Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How $1.46 Billion Was Stolen From Bybit’s Cold Wallet

The February 2025 Bybit theft exploited a compromised transaction-approval workflow around a Safe multisig cold wallet. Here is what Bybit, the FBI, and NCC Group reported, plus the exchange’s dated recovery figures.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On February 21, 2025, an attacker stole crypto from one of Bybit’s Ethereum cold wallets by compromising the transaction-approval workflow around its Safe multisignature wallet. Bybit’s preliminary account says Safe developer credentials were compromised; technical analysis by NCC Group explains how malicious code in the signing interface could make signers approve a transaction different from the one they thought they were reviewing. The attack did not establish that multisignature cryptography itself was broken. Bybit valued the stolen assets at about US$1.46 billion in its incident timeline.

What was stolen from Bybit?

Bybit’s incident timeline itemized the assets taken from one Ethereum cold wallet as follows. The quantities and approximate US-dollar valuation below are Bybit’s reported figures; the valuation is the company’s estimate in its 2025 timeline, not a fixed value for those tokens at every later date.

Asset Amount Bybit reported stolen
ETH 401,347
stETH 90,375
cmETH 15,000
mETH 8,000

Bybit put the combined value at about US$1.46 billion. The headline figure is therefore a dated valuation of the reported token amounts, rather than a claim that the same quantity would have the same market value later.

How was the Bybit hack done?

A routine transfer became the approval opportunity

Bybit described the event as a routine transfer from an Ethereum multisignature cold wallet to a warm wallet. In its February 26, 2025 preliminary forensic update, the exchange said Safe developer credentials had been compromised, giving the attacker access to Safe Wallet infrastructure. Bybit’s incident timeline says the Safe multisig interface was spoofed in a phishing-style attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

The approval screen did not reliably show what was being signed

NCC Group’s March 10, 2025 technical analysis describes malicious JavaScript manipulating the transaction data presented during approval. In practical terms, signers could see what appeared to be an ordinary transfer while their signatures authorized a change to the wallet’s smart-contract logic. That change gave the attacker control of the wallet’s contract implementation, after which the assets could be moved.

The crucial weakness was the gap between the transaction a signer believed they were approving and the transaction their signature actually authorized. Multiple signatures do not provide much protection if each signer is misled by the same compromised approval path.

Rank #2
Sale
TANGEM Crypto Wallet Pack of 3 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide (4.9 App Store, 4.8 Google Play) - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

What the incident does—and does not—show about cold storage

Cold storage describes how signing keys are kept; it does not guarantee that the transaction presented to a signer is trustworthy. Likewise, this incident is not evidence that Safe’s multisignature cryptography was cracked. The accounts available describe a compromised interface and signing workflow, not a mathematical break of the multisignature scheme.

Bybit said its preliminary investigation found no indications that its own infrastructure had been compromised. That is the company’s account of its investigation, not an independently established finding about every system involved. The reporting also does not show that an ordinary consumer hardware wallet would have prevented the attack: the described failure was in the interface and transaction approval path, and no cited source tested a consumer device against it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

Who did the FBI say stole the funds?

On February 26, 2025, the FBI attributed the theft to the Democratic People’s Republic of Korea (DPRK) and referred to the actors as TraderTraitor. Bybit’s own February 26 preliminary forensic update named Lazarus Group. These are attributed statements by the FBI and Bybit, respectively; they should not be collapsed into a claim that every detail of the attackers’ identities or operations has been independently established here.

The FBI said TraderTraitor actors were converting some stolen assets into Bitcoin and other virtual assets and dispersing them across thousands of addresses on multiple blockchains. That description indicates a broad laundering effort, but attribution and movement across addresses do not establish where every asset is now or whether it can be recovered.

