home.social

#safewallet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #safewallet, aggregated by home.social.

  1. Safe Axes 14 Staff as $1.43B Bybit Hack Fallout Triggers Radical Reorg - Months after one of the largest crypto-related thefts in recent history shook the ... - cryptonews.com/news/safe-cut-1 #safewallet #bybithack #definews #news

  2. #NorthKorea has finished laundering all of the $1.4 billion worth of crypto it stole from #Bybit into other tokens almost entirely through #ThorChain who made $5.5 million in fees on the laundering effort 👏🏼👏👏🏾.

    x.com/benbybit/status/18967984

    #LazarusGroup #moneylaundering #crime #Infosec #cybersecurity #DPRK #SafeWallet

  3. this interview w/one of the only #cybersecurity people in the crypto industry who has any idea what he's talking about goes through all the incredible failures at every level of both #Bybit & #SafeWallet (whose main product is #GnosisSafe, AKA "the most important smart contract in the industry"), from the most basic opsec to permissioning to whatever, is a fun time if you're interested in that kind of thing.

    tl;dr the whole crypto industry is an absolute clown car. a clown car that stores $1.4 billion in a single account that the entire C-suite can access.

    youtube.com/watch?v=W82FxAK9Ac

    #infosec #LazarusGroup #NorthKorea #DPRK #crypto

  4. #Bybit released the conclusions of their investigation into how they got rekt for $1.4 billion by North Korea's #LazarusGroup. Summary:

    1. (background) Bybit were dumb enough to store billions of dollars in a single wallet contract using software from a company called SafeWallet (a "Gnosis Safe")

    2. A dev machine of SafeWallet (name is lol) was compromised by Lazarus and used to access SafeWallet's cloud data stores (S3)

    3. malicious JavaScript was pushed to the cloud drive and eventually distributed in a release (?).

    4. The malicious JavaScript code targeted specifically the Bybit contract address to change the content of the transaction during the signing / approval process.

    * Bybit reports: docsend.com/view/s/rmdi832mpt8
    * Full Statement from SafeWallet: x.com/safe/status/189476852272

    in a normal world Bybit could probably sue SafeWallet, but I'm sure SafeWallet barely exists as an entity.

    #infosec #cybersecurity #safewallet #gnosissafe #ethereum #DPRK #NorthKorea #crime #hackers #blackhat

  5. Hacker Drains Over $2 Million from Safe Wallet- What’s Going On? - Source: Pixabay
    A malicious actor has stolen over $2 million from Safe Wallet user... - cryptonews.com/news/hacker-dra #blockchainnews #scamsniffer #safewallet #$2million #$5million #scam