1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
🚨 Bybit just delivered a masterclass in crisis communications after experiencing the largest hack in crypto history. The situation is still live, but they’ve already succeeded in calming markets.
It’s a teachable moment for the rest of us. Here’s what they did right—and why it matters. 🧵👇
Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change the smart contract logic of our ETH cold wallet. This resulted Hacker took control of the specific ETH cold wallet we signed and transfered all ETH in the cold wallet to this unidentified address. Please rest assured that all other cold wallets are secure.
All withdraws are NORMAL.
I will keep you guys posted as more develops, If any team can help us to track the stolen fund will be appreciated.
https://t.co/ckwZgma8Lf