TGViewer
Netlas.io Netlas.io @netlas · 2.32K subscribers
Post #456 613
The $1.5 B Bybit Hack & How OSINT Cracked the Case 🔍

On February 21, 2025, the Lazarus Group tricked a Safe{Wallet} developer into approving malicious multisig transactions — netting over $1.4 billion from Bybit’s cold wallet — and covered their tracks with targeted JavaScript injection.

In our latest article, see how open-source sleuthing linked the heist to North Korea’s premier APT and learn the OSINT techniques that unraveled this record-breaking crypto theft.

👉 Read now: https://netlas.io/blog/bybit_hack
netlas.io The $1.5B Bybit Hack & How OSINT Led to Its Attribution - Netlas Blog Insights on the record-breaking Lazarus heist: how social engineering, AWS token hijacking, and Safe{Wallet} code injection enabled the Bybit hack.
  • 👍 7
  • 👾 3
More from @netlas
  1. Sep 25, 2026CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating 🔥 Rec…
  2. Sep 24, 2026CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Ranc…
  3. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
  4. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  5. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  6. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →