The fallout from the $1.5 billion Bybit cryptocurrency heist is becoming clearer, and it’s worse than initially feared. Safe{Wallet}, a platform offering secure multi-signature services for Web3 assets, has now confirmed that the attack was not only state-sponsored but also executed with surgical precision.

The culprit? A North Korea-linked hacking group known as TraderTraitor — also tracked as Jade Sleet, PUKCHONG, and UNC4899. This group has been tied to multiple previous crypto-focused breaches and is now being held responsible for one of the largest digital heists in history.

How the Attack Unfolded: From Docker to Developer

A Social Engineering Trap

According to Safe{Wallet}, the hackers tricked a developer into downloading a Trojanized Docker project disguised as a stock investment simulator. The infected file, named MC-Based-Stock-Invest-Simulator-main, was downloaded on February 4, 2025, from a site registered just two days earlier — a key indicator of a tailored attack.

This wasn’t random malware. It was specifically crafted to target the developer’s macOS system, compromise their credentials, and embed backdoors for remote access.

Targeting Developer1: A High-Privilege Victim

The victim, identified as Developer1, was one of the few with elevated privileges on the team — someone whose role granted broad AWS access. That made them a perfect target for gaining control over key systems.

After breaching the machine, the hackers used the stolen AWS session tokens to bypass multi-factor authentication (MFA). This allowed them to act as if they were the developer, carrying out malicious activity during working hours to avoid raising alarms.

From AWS Access to $1.5 Billion Gone

Moving Quietly Inside the Cloud

Once inside the AWS environment, the attackers:

  • Conducted cloud reconnaissance
  • Identified digital assets and access points
  • Hijacked active user sessions
  • Coordinated malicious activity with the developer’s real schedule

To avoid being caught, they wiped traces of the malware, deleted bash history logs, and used obfuscation tactics like routing through ExpressVPN IPs. Their user agent string (distrib#kali.2024) even pointed to the use of Kali Linux, a toolset widely used by penetration testers and cyber attackers alike.

JavaScript Injection on Safe{Wallet}

The hackers weren’t done. They injected malicious JavaScript into the Safe{Wallet} website itself between February 19 and 21, potentially compromising even more users during that window.

They also used the Mythic framework, an open-source toolkit designed for red team operations — further demonstrating how professional and adaptable this group is.

Bybit’s Response and the Aftermath

Assets Tracked, Some Frozen

Bybit CEO Ben Zhou confirmed the staggering scale of the breach and provided a breakdown of the stolen assets:

  • 77% of funds still traceable
  • 20% have disappeared (“gone dark”)
  • 3% have been frozen with help from industry partners

In total, 417,348 ETH (around 83% of the haul) has already been converted into bitcoin, then split across nearly 7,000 wallets, making recovery complex and slow.

Zhou credited 11 organizations, including Mantle, Paraswap, and blockchain investigator ZachXBT, for their rapid assistance in freezing stolen assets.

TraderTraitor: North Korea’s Crypto Crime Machine

A Familiar Tactic with New Wrinkles

The attack fits the pattern of TraderTraitor’s earlier campaigns. These hackers have a well-documented history of targeting developers in the crypto space, often using:

  • Fake job offers
  • Telegram chats with “tech collaborators”
  • Booby-trapped projects and shared tools

Their tool of choice for persistence in this attack was PLOTTWIST, a custom backdoor malware that enables remote control of infected machines.

While the exact infection vector this time remains unclear, Safe{Wallet} noted that signs point to a social engineering playbook—starting with that fake Docker project and ending with an empty audit trail.

Web3 Heists Surge: $1.6B Lost in Just Two Months

2025 Is Already a Record Year

With this incident, crypto theft in 2025 has already hit $1.6 billion — just two months into the year. That’s eight times more than the total for the same period in 2024.

According to blockchain security firm Immunefi, the spike reflects:

  • Increased sophistication of threat actors
  • Inadequate safeguards in some Web3 protocols
  • Poor transaction verification flows

The attack proves that multi-signature wallets, while more secure than basic wallets, are not invincible, especially when endpoint security is weak or when developers are manipulated.

Safe{Wallet} Calls for Industry-Wide Action

It’s Not Just a User Problem

Following the attack, Safe{Wallet} released a sobering statement:

“Verifying that the transaction you are signing will result in the intended outcome remains one of the biggest security challenges in Web3. And this is not just a user or education problem — it is an industry-wide issue.”

The platform is now working closely with Google Cloud’s Mandiant team to fully understand the breach, prevent future occurrences, and share its findings with the wider Web3 community.

How This Attack Highlights Critical Web3 Flaws

Security Weak Spots Exposed

This attack lays bare several ongoing issues in the crypto and DeFi space:

  • Session hijacking still bypasses MFA in many cloud environments
  • Developer endpoints remain vulnerable to social engineering
  • Widespread trust in “helpful” open-source projects leads to easy malware entry
  • Transaction previews and confirmations are still confusing to many users
  • Even “secure” wallets are only as safe as the machines they run on

FAQs

Who carried out the Bybit $1.5 billion heist?
A North Korean hacking group known as TraderTraitor, also referred to as Jade Sleet or UNC4899.

