Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Bybit’s $1.5 Billion Crypto Hack: What Happened and What It Means for Customers

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On February 21, 2025, attackers stole about $1.46 billion in Ethereum-linked assets from one Bybit cold wallet. The FBI later attributed the theft to North Korea’s TraderTraitor operation; private investigators linked it to the Lazarus Group. Bybit kept withdrawals operating and said it restored 1:1 reserve coverage within roughly 72 hours—but that replenishment was not recovery of the stolen coins.

What happened at Bybit?

Bybit said the incident began during what appeared to be a routine transfer from an Ethereum cold wallet to a warm wallet. The signing workflow was manipulated so the transaction looked legitimate to the people approving it. Attackers then changed the targeted wallet’s control logic and moved its assets to an address they controlled. Bybit reported that one Ethereum cold wallet was compromised and that its other major wallets were unaffected. Bybit’s incident timeline describes the event and its response.

The theft was widely called the largest cryptocurrency hack or theft at the time, in February 2025. That is a dated ranking, not a permanent one. The dollar figure is also an estimate based on asset prices at the time, not a fixed measure of what those tokens are worth today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How much was stolen?

The FBI and many news reports rounded the loss to about $1.5 billion. Bybit’s more detailed accounting put it at approximately $1.46 billion and listed four Ethereum-related assets:

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Asset Amount Approximate value reported by Bybit
ETH 401,347 $1.12 billion
stETH 90,375 $253.16 million
cmETH 15,000 $44.13 million
mETH 8,000 $23 million

So the loss was not entirely plain ETH: much of it consisted of liquid-staking or wrapped assets linked to Ethereum. The rounded $1.5 billion and the more specific $1.46 billion are compatible descriptions, not competing counts of the same dollar value at every later date. Bybit’s breakdown gives the asset-level figures.

How the signing workflow was compromised

The available forensic accounts point to a compromise of the interface and infrastructure used in the signing process, not a demonstrated break of Ethereum’s base layer. Bybit used Safe{Wallet}, a third-party multisignature wallet platform. A later investigation by cybersecurity firm Sygnia described social engineering against a Safe developer, theft of session credentials, misuse of cloud resources and malicious JavaScript served through Safe-related infrastructure. The injected code reportedly manipulated what Bybit signers saw when they reviewed the transaction.

In simplified terms, the sequence was:

  1. A developer environment associated with Safe was compromised through social engineering.
  2. Attackers obtained access or session material tied to cloud resources.
  3. Malicious code was inserted into or served through the wallet interface used in the approval flow.
  4. Signers were shown a representation that appeared consistent with a legitimate transfer, while the transaction’s effective behavior altered the wallet’s control path.
  5. After approval, the attacker transferred the assets out and dispersed them among many addresses.

Sygnia’s account adds details including the reported compromise of a developer’s macOS workstation, AWS access and an attempted registration of a fraudulent MFA device. These are findings attributed to that investigation, rather than a court finding about the identity of individual attackers. See Sygnia’s technical overview and its investigation summary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

This distinction matters: “cold wallet” does not necessarily mean an entirely offline, air-gapped system. A multisignature cold-storage setup may rely on signing machines, wallet software, browser interfaces, cloud-hosted code, hardware devices and human review. The private keys need not be stolen directly for an attacker to exploit the process that constructs and displays a transaction. Multisig reduces the risk of a single stolen key being enough, but it cannot protect signers who approve malicious instructions presented through a compromised interface.

Why investigators linked the theft to North Korea and Lazarus

Attribution has different levels of certainty and should be described precisely. The FBI formally attributed the theft to North Korea and called the activity TraderTraitor. It said the stolen assets were being rapidly converted and dispersed across thousands of addresses on multiple blockchains. The FBI’s public notice is the government attribution.

