Bybit hack — February 2025
Incident facts
| Date of incident | |
|---|---|
| Target type | Centralised exchange |
| Loss | $1,460,000,000Published estimates range $1,400,000,000 to $1,500,000,000Price at time of incident |
| Method | Supply chain or frontend compromiseCompromised Safe{Wallet} infrastructure served a malicious signing interface |
| Chains | Ethereum |
| Attributed to | North Korea (TraderTraitor / Lazarus Group)Confirmed |
| Outcome | Unresolved |
What happened
Bybit lost roughly $1.4bn to $1.5bn of Ethereum on 21 February 2025 in what is, by value, the largest cryptocurrency theft recorded. The exchange was moving funds from a cold wallet to a hot wallet through Safe{Wallet}, the multisig platform used in its signing workflow, when the transfer was rerouted to addresses the attacker controlled.
The compromise was not of Bybit's own contracts. Infrastructure belonging to Safe{Wallet} was breached, and the signers were shown a transaction that differed from the one they were actually approving. Once signed, the funds were converted to Bitcoin and other assets and spread across thousands of addresses.
The FBI attributed the theft to North Korean actors it tracks as TraderTraitor, also known as Lazarus Group and APT38, in a public service announcement five days later, and published laundering addresses so that providers could block them.
Published loss figures differ: the FBI cited approximately $1.5bn, while several analyses put the figure nearer $1.4bn. The difference is a valuation question rather than a dispute about what was taken, and both figures are recorded here.
Law enforcement
The FBI published a public service announcement on 26 February 2025 attributing the theft to North Korean actors it tracks as TraderTraitor, and released Ethereum addresses used to launder the proceeds with a request that providers block transactions involving them.
Sources
- FBI Internet Crime Complaint CenterPrimary · retrieved 2026-08-01
- Federal Bureau of InvestigationPrimary · retrieved 2026-08-01
- SecurityWeekSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bybit hack — February 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bybithttps://itokenly.com/hacks/bybitPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.