www.bybit.com
Bybit Suffers $1.46 Billion Loss in North Korean Hacking Incident
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On February 21, 2025, Bybit experienced a significant security breach involving a routine transfer from an Ethereum cold wallet to a warm wallet. The attack, attributed to North Korea's Lazarus Group, exploited the user interface of the Safe multisig cold wallet through a sophisticated phishing attack. This manipulation allowed hackers to alter the smart contract logic, resulting in the unauthorized transfer of approximately 401,347 ETH and other assets, totaling a loss of $1.46 billion. Bybit's CEO assured users that the exchange remains solvent and can cover the losses, while investigations into the attack continue. The incident highlights vulnerabilities in crypto security, particularly the misleading nature of 'audited' badges that imply comprehensive safety. The attack has raised concerns about the security practices of cryptocurrency exchanges and the potential for similar incidents in the future.
Key Points: • Bybit lost $1.46 billion due to a phishing attack linked to North Korea's Lazarus Group. • Hackers exploited the Safe multisig wallet's UI to manipulate transaction approvals. • Bybit's CEO confirmed the exchange's solvency and ongoing investigations into the breach.