A Fake Job Offer Opened the Ronin Bridge
The Lazarus Group targeted a Sky Mavis developer through a fake job offer on LinkedIn. The tech test arrived as a Dockerfile that deployed malware on the developer’s machine. That gave attackers access to four of the nine Ronin voting nodes owned by Sky Mavis. A fifth node was compromised through leftover developer credentials that had never been cleaned up. With five votes, the attackers authorized a fraudulent transaction. They siphoned $625 million in Ethereum and USDC through the Ronin bridge.
The Louvre Ran Windows XP and Password “Louvre”
The Louvre’s security cameras were out during the heist, not from a cyber attack but from years of neglected systems. The password for the security system was “Louvre”. The museum still ran Windows 2000 and Windows XP. Three separate audits by France’s national cyber security agency had flagged the problems. Staff had warned management for years. Two gang members used a furniture lift to reach a first-floor window, cut through with disc cutters, threatened unarmed guards with power tools, and escaped on mopeds with eight items of jewelry worth over €100 million.
Safe Wallet’s Supply Chain Led to a $1.5B Heist
The Lazarus Group targeted Safe Wallet, Bybit’s transaction software provider. They compromised a Safe Wallet developer to inject code that triggered only when Bybit proposed a transfer. When a Bybit employee initiated a routine cold-to-hot wallet transfer, the malware replaced the destination address with one controlled by the attackers. Three of six approvers signed the transaction, seeing only a simplified Ledger UI that showed nothing suspicious. The signed contract gave the Lazarus Group $1.5 billion in crypto assets.
The Same Attack Patterns Keep Working
James Birnie lists missed opportunities from all three heists. The Ronin bridge exploited phishing, missing EDR, and a network where Sky Mavis owned four of nine nodes. The Louvre heist came down to nobody caring about security. The Bybit hack succeeded through an unaudited supply chain and a UI that made fraudulent transactions nearly invisible. None of these failures are new. Attacks have not changed character for decades. They still start with a phishing email.
Security Needs Storytellers, Not Just Technicians
The biggest problem in cybersecurity is getting the rest of the business to care. Birnie points to a Darknet Diaries story about pen testers who made a doll catch fire through a replay attack. That story got the CEO’s attention. Technical jargon like “replay attack” does not. His core message: stop listing vulnerabilities and start telling stories that business leaders understand. Frame the risk in terms they feel. Zero standing privileges and proper PAM systems help, but only if leadership funds them.
Notable Quotes
the password for the security systems was Louvre. James Birnie · ▶ Watch (35:17)
the museum was still running Windows 2000 and Windows XP at the time of the robbery. James Birnie · ▶ Watch (35:29)
attack so many times that they made the doll catch fire. Now, that’s a story you can take to the CEO, right? James Birnie · ▶ Watch (55:06)
Key Takeaways
- Phishing via fake job offers on LinkedIn remains the most effective initial access vector.
- Poor credential hygiene, such as leftover tokens and default passwords, undermines secure systems.
- Security professionals must translate technical risks into business stories executives act on.
About the Speaker
James Birnie has been working on commercial software since the late 1990s. He joined a startup in 2006, worked there for nine years, then moved into consultancy focusing on code quality, culture, and continuous improvement. He later served as Head of Platform in a fintech acquired by Visa for $1Bn and as VP of Engineering in a startup. He now drives transformation in cyber security at a major UK bank as an independent consultant.