How to Protect Developer Workstations and Short-Lived AWS Sessions
Retrospective: this article looks back at events from February 2025, written in 2026 with the benefit of hindsight.
The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value of their AWS sessions.
Part 1: Developer workstations
- Managed and compliant: developers use company-managed devices with EDR (Defender for Endpoint or equivalent), disk encryption and automatic updates.
- Separate environments: keep untrusted activity (testing unknown projects, downloading tools) in isolated VMs or dev containers, not on the device that holds production access.
- Privileged access workstations: for production administration, use a hardened device or cloud-hosted admin workstation used for nothing else.
- Social engineering awareness: fake job offers and malicious coding tests are a known technique against developers in the crypto and tech sectors.
Part 2: AWS session hygiene
- IAM Identity Center with short session durations for production permission sets (for example, one hour).
- Separate permission sets for read-only and write access; require elevation for write access to production.
- Just-in-time access with approval for sensitive actions (AWS offers temporary elevated access patterns; third-party tools add approvals).
- Require MFA at session start and use phishing-resistant MFA.
- Avoid long-lived credentials cached on disk; use
aws sso loginand clear sessions.
Part 3: Protect production assets
- Restrict write access to buckets serving production web assets to deployment pipelines only.
- Enable versioning and alerts on changes to front-end assets.
- Use Subresource Integrity (SRI) and content security policies where applicable.
- Monitor with CloudTrail data events for those buckets.
Part 4: Detect session theft
Alert on AWS sessions used from IPs that don't match the developer's usual locations (see detection article).
Verify
Review who can write to production assets today. It should be a pipeline, not people.