Rank #4
DCENT Hardware Wallet | Biometric Cold Storage, Bluetooth, Multi-Crypto
  • EAL5+ CERTIFIED SECURE ELEMENT + FINGERPRINT PROTECTION — Your private keys stay encrypted offline on a certified EAL5+ chip, the same security tier used in EMV bank cards. Built by DCENT, securing crypto since 2018. Fingerprint authentication adds a second layer no PIN-only wallet can match.
  • 10,000+ ASSETS NATIVE ON 100+ BLOCKCHAINS — Hold Bitcoin, Ethereum, XRP, Solana, Cardano, popular stablecoins (USDT, USDC), and NFTs in one wallet. No third-party apps, no fragmented setup — every supported asset works straight out of the box.
  • TAP-TO-SIGN MOBILE EXPERIENCE — Pair your wallet with the DCENT mobile app over Bluetooth. Manage tokens, review transactions, and access in-app swap features directly from your phone — no cables, no desktop required.
  • WEB3 & dAPP ACCESS VIA METAMASK — Connect to MetaMask and other browser extension wallets to manage NFTs, claim airdrops, and access dApps. A large screen and intuitive 4-button interface keep every transaction clearly visible before you sign.
  • SEAMLESS FIRMWARE UPDATES & 30-DAY MONEY-BACK GUARANTEE — Apply security updates without resetting your wallet or migrating funds. Backed by Amazon's 30-day money-back guarantee — your purchase is risk-free.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Were Bybit customer funds safe after the theft?

Bybit’s reported response in 2025

Bybit’s March 3, 2025 incident chronology said withdrawals continued after the theft and that the exchange covered the ETH deficit through bridge loans, deposits from large holders, and over-the-counter purchases. The chronology also described a February 24 proof-of-reserves report by Hacken and Bybit’s claim that key assets had collateral ratios above 100% at that time.

Those statements describe Bybit’s response and reported reserve position in 2025. They do not by themselves establish the exchange’s current financial position, prove that every customer’s assets were continuously available, or substitute for an independent assessment of its present-day liabilities and reserves.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Trezor Safe 7 Crypto Hardware Wallet with Bluetooth for Android/iOS/Desktop
  • Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
  • Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
  • See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
  • Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
  • Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.

Recovery and litigation reported in August 2026

In a release dated August 7, 2026, Bybit said it had filed a civil lawsuit in the U.S. District Court for the District of Columbia against the DPRK, its Reconnaissance General Bureau, Lazarus Group, and John Doe defendants. Bybit said the court granted a preliminary injunction freezing identified assets during the litigation. The company quoted the court as finding that “Bybit has demonstrated a likelihood of success on the merits”; that quotation and description of the ruling are reported by Bybit, rather than cited here directly to the court record.

In the same release, Bybit reported approximately US$48.4 million recovered and more than approximately US$30.5 million frozen across more than 28 exchanges and custodians. It said the frozen assets remained subject to legal and investigative action and that proceedings were ongoing. These are Bybit’s figures and status as of August 7, 2026, not independently verified totals or a final judgment; recovery amounts can change as investigations and litigation continue.

What would make a signing workflow safer?

The incident points to safeguards around transaction review and approval, not simply to adding another device or another signer. A custody system’s practical resilience depends on whether it can detect a mismatch between what the interface displays and what is actually signed.

Quick Recap

  • Independently verify transaction data: Compare the destination, operation, and contract changes shown for approval with the transaction that the signing process will authorize. A screen controlled by the same compromised interface is not an independent check.
  • Limit what approvals can do: Restrict arbitrary contract operations where the system allows it, so a routine transfer cannot silently authorize a change to wallet logic.
  • Protect developer and interface access: Compromised developer credentials and web-interface code can affect what signers see, so access controls and review of changes to signing infrastructure matter alongside protection of private keys.
  • Plan for assets that move on-chain: Once funds are dispersed across chains and addresses, recovery may depend on tracing, cooperation from exchanges or custodians, freezes, and legal action. A freeze is not the same as a completed recovery.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.