Separately, blockchain analytics firm Chainalysis and private forensic investigators linked the operation to Lazarus Group activity based on fund movements, attack methods and similarities to earlier DPRK-associated operations. Those assessments provide context for the FBI attribution, but they are not a criminal conviction establishing the identity of each person involved. Chainalysis’ analysis discusses tracing and the broader DPRK-linked pattern.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Bybit’s response: withdrawals, reserves and a recovery effort

The hack immediately raised a practical question for customers: could they withdraw, and could Bybit meet its obligations? Bybit disclosed the incident publicly, its chief executive addressed it in a livestream, and the exchange continued processing withdrawals. Bybit reported more than 350,000 withdrawal requests, with 99.994% processed within 10 hours.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To close the ETH reserve gap, Bybit said it sourced assets through bridge loans, over-the-counter purchases, whale deposits and support from industry partners. It reported that customer-asset reserve coverage returned to a 1:1 ratio within about 72 hours. Hacken reviewed the relevant proof-of-reserves material; Bybit’s announcement describes the review and its scope. The exchange also launched a recovery bounty offering up to 10% of recovered stolen funds. See Bybit’s 72-hour reserve announcement and its recovery bounty announcement.

These are three separate outcomes: withdrawals continued; the exchange said it replenished reserves backing customer claims; and the original stolen assets would need to be traced and returned to count as recovered. Bybit’s reserve response supports the first two, not the third. The FBI described the assets as dispersed and subject to further laundering and conversion. The available evidence does not establish that the original haul was fully recovered.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Did Bybit remain solvent?

Bybit said it remained solvent and reported sufficient reserves for in-scope customer liabilities in its proof-of-reserves materials. A Hacken review published shortly after the incident reported 1:1 coverage for the assets it examined. Bybit has also published later proof-of-reserves reports, including reports dated November 19, 2025 and May 27, 2026.

That evidence is relevant, but it is not a blanket guarantee of the exchange’s financial condition or future ability to meet every obligation. Proof-of-reserves reporting is tied to a date, scope and methodology. It does not, by itself, establish the quality of every liability calculation, operational control, governance process or counterparty exposure, nor does it show that stolen tokens have been recovered. Read any reserve claim with the report’s date and coverage in mind. Bybit’s May 2026 report is a later snapshot, not evidence that the 2025 theft was undone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the incident means for crypto custody

The Bybit case was a major security failure in a signing workflow, but it does not show that Ethereum itself was cryptographically broken. Nor does it mean that multisignature wallets are useless. It shows that custody depends on more than key storage: the code that builds a transaction, the interface that renders it, the devices and accounts used by signers, and the policies governing approval all matter.

Best Value
Sale
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
  • Verify what the transaction does, not only what a screen says. For high-value transfers or changes to wallet logic, organizations need independent transaction rendering and a way to verify destination, permissions and contract changes outside the potentially compromised interface.
  • Treat vendors and developer environments as part of the custody perimeter. A third-party interface can be a critical link even if the exchange controls its own signers and keys.
  • Use policy controls and out-of-band checks. Separate approval channels, transaction simulation, limits and additional scrutiny for contract upgrades can make a deceptive request harder to pass.
  • Plan liquidity and communications before an incident. Bybit’s ability to keep withdrawals open and source assets helped contain customer panic, but emergency funding and replenishment raise questions users should assess for any exchange.

What customers can do

This incident alone cannot establish whether an exchange is safe or unsafe for every customer. The right balance depends on whether you need trading liquidity, how long you plan to hold assets, your jurisdiction and your ability to manage self-custody securely. Consider the following practical steps:

  • Keep on an exchange only the amount you need for active trading or near-term use, if that fits your circumstances.
  • Review the exchange’s withdrawal process, security options, reserve-report scope and jurisdiction-specific terms. A reserve snapshot is one input, not a complete risk assessment.
  • Enable phishing-resistant hardware authentication for exchange, email and password-manager accounts where supported, use unique credentials, and secure account recovery methods.
  • For long-term self-custody, understand seed-phrase backup, recovery and inheritance before moving a significant balance. Test the process with a small amount first.
  • Verify addresses and transaction details through an independent channel. A hardware wallet does not automatically prevent phishing or a misleading signing interface.
  • Be wary of unsolicited messages promising to recover stolen crypto. A recovery bounty or investigation does not legitimize an unknown party asking for seed phrases, private keys or advance payments.

Self-custody reduces reliance on an exchange but shifts responsibility to the owner: lost seed phrases, malware, phishing, signing mistakes and poor recovery planning can be irreversible. Institutional custody may offer additional governance and policy controls, but introduces fees, onboarding, counterparty dependence and possible withdrawal constraints. Neither approach removes risk; the useful question is which risks you can understand and manage.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.