Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn
Multi-signature wallet Safe: North Korean hacker group TraderTraitor is behind previous hacker attacks

Multi-signature wallet Safe: North Korean hacker group TraderTraitor is behind previous hacker attacks

CointimeCointime2025/03/06 15:45
By:Cointime

The multi-signature wallet Safe announced on the X platform that a security investigation conducted in conjunction with Mandiant (now owned by Google Cloud) has made crucial progress and confirmed that the attack on February 21 was carried out by the North Korean hacker group TraderTraitor (UNC4899), which has previously launched multiple attacks on the cryptocurrency industry. The hackers gained critical access by infiltrating the computer of Safe{Wallet} developers and hijacking AWS session tokens to bypass multi-factor authentication (MFA). Safe stated that although the attack had some impact, the smart contracts were not compromised, the system has been fully reset, and tighter security measures have been implemented, including:

- Infrastructure reset: regenerate all credentials, reset clusters, update keys and confidential information, and redeploy container images.

- External access restriction: temporarily block external access to transaction services, only allowing internal communication, and strengthen firewall rules.

- Malicious transaction detection upgrade: collaborate with Blockaid to strengthen transaction monitoring, increase risk markers for Safe account control upgrades.

- Enhanced real-time monitoring: improve logging and threat detection capabilities for faster response to security incidents.

- Pending transaction cleanup: clear all pending transactions from the database to prevent potential security risks.

- UI and security verification tool optimization: introduce Safe Utils as a third-party transaction verification tool and plan to provide a fully IPFS-hosted version of Safe{Wallet}.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Franklin Templeton says Solana’s DeFi rise presents a threat to Ethereum

Share link:In this post: A Franklin Templeton report suggested that Solana threatened Ethereum due to its growing influence. Solana’s DEX volumes surpassed the Ethereum ecosystem in January, highlighting a potential market shift. According to the report, the shift to activity to the layer two blockchain shows the Ethereum scaling approach was working.

Cryptopolitan2025/03/06 18:55