"Bit ByBit - emulation of the DPRK's largest cryptocurrency heist" published by Elastic. #Bybit, #SafeWallet, #TraderTraitor, #DPRK, #CTI https://www.elastic.co/security-labs/bit-bybit
Bit ByBit - emulation of the DPRK's largest cryptocurrency heist — Elastic Security Labs

A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.

"Bybit – What Do We Know So Far" published by Sygnia. #Bybit, #SafeWallet, #DPRK, #CTI https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/
Sygnia’s Investigation into the Bybit Hack: What We Know So Far

Sygnia investigates the Bybit hack of February 2025, uncovering how attackers exploited security gaps across multiple domains. Learn key findings and lessons for the crypto industry.

Sygnia
"How North Korean hackers executed history’s biggest $1.5 billion crypto heist" published by BBC. #Bybit, #SafeWallet, #Youtube, #News, #DPRK, #CTI https://www.youtube.com/watch?v=gpLYnKC3mGk
How North Korean hackers stole $1.5 billion in crypto - BBC World Service

YouTube
"Lazarus Group Bybit Heist: C2 forensics" published by Validin. #Bybit, #SafeWallet, #Lazarus, #DPRK, #CTI https://www.validin.com/blog/bybit_hack_infrastructure_hunt/
Lazarus Group Bybit Heist: C2 forensics | Validin

An in-depth hunt for Lazarus APT group infrastructure related to the Bybit hack using Validin's host response and DNS databases.

Validin
"In-Depth Technical Analysis of the Bybit Hack" published by NCCGroup. #Bybit, #SafeWallet, #DPRK, #CTI https://www.nccgroup.com/us/research-blog/in-depth-technical-analysis-of-the-bybit-hack/
Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist

Bybit’s $1.5B crypto heist linked to North Korean hackers. 77% of funds remain traceable, while Web3 losses hit $1.6B in 2025

The Hacker News

#SafeWallet published the results of an investigation into #NorthKorea's theft of $1.4 billion worth of ethereum from #Bybit.

https://x.com/safe/status/1897663514975649938

#infosec #mandiant #cybersecurity #crypto #DPRK #TraderTraitor #LazarusGroup

Safe.eth (@safe) on X

Investigation Updates and Community Call to Action

X (formerly Twitter)
"Investigation Updates and Community Call to Action" published by Safe.eth. #Bybit, #SafeWallet, #UNC4899, #DPRK, #CTI https://archive.is/OxemM

#NorthKorea has finished laundering all of the $1.4 billion worth of crypto it stole from #Bybit into other tokens almost entirely through #ThorChain who made $5.5 million in fees on the laundering effort 👏🏼👏👏🏾.

https://x.com/benbybit/status/1896798476945744010

#LazarusGroup #moneylaundering #crime #Infosec #cybersecurity #DPRK #SafeWallet

Ben Zhou (@benbybit) on X

3.4.25 Executive Summary on Hacked Funds: Total hacked funds of USD 1.4bn around 500k ETH, 77% are still traceable, 20% has gone dark, 3% have been frozen. Breakdown: - 83% (417,348 ETH, ~$1B) have been converted into BTC with 6,954 wallets (Average 1.71 btc each) . This and

X (formerly Twitter)

this interview w/one of the only #cybersecurity people in the crypto industry who has any idea what he's talking about goes through all the incredible failures at every level of both #Bybit & #SafeWallet (whose main product is #GnosisSafe, AKA "the most important smart contract in the industry"), from the most basic opsec to permissioning to whatever, is a fun time if you're interested in that kind of thing.

tl;dr the whole crypto industry is an absolute clown car. a clown car that stores $1.4 billion in a single account that the entire C-suite can access.

https://www.youtube.com/watch?v=W82FxAK9Acg

#infosec #LazarusGroup #NorthKorea #DPRK #crypto

Bybit Should Have Checked the Hash - Unchained w/ Mudit Gupta

YouTube