Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
North Korean Cryptocurrency Hack - News Directory 3

North Korean Cryptocurrency Hack

February 22, 2025 Catherine Williams Tech
News Context
At a glance
  • In a stunning revelation, blockchain intelligence firm Arkham Intelligence has identified the notorious North Korean hacking group, Lazarus, as the masterminds behind the recent $1.46 billion cyber heist...
  • Arkham Intelligence initially offered a reward of 50,000 ARKM tokens to anyone who could identify the attackers.
  • Its presentation included a detailed analysis of the test transactions and connected wallets used before the attack, as well as multiple forensic graphics and time analysis.
Original source: es.tradingview.com

North Korean Hackers Allegedly Behind Massive $1.46 Billion Bybit Cryptocurrency Heist

Table of Contents

  • North Korean Hackers Allegedly Behind Massive $1.46 Billion Bybit Cryptocurrency Heist
  • North Korean Hackers Allegedly Behind Massive $1.46 Billion Bybit Cryptocurrency Heist
    • Frequently Asked Questions
      • What is the “blind signing” attack vector, and how does it relate to the Bybit heist?
      • Who are the Lazarus group, and what makes them notorious in the cyber world?
      • How was the $1.46 billion heist from Bybit executed?
      • What are the implications of this heist for the cryptocurrency industry?
      • How is Bybit addressing the security vulnerabilities exposed by this heist?
      • What can other exchanges learn from Bybit’s experience?
    • Conclusion

In a stunning revelation, blockchain intelligence firm Arkham Intelligence has identified the notorious North Korean hacking group, Lazarus, as the masterminds behind the recent $1.46 billion cyber heist targeting the cryptocurrency exchange Bybit. The detection was made by the renowned cybersecurity expert Zachxbt, who provided definitive evidence linking the attack to the Lazarus group.

Arkham Intelligence initially offered a reward of 50,000 ARKM tokens to anyone who could identify the attackers. Zachxbt’s submission included a comprehensive analysis of test transactions, connected wallets, forensic graphics, and a detailed time analysis. This evidence was crucial in pinpointing the North Korean hackers as the culprits.

Its presentation included a detailed analysis of the test transactions and connected wallets used before the attack, as well as multiple forensic graphics and time analysis.

Arkham Intelligence

The hack, which sent shockwaves through the crypto market and caused a significant drop in most cryptocurrency prices, has been described as “the largest crypto robbery of all time, by a wide margin” by Tom Robinson, co-founder and chief scientist of Elliptic. The next largest crypto heist was the $611 million stolen from Poly Network in 2021. This attack could potentially be the largest individual theft in history.

The next largest crypto robbery would be that of 611 million dollars stolen from Poly Network in 2021. In fact, it may even be the largest individual theft of all time.

Tom Robinson, Co-founder and Chief Scientist of Elliptic

According to blockchain data provider Nansen, the attackers initially withdrew nearly $1.5 billion in exchange funds and transferred them to a main wallet before distributing the funds among several other wallets. The stolen assets, including Steth, CMETH, and METH, were converted to ETH and then systematically transferred in increments of $27 million to more than 10 additional wallets.

Initially, stolen funds were transferred to a main wallet, which later distributed them among more than 40 wallets.

Nansen

The attack vector used in this heist is known as “blind signing,” where an intelligent contract transaction is approved without complete knowledge of its content. This method is becoming increasingly popular among advanced threat actors, including North Korea. Similar attacks have been used in the breaches of Radiant Capital and Wazirx.

This attack vector is quickly becoming the favorite form of cyber attack used by threat actors Advanced, including North Korea. It is the same type of attack that was used in the violation of Radiant Capital and the Wazirx incident.

Ben Natan, CEO of Blockchain Security Firm Blockoid

Ben Natan, CEO of the blockchain security firm Blockoid, explained that the problem lies in the delegation of the signature process to software interfaces that interact with decentralized applications. This creates a critical vulnerability that can be exploited by malicious actors. Ben Zhou, Executive Director of Bybit, confirmed that a hacker took control of a specific cold wallet containing ETH and transferred all funds to an unidentified address. Despite the loss, Bybit remains solvent and capable of covering the losses.

The problem is that, even with the best management solutions of keys, today most of the signature process is delegated to software interfaces that interact with decentralized applications. This creates a critical vulnerability: it opens the door to the malicious manipulation of the signature process, which is exactly what happened in this attack.

Ben Natan, CEO of Blockoid

In response to the attack, Bybit has taken immediate steps to enhance its security measures. The exchange has implemented stricter protocols for transaction approvals and increased monitoring of wallet activities. Bybit’s swift action highlights the importance of robust cybersecurity measures in the face of evolving threats.

