Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →The FBI said on February 26, 2025, that North Korean TraderTraitor actors stole about $1.5 billion in virtual assets from Bybit on or about February 21. Bybit’s detailed estimate was approximately $1.46 billion, taken from one Ethereum cold wallet. The attackers were already converting assets and spreading them across thousands of addresses on multiple blockchains, the FBI warned.
What the FBI said—and what it did not
The FBI’s February 26, 2025, public service announcement attributed the Bybit theft to North Korean actors it calls TraderTraitor. It said the stolen assets were being converted into Bitcoin and other virtual assets and distributed across thousands of addresses on multiple blockchains. The agency expected further laundering and eventual conversion into fiat currency. The FBI asked exchanges, bridges, RPC providers, blockchain analytics firms, DeFi services and other virtual-asset providers to identify and block addresses associated with the laundering.
This was an FBI public service announcement and attribution notice, not a criminal indictment naming individual hackers or a complete technical forensic report. The FBI’s conclusion is the clearest official attribution in the available record; the evidence behind it should not be mistaken for a public confession or a court finding.
How the Bybit theft happened
Bybit’s account describes an attack on the signing workflow for one Ethereum cold wallet, not a demonstrated breach of the exchange’s entire trading platform. A cold wallet keeps assets outside routine online operations, while a multisignature wallet requires approvals from multiple signers. Those protections did not help if the signers were shown misleading transaction details.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
- Routine transfer: Bybit said it initiated a transfer from an Ethereum multisignature cold wallet to a warm wallet at about 13:30 UTC on February 21, 2025.
- Signing interface manipulated: Bybit said the Safe wallet interface associated with the signing workflow was compromised or manipulated. The transaction details displayed to signers allegedly did not accurately represent the action they were approving.
- Wallet logic changed: The signers approved a transaction that changed the cold wallet’s smart-contract logic, according to Bybit’s timeline. That change gave the attackers control of the targeted wallet.
- Assets transferred: At about 14:13 UTC, Bybit reported the malicious wallet-interface event. The assets left the wallet and were initially split across 39 addresses, according to Bybit.
Bybit’s preliminary investigation attributed the incident to malicious JavaScript affecting the Safe interface, rather than a compromise of Bybit’s core infrastructure. That is Bybit’s account and should be read alongside Safe’s separate statements: Bybit said Safe reported that its codebase was not compromised, that it found no malicious dependencies, and that other Safe addresses were not affected. Safe temporarily paused wallet functionality while it reviewed the service. These statements point to a targeted interface or development-environment compromise, not a finding that every Safe wallet was affected. Bybit’s incident timeline and its statement on infrastructure integrity provide the company’s account.
What was stolen
Bybit’s incident-time valuation was approximately $1.46 billion. The FBI’s widely reported $1.5 billion figure is a rounded estimate, not a separate exact accounting of the assets. The dollar amounts below are Bybit’s stated values at the time of the incident, not current market values.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
| Asset | Approximate amount | Bybit’s stated value at the time |
|---|---|---|
| ETH | 401,347 | $1.12 billion |
| stETH | 90,375 | $253.16 million |
| cmETH | 15,000 | $44.13 million |
| mETH | 8,000 | $23 million |
| Total | — | Approximately $1.46 billion |
The combined figure reflects the prices used when Bybit reported the loss. The value of crypto assets changes with market prices, so it should not be used as a current valuation or as a measure of how much was ultimately recovered. Bybit’s timeline lists the amounts and incident-time valuations.
Why investigators attributed the attack to North Korea
The attribution developed in stages. Blockchain investigators and analytics firms identified links and behavior they considered consistent with past North Korean cryptocurrency thefts; the FBI subsequently made its public attribution. Chainalysis said the tactics, techniques and procedures matched DPRK-linked activity. Elliptic independently analyzed the laundering trail and attributed the theft to North Korea. Both companies described evidence such as wallet relationships, test transactions, timing and conversion patterns—not a public identification of individual operators.
Recommended Free Tools
Rank #3
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
“North Korea,” “TraderTraitor” and “Lazarus” are related attribution labels, but they are not interchangeable legal entities. TraderTraitor is the FBI’s term in its announcement; Lazarus is a broader label used by investigators and industry analysts for North Korean-linked activity. The public evidence supports reporting the FBI’s attribution and the analysts’ assessments as attributed conclusions, rather than presenting a named group’s legal responsibility as settled in court. See Chainalysis’s analysis and Elliptic’s laundering analysis.
