Bybit: The $1.5 Billion Heist That Shook Crypto
The largest crypto hack ever. $1.5 billion. One transaction.

February 21, 2025. A routine transaction on Bybit's multi-sig Safe wallet turned into the largest single theft in cryptocurrency history. Roughly 400,000-500,000 ETH, worth $1.4 to $1.5 billion depending on the moment it's measured, gone in one session.
The attack was terrifyingly sophisticated, and it never touched Bybit's own infrastructure directly. The Lazarus Group, North Korea's state-sponsored hacking unit, went after Safe{Wallet}, the third-party interface Bybit's signers used to review and approve multi-signature transactions, having compromised a Safe{Wallet} developer's machine through social engineering as early as February 4. By February 19, malicious JavaScript was quietly injected into the interface specifically to target Bybit. The exploit sat in the trust boundary between the signing software and the humans reviewing it: what the signers saw on their screens during a routine cold-to-warm wallet transfer did not match what the blockchain actually received. The transaction looked like an ordinary internal transfer. The signers approved it. Underneath, the real transaction redirected the funds to an address the attackers controlled.
Bybit CEO Ben Zhou confirmed the breach within hours and insisted the exchange remained solvent, but the reassurance didn't stop nearly $10 billion in panic withdrawals hitting the platform in the immediate aftermath. What happened next became the case study in how to survive a hack of this size. In under 72 hours, Bybit pieced together roughly 447,000 ETH to fully replenish its reserves, drawing on emergency loans and large deposits from firms including Galaxy Digital, FalconX, and Wintermute. Bitget CEO Gracy Chen personally extended a 40,000 ETH loan, worth about $100 million, with no interest and no collateral required, a rare show of direct competitor-to-competitor support in an industry that usually watches disasters from a distance. A proof-of-reserves audit from cybersecurity firm Hacken confirmed Bybit's holdings, across bitcoin, ether, solana, USDT, and USDC, had been restored above 100% collateralization.
Recovering the actual stolen funds proved far harder than replacing the money. Bybit launched a bounty program offering 10% of any recovered assets, worth up to $140 million, to cybersecurity researchers and blockchain analysts who could help trace the stolen ETH. Blockchain investigator ZachXBT confirmed early on that at least 5,000 ETH from the theft had already moved through the no-KYC exchange eXch and been bridged into Bitcoin via Chainflip. Elliptic later reported that roughly $200 million of the stolen funds passed through eXch before that service shut down entirely on May 1, 2025, reportedly under pressure tied to its role in laundering the Bybit funds. Ben Zhou said publicly that his team could still trace 88.87% of the stolen assets on-chain, even as the practical odds of clawing any of it back stayed low.
The FBI formally attributed the attack to the Lazarus Group's TraderTraitor unit on February 26, 2025, the same outfit behind the $625 million Ronin Bridge theft three years earlier, this time refining its technique to target the interface layer instead of the blockchain itself. Elliptic estimates North Korea-linked actors have stolen more than $6 billion in crypto since 2017, and the Bybit theft alone exceeded the group's entire reported 2024 haul of $1.34 billion in a single attack.
Bybit's longer-term response has been aggressive. By March 2026, the exchange had published 31 consecutive monthly Proof of Reserves audits through Hacken, earned a CertiK AA security rating, and rolled out more than 50 separate security upgrades, including FIDO passkey support, IP allowlisting for API keys, and a "Secure Transaction Approval" flow requiring confirmation from a primary trusted device. No Bybit user lost funds in the incident. The crypto industry took away a less comfortable lesson: if a state-sponsored group can manipulate what a signer sees on their own screen, no amount of on-chain security matters. The weakest link isn't the blockchain. It's the interface sitting between a human and it.
The Aftermath
The largest crypto hack in history. The FBI attributed it to North Korea's TraderTraitor/Lazarus Group on Feb 26, 2025. Elliptic reported ~$200M of stolen funds moved through eXch, a no-KYC service that shut down May 1, 2025. Minimal funds recovered. Elliptic estimates DPRK actors have stolen over $6 billion in crypto since 2017. The Bybit hack alone exceeded North Korea's entire 2024 haul of $1.34B.
COMMENTS