This incident underscores the need for heightened vigilance and advanced cybersecurity measures in the cryptocurrency industry. As the value of digital assets continues to rise, so does the attractiveness of these assets to cybercriminals. The Lazarus group’s involvement in this heist serves as a stark reminder of the sophisticated and persistent threats facing the crypto market.

Experts suggest that the best defense against such attacks is a multi-layered approach to security, including advanced threat detection systems, regular security audits, and employee training on cybersecurity best practices. Bybit’s resilience in the face of this attack demonstrates the importance of being prepared for the worst-case scenario and having contingency plans in place.

As the investigation continues, the crypto community awaits further developments and potential legal actions against the perpetrators. The U.S. government, along with international allies, is likely to intensify efforts to combat cybercrime, particularly from state-sponsored actors like North Korea.

In the wake of this high-profile heist, the crypto market has shown resilience, with prices stabilizing and investor confidence slowly returning. However, the incident serves as a wake-up call for the industry to prioritize security and implement stringent measures to protect against future attacks.

For the latest updates on this developing story, stay tuned to newsdirectory3.com.

North Korean Hackers Allegedly Behind Massive $1.46 Billion Bybit Cryptocurrency Heist

Frequently Asked Questions

What is the “blind signing” attack vector, and how does it relate to the Bybit heist?

  • Definition: Blind signing is a method were intelligent contract transactions are approved without complete knowledge of their content. This technique allows attackers to manipulate transaction outcomes by tricking the signer into approving a transaction written by the attacker.
  • Relation to Bybit Heist: North Korean hackers employed blind signing to acquire nearly $1.5 billion from Bybit. This approach made it possible for hackers to secretly transfer stolen funds without caring what specific transactions were being processed [3].
  • Prevalence: Blind signing is becoming a favored method among advanced threat actors, including groups from North Korea. Similar techniques have been used in breaches by Radiant Capital and Wazirx [2].

Who are the Lazarus group, and what makes them notorious in the cyber world?

  • Identity: The Lazarus group, linked to North Korea, has been identified as a primary suspect behind numerous high-profile cyber heists, including the massive $1.46 billion Bybit heist.
  • Notoriety: This group has a history of significant cyber attacks and is noted for its refined methodologies and links to state-sponsored operations. Their involvement in the Bybit heist suggests a high level of planning and execution [1].

How was the $1.46 billion heist from Bybit executed?

  • Initial Transfer: The attackers initially withdrew approximately $1.5 billion, transferring it to a main wallet. This fund was then split among more than 40 additional wallets for distribution [3].
  • conversion and Distribution: The stolen assets, which included Steth, CMETH, and METH, were converted to ETH and systematically transferred in increments to over ten additional wallets. This method helped obscure the trail and complicated recovery efforts.

What are the implications of this heist for the cryptocurrency industry?

  • Market Impact: The hack caused significant turmoil in the crypto market, leading to substantial price drops across most cryptocurrencies. It’s noted as the largest crypto robbery of all time [2].
  • Industry Lesson: This incident highlights the need for robust cybersecurity measures in the cryptocurrency industry. It stresses the importance of multi-layered security approaches, including advanced threat detection, regular audits, and extensive employee training.

How is Bybit addressing the security vulnerabilities exposed by this heist?

  • Immediate Actions: Bybit has since increased monitoring of wallet activities and implemented stricter transaction protocols. These measures are designed to prevent future occurrences of similar attacks.
  • Resilience and Recovery: Despite significant losses, Bybit remains solvent and has the capability to cover the financial impact. The rapid response signifies a commitment to improved security practices [1].

What can other exchanges learn from Bybit’s experience?

  • Security Upgradation: Exchanges should evaluate and upgrade their security frameworks, focusing on transaction approval processes and wallet security.
  • Employee Training: Continuous cybersecurity training for employees can further diminish the risk of similar attacks.
  • Vulnerability Assessment: Regular security audits and assessments can definitely help identify potential vulnerabilities before they are exploited.

Conclusion

The bybit heist represents a wake-up call for the entire cryptocurrency industry. By understanding the tactics used by sophisticated threat actors like the lazarus group and taking proactive measures, industry players can better protect their assets and user trust. As the crypto market continues to evolve,staying ahead of cyber threats will be crucial in maintaining a secure and resilient digital financial ecosystem.

For more updates on this developing story, follow trusted sources like newsdirectory3.com.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Keep reading

  • On October 4, 2026, Saturn will reach opposition, bringing the planet to its closest point to Earth
  • How I Built an AI-Powered To-Do List App Using Gemini
  • South Korean President Lee Jae Myung Demands Ukraine Apology Over POW Row (time.news)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com