Dubai-based cryptocurrency exchange Bybit said attackers had stolen more than 400,000 ETH and related tokens, worth about US$1.5bn, from one of its Ethereum cold wallets on 21 February. On 26 February the FBI attributed the theft to North Korea, in activity it tracks as TraderTraitor.
What happened
- The attackers manipulated a routine transfer from Bybit’s cold wallet so that its signers unknowingly approved a transaction that handed control of the wallet to the thieves.
- Investigators traced the compromise to a hacked developer machine at Safe{Wallet}, the multisignature wallet provider used by Bybit, where malicious code was injected into its web interface to target Bybit specifically.
- Bybit said it remained solvent, and within days its chief executive said the exchange had fully replenished its ETH reserves, partly through bridge loans and purchases.
- The FBI said the stolen funds were quickly converted and dispersed across thousands of addresses on multiple blockchains.
Why it mattered
It was widely reported as the largest cryptocurrency theft on record, underlining North Korea’s use of cybercrime to fund the state. It also showed that attackers increasingly target the suppliers and tools around exchanges rather than the exchanges directly.
Lessons for organisations
Signing and approval processes are only as strong as the tools that display what is being signed, so verify high-value transactions independently. Supplier risk assessments should include the security of third-party software in critical payment paths.
Sources: FBI (IC3), BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.