Bybit Suffers $1.46 Billion Loss in North Korean Hacking Incident

Bybit Suffers $1.46 Billion Loss in North Korean Hacking Incident

First seen 9 Aug 2026, 15:33 UTC Cryptoslatewww.bybit.comsafe.globalarxiv.org 86% similarity 74.0

Article Content

Browse articles
ThreatCluster

On February 21, 2025, Bybit experienced a significant security breach involving a routine transfer from an Ethereum cold wallet to a warm wallet. The attack, attributed to North Korea's Lazarus Group, exploited the user interface of the Safe multisig cold wallet through a sophisticated phishing attack. This manipulation allowed hackers to alter the smart contract logic, resulting in the unauthorized transfer of approximately 401,347 ETH and other assets, totaling a loss of $1.46 billion. Bybit's CEO assured users that the exchange remains solvent and can cover the losses, while investigations into the attack continue. The incident highlights vulnerabilities in crypto security, particularly the misleading nature of 'audited' badges that imply comprehensive safety. The attack has raised concerns about the security practices of cryptocurrency exchanges and the potential for similar incidents in the future.

Key Points: • Bybit lost $1.46 billion due to a phishing attack linked to North Korea's Lazarus Group. • Hackers exploited the Safe multisig wallet's UI to manipulate transaction approvals. • Bybit's CEO confirmed the exchange's solvency and ongoing investigations into the breach.

ThreatCluster AI How this analysis works

Timeline

2025-02-21
Routine transfer initiated at Bybit
Bybit began moving funds from an Ethereum cold wallet to a warm wallet, starting with 30,000 ETH.
www.bybit.com
2025-02-21
Phishing attack exploited Safe wallet UI
Hackers manipulated the transaction interface, changing the smart contract logic and allowing fund transfers.
www.bybit.com
2025-02-21
Loss of $1.46 billion confirmed
The breach resulted in the loss of 401,347 ETH and other assets, totaling approximately $1.46 billion.
www.bybit.com
2025-02-21
CEO reassures users of solvency
Bybit's CEO stated that the exchange is solvent and can cover the loss, ensuring client assets are backed 1:1.
www.bybit.com
2025-02-21
Link to Lazarus Group confirmed
ZachXBT provided evidence linking the attack to the North Korean Lazarus Group, a state-backed cybercriminal organization.
www.bybit.com

Community

Browse all →