Safe{Wallet} Reveals $1.46 Billion Bybit Attack Details

3 Min Read Tags:

  • Safe{Wallet} confirmed North Korean-linked TraderTraitor group behind the Bybit attack.
  • Compromised AWS session tokens from a developer’s laptop facilitated the breach.
  • Enhanced security measures were implemented to safeguard against future threats.
  • Collaboration with cybersecurity experts and Blockaid improved threat detection and response.
  • Initiatives to migrate Safe{Wallet} to IPFS for increased decentralization were announced.

Safe{Wallet} Reveals Details of Bybit Hack: A $1.46 Billion Loss

The recent revelation that Safe{Wallet}, in collaboration with Mandiant cybersecurity experts, has identified the North Korean-affiliated hacking group TraderTraitor as responsible for the significant Bybit exchange breach is a wake-up call for the crypto industry. This attack, which resulted in losses amounting to $1.46 billion, underscores vulnerabilities within digital infrastructures.

The Attack Unraveled

On February 21, TraderTraitor managed to infiltrate Safe{Wallet}’s systems by intercepting AWS session tokens from a developer’s laptop. This developer, referred to as “Developer1,” had extensive access rights that allowed hackers to bypass multifactor authentication (MFA) and penetrate key systems. The fallout of this incident necessitated immediate and comprehensive action from Safe{Wallet}.

Strengthening Cybersecurity Posture

In response, Safe{Wallet} underwent a complete infrastructure overhaul. This included credential rotations, server updates, and stricter external access controls. Additionally, collaboration with Blockaid resulted in enhanced real-time network monitoring and removal of all pending transactions to thwart subsequent attacks.
To further mitigate risks, support for native hardware wallets was temporarily disabled. Users now have access to tools for independent transaction hash verification. Moreover, plans are underway to host Safe{Wallet} on the InterPlanetary File System (IPFS), thereby enabling users direct service interaction without relying on centralized servers.

A Call for Industry Collaboration

Safe{Wallet} emphasizes the importance of unified efforts among Web3 platforms to bolster cybersecurity defenses across the board. The company highlights transaction verification prior to signing as the final defense line against compromised security protocols. Achieving transparency and simplicity in these processes demands collective industry solutions.
An upcoming guide will soon be available for users on secure transaction verification practices.
This incident serves as a stark reminder of the persistent threats facing cryptocurrency platforms today. It also illustrates how rapid response strategies and collaborative efforts can reinforce security frameworks against increasingly sophisticated cyber threats.

TAGGED:
Canary Capital Launches First US Spot TRX ETF With Staking

Canary Capital launched the Canary Staked TRX ETF on Cboe BZX under ticker TRXS on Sept. 9, 2026, offering direct TRX exposure and staking rewards.

5 Min Read
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read