{"id":120174,"title":"North Korean hackers pulled off record $1.5bn heist in just two minutes.","publisher":"Share Talk","author":"sharetalk","published":"2025-03-01T12:37:54+00:00","modified":"2025-03-01T12:37:54+00:00","canonical_url":"https://www.share-talk.com/north-korean-hackers-pulled-off-record-1-5bn-heist-in-just-two-minutes/","markdown_url":"https://www.share-talk.com/north-korean-hackers-pulled-off-record-1-5bn-heist-in-just-two-minutes.md","json_url":"https://www.share-talk.com/north-korean-hackers-pulled-off-record-1-5bn-heist-in-just-two-minutes.json","category":"B2B","categories":["B2B","Blogs","Business & Support Services","Fintech","Technology","Technology, Media & Telecoms"],"tags":["Ben Zhou","Binance","Binance's BNB token","Bitcoin","BNB","BTC","Bybit","Cardano","crypto heists","cryptocurrencies","cryptocurrency","cryptocurrency exchange","DOGE","Dogecoin","Dubai","Elon Musk","encrypted","encrypted USB drives","ETFs","ETH","Ethereum","FBI","Hackers","Lazarus Group","Litecoin","LTC","North Korean","Ripple","Safe Wallet","SEC","SOL","Solana","state-sponsored","Sygnia","TSLA","US Securities and Exchange Commission","USA","USB drives","Verichains","withdrawal requests","XRP"],"featured_image":"https://i0.wp.com/www.share-talk.com/wp-content/uploads/2025/03/dreamstime_xxl_161784861-scaled.webp?fit=1200%2C800&quality=80&ssl=1","format":"news","language":"en-GB","content":"According to cybersecurity researchers, north Korean hackers executed the largest cryptocurrency heist in history, stealing $1.5 billion (£1.2bn) in just two minutes.\n\nA post-mortem investigation commissioned by [cryptocurrency exchange Bybit](https://www.share-talk.com/bybit-calls-on-cybersecurity-experts-after-1-5-billion-crypto-heist/)—recently targeted by a Pyongyang-linked group that stole hundreds of millions in Ethereum—has revealed how the attackers infiltrated its systems.\n\nThe hackers compromised a so-called cold wallet, a hardware-based storage system designed to keep cryptocurrency secure by remaining offline. These wallets, similar to encrypted USB drives, are considered highly secure.\n\nHowever, when Bybit attempted to transfer funds from its cold wallet to an online account, the attackers struck within seconds, exploiting the transaction window.\n\nCybersecurity firms Sygnia and Verichains determined that the breach stemmed from a vulnerability in Safe Wallet, a technology used for secure transactions, after reconstructing the attack from digital records.\n\nTwo days before the attack, North Korean hackers—believed to be part of the notorious Lazarus Group—embedded malicious code into the online infrastructure of Safe Wallet, the system used to communicate with Bybit’s account upon activation.\n\nSafe Global, the company behind Safe Wallet, revealed that the hackers had successfully “compromised the machine of a Safe Wallet developer,” attributing the breach to the group’s “sophisticated social engineering attacks.”\n\nThe injected code was specifically crafted to exploit Bybit’s wallet. It was designed to mimic the coded “signature” of three key accounts, including that of Bybit’s chief executive, allowing the attackers to bypass security checks.\n\nAt 2:15 PM last Friday, when Bybit attempted to transfer funds, the hackers activated their backdoor function, instantly draining 400,000 Ethereum coins from the exchange’s wallets.\n\nAccording to a report by Sygnia, “two minutes after the malicious transaction was executed and published,” the hackers deleted their code and exited the system before Bybit even detected the theft.\n\nFollowing the heist, the North Korean group has been rapidly laundering the stolen funds through multiple cryptocurrency exchanges.\n\nOn Wednesday, the FBI officially attributed the heist to North Korea, identifying the hacking group responsible under the codename TraderTraitor.\n\nThe agency warned that the hackers are “moving quickly,” having already converted a portion of the stolen assets into Bitcoin and other cryptocurrencies, dispersing them across thousands of addresses on multiple blockchains."}