North Korea’s Lazarus Group Strikes Again: The $1.5B Bybit Heist!

In the dim light of the digital frontier, where fortunes are made and lost with the click of a button, a figure emerged from the shadows. ZachXBT, a modern-day sleuth with a knack for unraveling the tangled webs of cybercrime, pointed his finger at none other than North Korea’s infamous Lazarus Group. They had pulled off a heist that would make even the most seasoned bandit blush, snatching a staggering $1.5 billion from the unsuspecting Bybit exchange. And for his troubles, ZachXBT pocketed a tidy sum of 50k ARKM, proving that crime doesn’t pay—unless you’re the one catching the criminals! 💰

It was at the stroke of 19:09 UTC that ZachXBT, with the precision of a watchmaker, submitted irrefutable evidence linking the dastardly deed to the notorious hacking group. The digital world held its breath, waiting for the verdict, as if it were a courtroom drama unfolding in real-time.

BREAKING: BYBIT $1 BILLION HACK BOUNTY SOLVED BY ZACHXBT

At 19:09 UTC today, @zachxbt submitted definitive proof that this attack on Bybit was performed by the LAZARUS GROUP.

His submission included a detailed analysis of test transactions and connected wallets used ahead of…

— Arkham (@arkham) February 21, 2025

The investigation revealed that the hackers had exploited Bybit’s Ethereum (ETH) multisig cold wallet during what was supposed to be a routine transfer to the exchange’s warm wallet. It was like watching a magician pull a rabbit out of a hat, except the rabbit was a billion dollars and the hat was a cold wallet. The attackers, with the finesse of a cat burglar, manipulated the signing interface, making it appear as if everything was in order while they twisted the very logic of the smart contract beneath the surface.

Bybit’s CEO, Ben Zhao, confirmed the grim news: the breach had resulted in losses that would make even the most hardened investor weep. But fear not, dear users! Zhao assured everyone that all client withdrawals would be processed, even those that were currently under review. Because nothing says “trust us” like a promise in the wake of a billion-dollar heist! 😅

ZachXBT reveals connections between Bybit and Phemex hack

In a twist worthy of a soap opera, ZachXBT’s investigation uncovered direct on-chain connections between the Bybit incident and the recent Phemex exchange hack. It seemed the attackers had a penchant for commingling funds from both thefts, using the same initial addresses. A classic case of “you scratch my back, I’ll scratch yours,” but in the most illegal way possible. This pattern was all too familiar, echoing the Lazarus Group’s notorious tactics of linking multiple exchange compromises.

Lazarus Group just connected the Bybit hack to the Phemex hack directly on-chain commingling funds from the intial theft address for both incidents.

Overlap address:
0x33d057af74779925c4b2e720a820387cb89f8f65

Bybit hack txns on Feb 22, 2025:…

— ZachXBT (@zachxbt) February 22, 2025

The bounty submission was a treasure trove of detailed analyses, tracking the movements of wallets like a hawk eyeing its prey. It pointed directly to the North Korean state-sponsored group, leaving no stone unturned. Arkham, the digital watchdog, shared this forensic evidence with Bybit’s team, hoping to shed light on the dark corners of this ongoing investigation.

The saga began when Bybit detected unauthorized transfers from one of their Ethereum (ETH) cold wallets. Like a fire alarm in the dead of night, the exchange sprang into action, launching an investigation and enlisting the help of blockchain forensics experts to trace the stolen assets. They even issued an open call for assistance, as if shouting into the void for help from the digital cavalry.

This hack, dear reader, stands as one of the largest cryptocurrency exchange hacks in history—a tale of greed, cunning, and a dash of humor in the face of adversity. The Bybit team, in a show of solidarity, received aid from other exchanges to keep the withdrawals open for users, proving that even in the darkest of times, there’s always a glimmer of hope. 🌟

Read More

2025-02-22 16:41