How did the hackers gain access?
They tricked a developer into downloading a malicious Docker project, compromised their macOS system, and hijacked active AWS sessions to move within the cloud.

Was multi-factor authentication bypassed?
Yes. By using stolen AWS session tokens, the hackers avoided MFA and acted as if they were the authorized user.

What tools were used in the attack?
Key tools included the PLOTTWIST malware, the Mythic framework, ExpressVPN, and JavaScript injection. The attackers also wiped logs to hinder investigation.

How much of the stolen crypto has been recovered?
Roughly 3% of the funds have been frozen, while 77% remains traceable. About 20% is currently unaccounted for.

What does this mean for crypto security in 2025?
This attack signals a new level of sophistication and volume in crypto crime. It shows that the industry must improve endpoint security, session protection, and transaction validation.

Author

Share.

196 Comments

  1. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  2. Tongits Online Real Money: Easy Login, Register & App Download for the Best Casino Slots in the Philippines. Experience Tongits online real money! Enjoy easy Tongits login, fast Tongits register, and the Tongits app download for the best casino slots in the Philippines. Play and win big today! visit: tongits

  3. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  4. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  5. Can you be more specific about the content of your article? After reading it, I still have some doubts. Hope you can help me.

  6. If you’re looking for a new place to play, 615betwin is worth checking out. They’ve got a solid selection and the site runs smoothly. Nothing too flashy, but gets the job done. See if you can win: 615betwin

  7. The 68winapp is surprisingly decent. Easy to download and install, and it’s pretty responsive. Great selection of games too, so definitely worth a look, especially if you prefer playing on your phone: 68winapp

  8. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  9. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  10. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  11. Honestly impressed by how much useful content sits in such a small post, and a stop at firstisnotequallast confirmed the rest of the site packs a similar punch, density without confusion is a hard balance to strike and this site has clearly cracked the code on it across many different topic areas covered.

  12. Hey! I know this is kind of off topic but I was wondering if you knew where I could locate a captcha plugin for my comment form? I’m using the same blog platform as yours and I’m having difficulty finding one? Thanks a lot!

  13. The aftermath—both the frozen assets and the involvement of multiple cybersecurity tools indicates just how serious this breach is. As Mầm Non Đồng Nai residents know, ensuring one’s safety and security often involves being vigilant against all threats, not just those from our local neighborhood but also those from across the globe. Chaudhary Quietly

  14. Chọn Trường Mầm Non Sài Gòn đã nhận được thông tin chính xác và cập nhật từ các nhà chức trách về vụ hacker truy quét 1 tỷ USD của BitBycoin. Sự cố này không chỉ gây ra mất mát về tài sản mà còn là một cuộc tấn công lớn đối với ngành công nghiệp tiền điện tử nói chung. penetration deleted

  15. Wow! This article has really sparked my interest in cybersecurity and crypto-heists. It’s incredible how such massive theft can be orchestrated through social engineering and custom-built malware. The mention of “Sổ tay mần non” is a perfect way to describe that precise, surgical execution. It’s like the attackers were well-prepared and took every step necessary to avoid detection. Ben Billion

  16. Mầm non hà nội, nơi đây luôn được biết đến với vẻ đẹp hoang sơ và bình yên của cuộc sống dân dã. Trải qua nhiều năm phát triển, Hà Nội vẫn giữ được nét cổ kính mà không hề thay đổi, từ những con đường vắng người đến những vườn tre xanh mướt. out Web

  17. 5 billion Bybit cryptocurrency heist orchestrated by North Korea-linked hackers. Mầm chòi Lá that this attack involved both state-sponsored and cybercriminal elements is a stark reminder of how global cybersecurity remains fragile, especially when it comes to blockchain technology. The surgical precision with which they targeted Developer1 highlights the sophistication of modern hackers, who now have more tools than ever before to breach even the most secure systems. Billion target

  18. I couldn’t believe how skilled these North Korea-linked hackers were in carrying out such a heist with surgical precision. It’s shocking to think that even major companies are not immune to cyber attacks from these talented cyber criminals. As someone who recently read about the data breach at Việt Nam Preschool Resourcces, I can appreciate just how dangerous this kind of attack really is. tricked compromising

  19. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  20. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  21. An fascinating dialogue is worth comment. I believe that you should write extra on this topic, it won’t be a taboo topic but usually people are not enough to speak on such topics. To the next. Cheers

  22. Fantastic blog! Do you have any tips for aspiring writers? I’m hoping to start my own blog soon but I’m a little lost on everything. Would you suggest starting with a free platform like WordPress or go for a paid option? There are so many choices out there that I’m completely confused .. Any tips? Thank you!

Leave A Reply

© 2026 ThemeSphere. Designed by ThemeSphere.
Exit mobile version