T
iTokenly

Bybit hack — February 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$1,460,000,000Published estimates range $1,400,000,000 to $1,500,000,000Price at time of incident
MethodSupply chain or frontend compromiseCompromised Safe{Wallet} infrastructure served a malicious signing interface
ChainsEthereum
Attributed toNorth Korea (TraderTraitor / Lazarus Group)Confirmed
OutcomeUnresolved

What happened

Bybit lost roughly $1.4bn to $1.5bn of Ethereum on 21 February 2025 in what is, by value, the largest cryptocurrency theft recorded. The exchange was moving funds from a cold wallet to a hot wallet through Safe{Wallet}, the multisig platform used in its signing workflow, when the transfer was rerouted to addresses the attacker controlled.

The compromise was not of Bybit's own contracts. Infrastructure belonging to Safe{Wallet} was breached, and the signers were shown a transaction that differed from the one they were actually approving. Once signed, the funds were converted to Bitcoin and other assets and spread across thousands of addresses.

The FBI attributed the theft to North Korean actors it tracks as TraderTraitor, also known as Lazarus Group and APT38, in a public service announcement five days later, and published laundering addresses so that providers could block them.

Published loss figures differ: the FBI cited approximately $1.5bn, while several analyses put the figure nearer $1.4bn. The difference is a valuation question rather than a dispute about what was taken, and both figures are recorded here.

Law enforcement

The FBI published a public service announcement on 26 February 2025 attributing the theft to North Korean actors it tracks as TraderTraitor, and released Ethereum addresses used to launder the proceeds with a request that providers block transactions involving them.

Sources

  1. FBI Internet Crime Complaint CenterPrimary · retrieved 2026-08-01
  2. Federal Bureau of InvestigationPrimary · retrieved 2026-08-01
  3. SecurityWeekSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Bybit hack — February 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bybit
https://itokenly.com/hacks/bybit

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.