How the funds moved—and what “recovered” means
The FBI said the attackers converted some assets to Bitcoin and other virtual assets, then dispersed proceeds across thousands of addresses and multiple blockchains. Elliptic reported that much of the stolen Ether was converted to Bitcoin through eXch and other services. Moving assets, changing tokens and crossing chains can make following the trail more difficult, but a public blockchain can still expose transaction paths to investigators and analytics firms.
Rank #4
- EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
- 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
- TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
- WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
- SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.
- Tracked: investigators can see movements on public blockchains and associate addresses through analysis.
- Flagged: an address or transaction can be identified as linked to suspicious activity, but that alone does not stop it.
- Frozen: an issuer or centralized service with control over an asset or account may be able to immobilize it.
- Recovered: assets have been returned to Bybit or its customers. This is not the same as being traced or frozen.
- Laundered: assets have been moved or converted in ways intended to obscure their origin; that does not necessarily mean they have been cashed out successfully.
Bybit’s timeline reported that coordinated industry efforts froze or recovered approximately $42.89 million in exploited funds, and that Tether froze approximately $181,000 USDT linked to the incident. Those are reported figures, not proof that the entire theft—or any larger share of it—was returned. Bybit also offered a recovery bounty of up to 10% of recovered funds and published a suspicious-wallet blacklist/API for verified security partners. A bounty is an incentive for assistance, not evidence of recovery. Sources: Bybit’s incident timeline, its bounty announcement and its blacklist/API announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Did Bybit remain solvent?
The incident record shows no indication that the theft made Bybit insolvent. Bybit said it continued processing withdrawals and handled more than 350,000 withdrawal requests, with 99.994% completed within roughly 10 hours. It also said it received support through bridge loans, deposits and over-the-counter purchases. These are Bybit-reported figures and response details.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
Bybit said it restored a 1:1 reserve position for the relevant customer assets within 72 hours. A Hacken proof-of-reserves and proof-of-liabilities report commissioned by Bybit addressed that reserve position. It is evidence about the stated scope and point in time—not a universal audit of Bybit’s finances, governance, cybersecurity or all liabilities. Replacing missing assets to back customer balances is also different from recovering the assets from the attackers. Bybit’s announcement of the Hacken report describes the company’s reserve claim.
What the incident means for wallet security
The practical lesson is that a multisignature wallet can still fail if its signers trust a compromised screen. Requiring several approvals only helps when each signer can independently verify what the transaction will do. Cold storage likewise reduces some risks but cannot eliminate threats to the interfaces, devices, credentials and procedures used to authorize a transfer.
- Verify destination addresses, token amounts, contract calls and any wallet-logic changes through an independent channel—not solely the interface presenting the transaction for approval.
- Use transaction simulation or independent transaction rendering where available, and investigate any unexpected change in wallet permissions or contract behavior before signing.
- Separate approval duties and establish a pause-and-escalate process for unusual transfers; multiple signers should not rely on the same potentially compromised display.
- Treat wallet-management software, browser sessions, developer environments and signing devices as part of the custody security boundary.
- Plan for rapid incident coordination. Centralized exchanges and token issuers may have powers to block assets; decentralized protocols may not have a unilateral freeze mechanism.
A transaction visible on-chain does not prove a successful cash-out, and a frozen token is not necessarily permanently inaccessible. The limits depend on the asset and the service controlling it. Likewise, a hardware wallet can isolate private keys but does not automatically prevent a user from approving a malicious transaction shown by a compromised interface.
Timeline of the incident and response
- February 21, 2025: Bybit reported the Ethereum cold-wallet theft, which it said occurred during a routine transfer.
- February 22–24: Bybit described emergency response, withdrawal processing, recovery coordination and efforts to restore reserve coverage.
- February 25: Bybit announced a recovery bounty offering up to 10% of recovered funds.
- February 26: The FBI publicly attributed the theft to North Korean TraderTraitor actors and warned that funds were being converted and dispersed.
What is still not established publicly
The public accounts cited here do not establish the complete initial compromise path, the final disposition of every stolen asset, or the total amount permanently recovered. They also do not provide a full public technical forensic report or establish that specific individuals or services will face legal action. Those gaps do not undo the FBI’s attribution; they define what readers should not infer from a wallet trail, a reserve replacement or an agency announcement alone.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




