24/7 Cryptocurrency News

Bybit Hack Caused By Malicious Code In Safe Wallet’s Infrastructure: Report

A preliminary investigation into the Bybit hack reveals that the attack stemmed from compromised code within Safe Wallet’s infrastructure.
Published by
Bybit Hack Caused By Malicious Code In Safe Wallet’s Infrastructure: Report

Highlights

  • Bybit’s initial investigation into its hack points to a vulnerability from Safe Wallet.
  • The report says Bybit infrastructure remains uncompromised in the wake of the attack.
  • Concerted efforts are underway to recover stolen assets from the North Korean hacking syndicate.

Early reports point to a third-party vulnerability as Bybit tries to find the remote and immediate causes of its security breach. While the interim investigation has absolved the exchange of blame, experts say the hack may be mitigated with watertight guardrails.

Advertisement

Safe Wallet Vulnerability Triggered Bybit Hack

As Bybit reels from its jarring $1.5 billion hack, the company enlisted Web 3 security outfit Verichains and Sygnia Labs to investigate the breach. Company CEO Ben Zhou took to X to share the results of the interim investigation report, pointing to Safe Wallet as the source of the Bybit hack.

Per the document, the root cause of the Bybit hack from malicious code in the wallet’s infrastructure. Bad actors replaced the original JavaScript file of the app.safe.global with compromised code to target Bybit’s Ethereum Multisig Cold Wallet.

Preliminary investigations say the attack on the top exchange was scheduled to hit during the next Bybit transaction. Both Verichains and Sygnia Labs’ analysts say Safe Global AWS S3 and CloudFront accounts were likely targets for hackers.

The report cites Wayback Archives as proof of a “cached malicious file” given Google Search’s integrations of the service. Safe Wallet’s official statement also confirms the origin of the breach, pointing to a compromised Safe developer machine.

“Bybit remains steadfast in our commitment to security and transparency,” said Zhou. “The preliminary forensic review finds that our system was not compromised.”

Advertisement

A Concerted Effort Underway To Recover Funds And Protect Customers

In the hours following the attack, Bybit transferred the funds from its Safe Wallet to limit its damage. The exchange has frozen $42 million worth of stolen funds from attackers in a collaborative effort by industry players.

Zhou has announced a bounty hunt designed to stifle the Lazarus Group’s ability to cash out from the attack. A positive development confirms that the firm has acquired 100% of Ethereum lost in the hack via a raft of loans and OTC deals from industry giants like Galaxy Digital and Wintermute.

Advertisement

Share
Aliyu Pokima

Aliyu Pokima is a seasoned cryptocurrency and emerging technologies journalist with a knack for covering needle-moving stories in the space. Aliyu delivers breaking news stories, regulatory updates, and insightful analysis with depth and precision. When he's not poring over charts or following leads, Aliyu enjoys playing the bass guitar, lifting weights and running marathons.

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • 24/7 Cryptocurrency News

Cyber Hornet Seeks SEC Nod for S&P 500 and XRP ETF

Cyber Hornet has filed with the U.S. Securities and Exchange Commission (SEC) to launch a…

September 27, 2025
  • 24/7 Cryptocurrency News

Cathie Wood’s Ark Invest Eyes Stake in Tether as USDT Issuer Targets $500B Valuation

Tether Holdings is preparing for one of its biggest funding rounds, with two global investors…

September 26, 2025
  • 24/7 Cryptocurrency News

Kraken Secures $500M at $15B Valuation, Eyes IPO in 2026

Kraken raised $500 million, increasing its valuation to $15 billion, setting the stage for a…

September 26, 2025
  • 24/7 Cryptocurrency News

Bybit Lists Ripple’s RLUSD Following BlackRock and VanEck Integration

Crypto exchange Bybit has announced its listing of Ripple's RLUSD amid the stablecoin's growing adoption.…

September 26, 2025
  • 24/7 Cryptocurrency News

SWIFT Plans Stablecoin and On-Chain Messaging Pilot on Linea, Challenging Ripple

The world's largest interbank messaging network SWIFT has selected Ethereum layer 2 platform Linea to…

September 26, 2025
  • Bitcoin News

Breaking: U.S. PCE Inflation Rises To 2.7% YoY, Bitcoin Bounces

The August U.S. PCE inflation data has dropped in line with expectations, although it suggests…

September 26, 2025