to its lowest-ever price — score it for under $280

2 Min Read
News

5 reasons why I can’t ditch my Apple Watch for Android smartwatches

11 Min Read
News

Review: Anker’s compact 25,000mAh battery bank is top-notch for powering Apple devices – 9to5Mac

3 Min Read
News

Secret ancient papal palace where Popes lived before the Vatican is unearthed

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?