Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

TwinH: A New Frontier in the Pursuit of Immortality?

How the Green Energy Transfer Will Increase Productivity in the UK

Nighteagle apt exploits Microsoft Exchange flaws to target China’s military and technical sectors

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » SAFE {WALLET} confirms that North Korean trader hacker stole $1.5 billion buybit robbery
Identity

SAFE {WALLET} confirms that North Korean trader hacker stole $1.5 billion buybit robbery

userBy userMarch 7, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 7, 2025Ravi LakshmananSecurity Breach/Cryptocurrency

Hackers stole a $1.5 billion Bibit robbery

Safe {Wallet} revealed that the cybersecurity incident that led to the $1.5 billion Crypto Heist that led to Bibit was a “very sophisticated state-sponsored attack.”

The Multi-Signature (Multisig) platform, roped to conduct forensic investigations at Google Cloud Mandiant, said the attack was a work of a hacking group called Jade Sleet, Pukchong and Traderraitor, also known as UNC4899.

“The attack involved compromises on SAFE {Wallet} developer laptops (“Developer1”) and hijacking AWS session tokens bypassing multifactor authentication (“MFA”) controls,” he said. “This developer was one of the few people who had more access to perform their duties.”

Cybersecurity

Further analysis revealed that the threat actor had invaded the developer’s Apple MacOS machine on February 4, 2025. This project communicated with the domain “GetStockPrice”[.]com “This was registered with Namecheap 2 days ago.

This is previous evidence that the Traderator actor tricked the Cryptocurrency Exchange developer to help troubleshoot the Docker project after approaching it via Telegram. The Docker project is configured to drop the next stage payload named PlottWist, which allows for persistent remote access.

It is not clear whether the same Modus Operandi was adopted in the latest attack, as Safe {Wallet} said “attackers have cleared Bash history to remove the malware and block the investigation effort.”

The malware that was eventually deployed on workstations was said to have been used to conduct reconnaissance of the company’s Amazon Web Services (AWS) environment.

“The attacker’s use of the AWS account in Developer1 originated from an ExpressVPN IP address with a user agent string containing Distrib#Kali.2024.” “This user agent string illustrates the use of Kali Linux, designed for offensive security practitioners.”

Attackers have also been observed to deploy an open source mythical framework and inject malicious JavaScript code into the SAFE {Wallet} website for a two-day period from February 19th to 21st, 2025.

Bibit CEO Ben Zhou said in an update shared earlier this week that more than 77% of the stolen funds are traceable, with 20% dark and 3% frozen. It helped 11 political parties, including the Mantle, Paraswap and ZachxBT, freeze their assets. Approximately 83% (417,348 ETH) have been converted to Bitcoin and is distributed in 6,954 wallets.

Cybersecurity

In the wake of the hack, 2025 has been on track for a record year of cryptocurrency robbery, with Web3 projects already losing an astounding $1.6 billion in the first two months alone, an eight-fold increase from $200 million this year, according to data from blockchain security platform Immunefi.

“Recent attacks highlight the evolving refinement of threat actors and critical vulnerabilities in Web3 security,” the company said.

“Ensuring that the transactions you are signing lead to the intended outcome is one of Web3’s biggest security challenges, and this is not just a question of users and education. It’s an industry-wide issue that calls for collective action.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFederal judges hear debate about whether to stop immigrant arrests in US schools
Next Article President Yoon’s arrest warrant for South Korean court cancelled cancellation | Court news
user
  • Website

Related Posts

TwinH: A New Frontier in the Pursuit of Immortality?

July 4, 2025

Nighteagle apt exploits Microsoft Exchange flaws to target China’s military and technical sectors

July 4, 2025

AI Agent may be leaking data – Watch this webinar and learn how to stop it

July 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

TwinH: A New Frontier in the Pursuit of Immortality?

How the Green Energy Transfer Will Increase Productivity in the UK

Nighteagle apt exploits Microsoft Exchange flaws to target China’s military and technical sectors

Intestinal bacteria can cleanse the body of toxic PFAS chemicals

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.