lazarusholic

Everyday is lazarus.dayβ

Not So Safe

2025-03-13, Rekt
https://rekt.news/not-so-safe
#Bybit #SafeWallet

Contents

Not So Safe
North Korean hackers didn't need a zero-day exploit or billion-dollar quantum computer to pull off history's largest crypto heist.
The culprits? Not some basement-dwelling script kiddies, but TraderTraitor, a North Korean hacker unit operating under the Lazarus Group umbrella.
They socially engineered a developer into running a malicious Docker project and turned Web3's promises of security into digital ash.
You are one yaml.load away from losing everything – a bitter lesson Bybit learned when $1.4 billion vanished from their Safe multisig, the industry's supposedly unbreakable standard.
Safe's security reputation shattered in a heartbeat.
A decade of being crypto's Fort Knox crumbled not because of some revolutionary hack, but a boring config file mistake that Kim Jong Un's cyber goons exploited with surgical precision.
Laugh-cry at the irony: billions guarded by battle-tested smart contracts got jacked because someone screwed up a YAML file.
Web3 keeps flexing triple-audited code and mathematically perfect protocols while the billions they …