www.ainvest.com Bybit Hack: $1.5 Billion Theft by North Korean Hackers
Article Content
- •The Bybit hack resulted in a $1.5 billion loss, making it one of the largest in crypto history.
- •North Korean hackers exploited a supply chain vulnerability, highlighting risks in third-party security.
- •The incident raises significant geopolitical concerns, linking state-sponsored cyber operations to financial crimes.
In February 2025, a major hack on the Bybit cryptocurrency exchange resulted in the theft of $1.5 billion in Ethereum. The attack was attributed to the North Korean Lazarus Group's TraderTraitor subunit, exploiting a supply chain compromise through social engineering on a Safe{Wallet} developer. This breach accounted for 69% of the total $2.02 billion stolen by North Korean hackers in 2025. The incident highlighted vulnerabilities in the crypto exchange ecosystem, particularly the reliance on third-party security providers. The FBI confirmed the link to the Lazarus Group, emphasizing the geopolitical implications of such cyberattacks. The hack raised concerns about the long-term viability of investments in centralized exchanges, as investors face increasing operational risks. Following the breach, discussions around stricter regulations and enhanced security measures have intensified in the industry.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lazarus Group, TraderTraitor and Bybit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…