{"id":15433,"date":"2025-02-28T02:32:29","date_gmt":"2025-02-28T02:32:29","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=15433"},"modified":"2025-02-28T02:32:29","modified_gmt":"2025-02-28T02:32:29","slug":"fbi-points-to-north-korean-hackers-in-1-5-billion-crypto-breach-at-bybit","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=15433","title":{"rendered":"FBI Points to North Korean Hackers in $1.5 Billion Crypto Breach at Bybit"},"content":{"rendered":"<div>\n<p data-pm-slice=\"1 1 []\">The Federal Bureau of Investigation has <a href=\"https:\/\/www.washingtonpost.com\/business\/2025\/02\/27\/bybit-exchange-crypto-hack-north-korea\/6bb55c12-f4da-11ef-acb5-08900d482a27_story.html\" target=\"_blank\" rel=\"noopener nofollow\">implicated<\/a> North Korean-backed hacking groups in a major cryptocurrency heist involving $1.5 billion in digital assets.<\/p>\n<p data-pm-slice=\"1 1 []\">The cyberattack targeted Bybit, a Dubai-based cryptocurrency exchange, making it one of the largest crypto thefts publicly known. This incident has drawn attention to North Korea\u2019s ongoing role in cyber-enabled financial crimes.<\/p>\n<h2 data-pm-slice=\"1 1 []\">FBI Blames North Korean Hackers for $1.5 Billion Crypto Heist<\/h2>\n<p data-pm-slice=\"1 1 []\">The hackers\u2014identified as TraderTraitor and the Lazarus Group\u2014allegedly deployed malware through modified cryptocurrency trading applications, allowing them to seize Ethereum and convert it into other cryptocurrencies, according to an FBI statement released on Wednesday.<\/p>\n<p data-pm-slice=\"1 1 []\">The stolen funds were rapidly <a href=\"https:\/\/bitcoinist.com\/bybit-hack-stolen-funds-likely-headed-to-mixers\/\" target=\"_blank\" rel=\"noopener \">transferred to thousands of wallet addresses<\/a> across multiple blockchains. The FBI suspects these assets will eventually be laundered and converted into fiat currency.<\/p>\n<p data-pm-slice=\"1 1 []\">While the North Korean government has not acknowledged the theft, reports from South Korea\u2019s intelligence agencies suggest that North Korea has stolen <a href=\"https:\/\/bitcoinist.com\/ethereum-dev-blockchain-rollback-amidst-bybit-hack\/\" target=\"_blank\" rel=\"noopener \">$1.2 billion in cryptocurrency<\/a> over the past five years.<\/p>\n<p data-pm-slice=\"1 1 []\">The Washington Post reporting this noted:<\/p>\n<blockquote>\n<p class=\"c-paragraph\">It represents a rare source of badly needed foreign currency to support its fragile economy and fund its nuclear program in the face of intense U.N. sanctions and North Korea\u2019s strict border closures during the coronavirus pandemic. A UN experts panel separately said it was investigating 58 suspected cyberattacks by North Korea between 2017 to 2023 that saw some $3 billion stolen to \u201creportedly help to fund the country\u2019s development of weapons of mass destruction.\u201d<\/p>\n<\/blockquote>\n<h2 data-pm-slice=\"1 1 []\">Bybit\u2019s Response and Industry Implications<\/h2>\n<p>Bybit\u2019s co-founder and CEO, Ben Zhou, addressed the FBI\u2019s accusations by linking to a site offering bounties to track and freeze the stolen assets.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"zxx\"><a href=\"https:\/\/t.co\/FTHW8gIsT9\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/FTHW8gIsT9<\/a> <a href=\"https:\/\/t.co\/SdxPifNHUG\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/SdxPifNHUG<\/a><\/p>\n<p>\u2014 Ben Zhou (@benbybit) <a href=\"https:\/\/twitter.com\/benbybit\/status\/1894957686418182594?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">February 27, 2025<\/a><\/p>\n<\/blockquote>\n<p>The exchange revealed that the attack involved a sophisticated exploit targeting their offline or \u201ccold\u201d wallets, which are generally considered more secure than online storage. According to blockchain analytics firm Certik, this breach ranks as the largest<a href=\"https:\/\/bitcoinist.com\/bybit-turns-to-bitget-and-binance-for-239-million-eth-loan-amid-withdrawal-spike\/\" target=\"_blank\" rel=\"noopener \"> blockchain-related hack<\/a> to date.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\"><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/1f6a8.png\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">Bybit Incident Technical Analysis<\/p>\n<p>A phishing attack bypassed multi-sig safeguards, tricking signers into approving a malicious contract upgrade. Hackers exploited:<br \/>\n<img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/1f539.png\" alt=\"\ud83d\udd39\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> Device compromise (via social engineering)<br \/>\n<img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/1f539.png\" alt=\"\ud83d\udd39\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"> Blind signing (UI spoofing on Safe{Wallet} + Ledger)<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/1f6e1.png\" alt=\"\ud83d\udee1\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">Learn\u2026 <a href=\"https:\/\/t.co\/FwnTDbskcc\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/FwnTDbskcc<\/a><\/p>\n<p>\u2014 CertiK (@CertiK) <a href=\"https:\/\/twitter.com\/CertiK\/status\/1893556636935168244?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">February 23, 2025<\/a><\/p>\n<\/blockquote>\n<p data-pm-slice=\"1 1 []\">Blockchain analyst Manuel Villegas <a href=\"https:\/\/www.bloomberg\/business\/international\/2025\/02\/27\/fbi-accuses-north-korean-backed-hackers-of-stealing-15-billion-in-crypto-from-dubai-based-firm\/\" target=\"_blank\" rel=\"noopener nofollow\">explained<\/a> that the attackers used a \u201cblind signing\u201d exploit. This method involves a fake user interface mimicking the legitimate platform, tricking users into authorizing unauthorized transactions.<\/p>\n<p data-pm-slice=\"1 1 []\">The repercussions of this breach have extended beyond Bybit\u2019s ecosystem,<a href=\"https:\/\/bitcoinist.com\/is-bitcoin-showing-another-false-downside-deviation-analyst-weighs-in\/\" target=\"_blank\" rel=\"noopener \"> triggering a decline<\/a> in overall cryptocurrency prices. Bitcoin has so far <a href=\"https:\/\/bitcoinist.com\/bitcoins-peak-is-still-far-off-why-this-year-could-be-huge-according-to-analyst\/\" target=\"_blank\" rel=\"noopener \">faced significant plunge<\/a> falling to as low as $82,000 levels on Wednesday.<\/p>\n<p data-pm-slice=\"1 1 []\">Industry observers suggest that this incident will increase regulatory scrutiny on cryptocurrency exchanges and their security measures.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-medium\" src=\"https:\/\/www.tradingview.com\/x\/fq43aEgg\/\" alt=\"The global crypto market cap value on TradingView\" width=\"3250\" height=\"1794\"><\/p>\n<p data-pm-slice=\"1 1 []\">Featured image created with DALL-E, Chart from TradingView<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Federal Bureau of Investigation has implicated North Korean-backed hacking groups in a major cryptocurrency heist involving $1.5 billion in digital assets. The cyberattack targeted Bybit, a Dubai-based cryptocurrency exchange, making it one of the largest crypto thefts publicly known. This incident has drawn attention to North Korea\u2019s ongoing role in cyber-enabled financial crimes. FBI [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-15433","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/15433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15433"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/15433\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}