SECTIONS
CYNTRI AI$CYNT PRESALE
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

Bybit: The $1.5 Billion Heist That Shook Crypto

The largest crypto hack ever. $1.5 billion. One transaction.

S
SYNTH·Hack Database
Bybit: The $1.5 Billion Heist That Shook Crypto
Bybit exchange

February 21, 2025. A routine transaction on Bybit's multi-sig Safe wallet turned into the largest single theft in cryptocurrency history. $1.5 billion in Ethereum. Gone.

The attack was terrifyingly sophisticated. The Lazarus Group, North Korea's state-sponsored hacking unit, didn't break the Safe wallet's cryptography. They went after something much harder to defend: the human interface. They compromised the Safe wallet's UI layer, manipulating what the signers saw on their screens. The transaction looked like a normal internal transfer. The signers approved it. But under the hood, the smart contract logic had been altered to redirect funds to the attacker's address.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models. Built by SYNTH.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

Bybit CEO Ben Zhou announced the hack within hours, confirming that the exchange's hot wallet was not affected and that user funds were safe. Unlike many exchanges that fold after major hacks, Bybit moved fast. They launched a recovery bounty program, coordinated with law enforcement, and secured emergency liquidity to cover the gap.

The FBI attributed the attack to the Lazarus Group within weeks. The same North Korean outfit that had hit Ronin Bridge for $625 million three years earlier. This time they'd refined their technique, targeting the trust layer between humans and their tools rather than the blockchain itself.

The crypto industry collectively realized something unsettling: if a state-sponsored group can manipulate what you see on your screen, no amount of on-chain security matters. The weakest link isn't the blockchain. It's the screen you're reading this on.

The Aftermath

The largest crypto hack in history. The FBI attributed it to North Korea's TraderTraitor/Lazarus Group on Feb 26, 2025. Elliptic reported ~$200M of stolen funds moved through eXch, a no-KYC service that shut down May 1, 2025. Minimal funds recovered. Elliptic estimates DPRK actors have stolen over $6 billion in crypto since 2017. The Bybit hack alone exceeded North Korea's entire 2024 haul of $1.34B.

LESSONS LEARNED

!The biggest threat isn't the blockchain. It's the interface between humans and the blockchain.
!State-sponsored hackers keep getting better. North Korea funds its weapons program with stolen crypto.
!Even multi-sig wallets fail if the signers can't trust what they see on screen

COMMENTS

CMZ
END OF FILE
Filed under Hack Database