« 2025 »

778 reports

2025-02-26 • Bybit

LazarusBounty is a public bounty and transparency site for tracking sanctioned Lazarus-related cryptocurrency laundering activity. The page says users can connect wallets to trace stolen funds, claim moving wallets, and receive bounties when their submiss…

#Lazarus #Bybit
2025-02-26 • Ssol2

A malicious LNK sample shared on X with a Kimsuky tag used a DOCX icon lure and embedded an mshta.exe command, though the author cautions against relying heavily on the group label. LECmd analysis showed the shortcut extracting data from offset 0x0938 int…

#Kimsuky #LNK
2025-02-25 • Verichains

Verichains analyzed the February 21, 2025 Bybit hot wallet exploit, where a malicious transaction upgraded the Bybit Hot Wallet Proxy implementation through a SafeWallet call. The on-chain flow involved an attacker-controlled call to the proxy, delegateca…

#Bybit
2025-02-24 • Cobo

Cobo's Bybit analysis says attackers stole more than $1.5 billion after operators approved what appeared to be a normal Safe{Wallet} transfer from a cold wallet to a hot wallet. The transaction instead changed the Safe implementation contract and gave the…

#Bybit
2025-02-23 • Certi K

The Bybit cold Ethereum wallet theft involved a masked Safe{Wallet} transaction that obtained three valid signer approvals while sending malicious transaction data to Ledger devices. The attacker used a delegatecall to modify the Safe masterCopy storage s…

#Bybit