Bybit Hack investigation - BitcoinMarket.net

On February 21, 2025, at around 20:16 UTC, someone at a desk inside Bybit clicked "confirm" on a transaction that looked like routine business. Twenty-one minutes later, 401,347 ETH — roughly $1.5 billion at the time — had vanished from one of the most closely guarded cold wallets in the industry. Not a cryptographic bug. Not a private key stolen through some run-of-the-mill malware. A surgical visual deception, engineered to fool the eyes of people who were doing exactly what security procedure told them to do.

It is the largest cryptocurrency theft in history. And the way it happened should unsettle anyone who has ever repeated, like a reassuring mantra, the line "we use a multisig, so we're safe."


How to Steal a Billion and a Half Without Breaking a Single Cryptographic Key

Bybit kept part of its reserves in an Ethereum cold wallet managed through Safe{Wallet} (formerly Gnosis Safe), the most widely used multisig infrastructure in the institutional space. The principle is simple and, on paper, robust: no transaction goes out unless multiple independent signers approve it, each verifying the content on their own device before signing.

The problem is that on that day, the signers — including CEO Ben Zhou — weren't verifying what they thought they were verifying.

Weeks earlier, the attackers had compromised the machine of a developer working for a third-party vendor of Safe{Wallet}. From there they injected malicious code into the interface used to sign transactions: when Bybit's signers opened the app to approve what looked like an innocuous transfer, the interface displayed clean, familiar data, while in the background the actual transaction contained a smart-contract logic upgrade — a change that handed the attackers full control of the funds.

Every signer saw exactly what the attackers wanted them to see. Every signer approved exactly what the procedure told them to approve. The multisig worked perfectly — it simply authorized the wrong transaction, because none of the human or technical layers of security was designed to detect a lying interface.

This is the point the industry struggles to admit: multisig protects against the theft of a single key. It does not protect against a compromised interface that lies to every signer at once. It's an attack on visual trust, not on the mathematics of cryptography — and that's exactly why it worked against a system that, on paper, was designed to be nearly impossible to breach.


Lazarus Group: The Signature of a State, Not a Gang

Within hours of the hack, on-chain analytics firms — Elliptic, Chainalysis, independent researcher ZachXBT — began tracing laundering patterns identical to dozens of other thefts attributed to Lazarus Group, the hacking unit tied to the North Korean regime. The FBI formally confirmed the attribution in the days that followed.

This is not an isolated event. By the agencies' own estimates, North Korea-linked groups have stolen more than $3 billion in cryptocurrency since 2017, with a marked acceleration in recent years: Ronin Bridge, WazirX, dozens of smaller exchanges. According to the United Nations, the stolen funds finance a significant share of Pyongyang's missile and nuclear programs — sanctioned and isolated from every traditional financial channel, yet perfectly operational on public blockchains.

Here lies the story's first structural paradox: we're talking about a military intelligence unit of a nation-state, with the resources, time and patience to infiltrate a third-party vendor for weeks before striking — not a teenager with an exploit downloaded from a forum. Defenses designed for exchanges, wallet providers and retail users are not built to stop adversaries of this caliber. And indeed, they didn't.


The Laundering: Fast, Distributed, Nearly Unrecoverable

In the hours after the hack, the stolen funds were split into thousands of transactions and funneled through mixers, cross-chain bridges, and in particular THORChain, a decentralized swap protocol that requires no KYC and which — precisely for that reason — became the preferred channel for large-scale laundering of stolen funds in 2025.

A key role was also played by eXch, an unregulated exchange that processed a substantial share of the Bybit funds before being shut down by German authorities in April 2025 — an action that came months after the hack, by which point most of the funds had already been converted, mixed and made vastly harder to trace.

Bybit responded by offering a bounty of up to $140 million to anyone who helped trace, freeze or recover the stolen funds, actively enlisting the on-chain analyst community. The result was partial: some shares were frozen on cooperating centralized exchanges, but the overwhelming majority of the funds remain, to this day, beyond the reach of any authority.


The Regulatory Paradox: The Law Chases the Wrong User

And this is where the Bybit story exposes something deeper than a single technical flaw. The entire regulatory framework the European Union and other jurisdictions have built around cryptocurrency — MiCA chief among them, with its KYC obligations, transaction traceability, travel rule on transfers — is designed to monitor the retail user: whoever buys, sells, or moves funds between wallets.

Not a single clause of that framework touches, even marginally, a state-sponsored hacking unit operating outside every cooperative jurisdiction, through infrastructure specifically designed to leave no trace back to an identity. The regulator built a system of pervasive surveillance over the honest user depositing €500 on an exchange, while remaining structurally blind to an actor moving a billion and a half dollars in twenty-one minutes.

This is not an enforcement gap. It is a structural misalignment between who the rule can actually control and who represents the real systemic risk.


The Hypocrisy of Institutional-Security Marketing

For years, the industry sold institutional clients — and not just them — on multisig as synonymous with "bank-grade" security: no single point of failure, no single key that alone can move funds, distributed control. That's a legitimate selling point, when it correctly describes what a multisig actually protects.

The problem arises when that pitch gets presented as an absolute guarantee, without mentioning that the whole architecture collapses if the interface signers use to "see" what they're signing gets compromised upstream. Bybit hadn't picked some fly-by-night vendor: Safe{Wallet} is, to this day, the industry's de facto standard. If it happened to them, at that level of adoption and scrutiny, it can happen to anyone else relying on the same trust model — a human signer trusting whatever a screen shows them.

The job of any platform that markets its own security should be explaining what multisig actually protects and what it doesn't — not selling a sense of infallibility that the facts have disproven in the most expensive way possible.


What Bybit Got Right

That said, it would be dishonest to tell this story only as a disaster. In the hours immediately following the hack, Bybit did something much of the industry has historically failed to do: it communicated transparently and quickly, activated bridge loans and liquidity lines from institutional partners to cover the shortfall, and managed to guarantee that every single user could keep withdrawing their funds without interruption or suspension.

No insolvency. No frozen customer accounts. Zero losses on the user side — the entire loss was absorbed by the exchange itself.

That's the clear, measurable difference between how FTX or Mt. Gox handled a crisis — where users discovered months or years later that they'd lost everything — and how an exchange handled the largest theft in crypto history while honoring every obligation to its customers within days. It doesn't erase the scale of the upstream security failure. But it's a fact that deserves the same attention paid to the technical disaster, because it shows that post-incident handling isn't a footnote — it's often what separates an exchange that survives from one that drags thousands of victims down with it.


What Remains, a Year and a Half Later

Looking back, the Bybit hack isn't a closed chapter: it's a case study the entire industry should have studied line by line, and one that instead risks being filed away as "just another hack" on a list that grows every year. The stolen funds have, for the most part, already been spent or converted into hard-to-trace assets — most likely to the direct benefit of a UN-sanctioned state program.

The message for anyone who blindly trusts the "institutional multisig" label should be simple: the security of a distributed system depends on the weakest link in the human and technical chain around it, not on the number of required signatures. And as long as regulation keeps chasing the retail user instead of confronting the risk posed by organized state actors, episodes like this won't be the exception. They'll be the standard.

Editorial note: facts verified live on 8/30/2026 through web research and scraping (public sources: Bybit statements, FBI, independent industry analysis — including Cloudskope breach intelligence). Confirmed data: February 21, 2025, ~$1.5 billion in Ethereum, attribution to Lazarus Group/TraderTraitor (North Korea), compromise of Safe{Wallet}'s development infrastructure, shutdown of eXch by German authorities.