CIO Brief: Developers Are Privileged Users
Retrospective: this article looks back at events from February 2025, written in 2026 with the benefit of hindsight.
The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a developer at a wallet software company, used his cloud access to change the website Bybit's staff used, and tricked them into approving a theft.
Why developers are privileged users
Developers often have access to production systems, cloud accounts and the code customers rely on. Their laptops hold active sessions and keys. Attackers target them with fake job offers, malicious code projects and phishing — because one compromised developer can reach everything they can.
The business impact
- Catastrophic financial loss.
- Supply-chain compromise affecting customers.
- Bypassed security controls — multi-signature approvals didn't help when the interface itself was tampered with.
Questions to ask your team
- Which developers can change production systems directly?
- Do developers use separate, hardened devices or accounts for production access?
- How long do developers' cloud sessions last, and would we notice if one were used from somewhere else?
- Could someone change our customer-facing website or app without a review?
What good looks like
Production changes only through reviewed pipelines, short and monitored developer sessions, managed and protected developer devices, and integrity monitoring for customer-facing code.
The decision
Treat developer access to production like administrator access: limited, temporary, monitored and protected with the strongest controls.
- The $1.5B Bybit Theft (Feb 2025): A Developer Machine, Stolen AWS Session Tokens and a Poisoned S3 Asset Incident Teardowns
- How to Protect Developer Workstations and Short-Lived AWS Sessions How-To & Hardening
- Detecting AWS Session Token Hijacking: CloudTrail, GuardDuty and Athena Queries Detection & Response