The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →On or about February 21, 2025, attackers stole about $1.5 billion in crypto from Bybit by compromising the transaction-signing interface used for a transfer from an Ethereum cold wallet. Bybit’s signers approved what appeared to be a routine transaction, but the altered interface presented a malicious one. Public accounts describe a failure in the interface and approval process—not a demonstrated breach of Ethereum itself.
What happened at Bybit?
The FBI said on February 26, 2025, that the Democratic People’s Republic of Korea (DPRK) was responsible for stealing approximately $1.5 billion in virtual assets from Bybit on or about February 21. That is the FBI’s rounded valuation, not a precise dollar total that remains fixed as crypto prices move. Chainalysis described the principal movement as approximately 401,000 ETH, worth nearly $1.5 billion at the time; Elliptic’s early estimate was approximately $1.46 billion.
The theft was the largest crypto theft reported at the time, according to Elliptic’s February 2025 analysis. The comparison with the earlier Poly Network theft helps put the scale in context, but the figures come from different incidents and reporting dates.
| Incident | Reported amount | What the cited account says about the outcome |
|---|---|---|
| Bybit, February 2025 | About $1.5 billion, per the FBI’s February 26, 2025 announcement; Chainalysis estimated approximately 401,000 ETH. | Bybit’s August 7, 2026 announcement described an ongoing civil case and an injunction over identified assets; it did not give a comprehensive recovery total. |
| Poly Network, 2021 | $611 million, as cited by Elliptic in its 2025 analysis. | Elliptic said most of the stolen funds were eventually returned. |
FBI public service announcement, February 26, 2025; Chainalysis, February 24, updated February 27, 2025; Elliptic, February 23, updated March 5, 2025.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
How was the Bybit hack carried out?
Chainalysis’s account says the attackers gained access to a Safe developer’s computer and inserted malicious JavaScript into the Safe interface Bybit used. Safe is the transaction-signing interface involved in the transfer. During a transfer that appeared to move funds from Bybit’s Ethereum cold wallet to its hot wallet, the compromised interface caused signers to approve a malicious transaction. The assets then moved to addresses controlled by the attackers.
- Compromise the interface. The attackers altered the software interface used to prepare or review the transfer, according to Chainalysis.
- Exploit a routine approval. Signers believed they were authorizing an ordinary cold-to-hot-wallet transfer. The interface instead led them to approve a transaction that redirected the funds.
- Move the assets to attacker-controlled addresses. Once the transaction was approved and executed, the stolen crypto could be shifted and split across other addresses.
Sygnia’s June 18, 2026 investigation summary describes a more detailed sequence: social engineering against a developer workstation, stolen session tokens used to access AWS resources, an attempted fraudulent multi-factor authentication registration, and JavaScript injected into Safe’s AWS-hosted frontend. That is Sygnia’s investigation account; the FBI announcement does not independently set out those operational details.
Chainalysis’s account of the Bybit hack; Sygnia’s investigation summary, June 18, 2026.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Why didn’t cold storage and multiple signers stop it?
A cold wallet keeps its signing keys offline or otherwise separated from the systems used for routine, always-online hot-wallet operations. A multisignature arrangement requires approval from more than one signer. Those controls can reduce the risk of an attacker simply taking a key or draining a hot wallet, but they do not guarantee that an approved transaction is safe.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In this case, the reported weak point was what the human signers saw and approved. If the interface used to inspect a transaction is compromised, multiple people can approve the same deceptive request. The approvals may be valid under the wallet’s rules even though the signers were misled about the transaction’s destination or effect. Ars Technica’s contemporaneous explanation discusses both the multiple-signature process and the human and interface risks.
This distinction matters: the public accounts describe a compromise of the signing workflow and transaction interface. They do not establish that Ethereum’s consensus mechanism or the underlying blockchain was broken.
Rank #3
Ars Technica’s February 24, 2025 technical explanation.
When was North Korea blamed?
Attribution developed in stages. Early reports and analyst accounts on February 24, 2025, described North Korea as suspected or likely responsible, based on observed tactics and laundering patterns. Elliptic said it attributed the theft to North Korea based on its analysis of the laundering. Two days later, the FBI publicly stated that the DPRK was responsible.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThe FBI announcement is the U.S. government’s public attribution. The detailed technical descriptions cited here come from the named analytics and investigation firms; the FBI notice does not provide the same step-by-step account of the interface compromise.
Rank #4
Ars Technica, February 24, 2025; Elliptic’s analysis; FBI, February 26, 2025.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How did the stolen crypto move afterward?
Elliptic reported that the stolen tokenized assets were rapidly swapped into ETH. Unlike some tokens issued by a company that can freeze tokens under its control, ETH has no central issuer that can freeze it in the same way. In its March 5, 2025 update, Elliptic said that within two hours the funds had been distributed among 50 wallets holding about 10,000 ETH each, then moved through services including decentralized exchanges, bridges and centralized exchanges.
Those figures describe Elliptic’s time-specific tracing observations, not a complete account of every later movement or a current total of funds recovered. The Japanese Financial Services Agency’s March 2025 research paper summarized rapid coordination among exchanges, stablecoin issuers, investigators and analytics vendors. Its timeline records the FBI’s address list, a Bybit bounty, and early freezes and blocklisting efforts.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Elliptic’s March 5, 2025 update; Japanese Financial Services Agency research paper, March 2025.
What is the latest recovery and legal update?
On August 7, 2026, Bybit announced that it had filed a civil lawsuit in the U.S. District Court for the District of Columbia against the DPRK, its Reconnaissance General Bureau and Lazarus Group. Bybit said it had secured a preliminary injunction freezing identified stolen assets while the litigation continues. A preliminary injunction is not a final judgment, and the announcement does not establish that the named defendants have been found liable in a final ruling.
Bybit’s announcement did not publish a comprehensive amount recovered. The available update therefore supports saying that identified assets were subject to an injunction as of August 7, 2026—not that a stated share of the overall theft has been recovered. Bybit said it continues to cooperate with agencies including the FBI and share blockchain intelligence. In the same release, Bybit co-founder and CEO Ben Zhou said, “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable.”
Bybit’s civil lawsuit and injunction announcement, August 7, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




