Officials pinned the blame on North Korea’s Lazarus Group for the recent devastating $1.5 billion crypto heist against Bybit.
Earlier this month, popular cryptocurrency exchange Bybit suffered a devastating attack that inflicted a tremendous $1.5 billion loss.
Using a signing interface masking technique during an ETH transfer, threat actors gained control of a cold wallet and transferred its holdings to an attacker-owned address.
Bybit reported the incident to authorities and sought help from third-party blockchain analytics experts to identify the addresses of those involved, attempting to thwart perpetrators’ efforts to move the stolen funds.
Although security experts at blockchain security firm Elliptic pointed to Lazarus, the identities of the threat actors were not officially confirmed.
However, on Wednesday, federal authorities released a public service announcement (PSA) formally naming Lazarus Group as responsible for the record crypto heist against Bybit.
In this document, the FBI refers to the threat actors as “TraderTraitor.” Aside from their infamous moniker “Lazarus Group,” the North Korea-backed perpetrators are also tracked by security researchers as APT38, Stardust Chollima, and Blue Noroff.
“TraderTraitor actors are proceeding rapidly and have converted some of the stolen assets to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains,” reads the FBI’s PSA. “It is expected these assets will be further laundered and eventually converted to fiat currency.”
The Bureau included a list of Ethereum addresses connected to the high-profile heist. It encouraged appropriate entities, such as bridges, exchanges, DeFi services and RPC node operators to block transactions originating from or connected to these addresses, to prevent TraderTraitor from laundering stolen assets.
The list of rogue wallet addresses is as follows:
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all postsFebruary 20, 2025
February 11, 2025
December 24, 2024
December 19, 2024