DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
Bybit

How North Korea Pulled Off the $1.5 Billion Bybit Crypto Heist

The February 2025 Bybit theft was enabled by a compromised signing interface that misled transaction approvers. Here’s what investigators reported about the attack, North Korea attribution, laundering and the later injunction.

By TheFinanceBase Team 5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On or about February 21, 2025, attackers stole about $1.5 billion in crypto from Bybit by compromising the transaction-signing interface used for a transfer from an Ethereum cold wallet. Bybit’s signers approved what appeared to be a routine transaction, but the altered interface presented a malicious one. Public accounts describe a failure in the interface and approval process—not a demonstrated breach of Ethereum itself.

What happened at Bybit?

The FBI said on February 26, 2025, that the Democratic People’s Republic of Korea (DPRK) was responsible for stealing approximately $1.5 billion in virtual assets from Bybit on or about February 21. That is the FBI’s rounded valuation, not a precise dollar total that remains fixed as crypto prices move. Chainalysis described the principal movement as approximately 401,000 ETH, worth nearly $1.5 billion at the time; Elliptic’s early estimate was approximately $1.46 billion.

The theft was the largest crypto theft reported at the time, according to Elliptic’s February 2025 analysis. The comparison with the earlier Poly Network theft helps put the scale in context, but the figures come from different incidents and reporting dates.

Incident Reported amount What the cited account says about the outcome
Bybit, February 2025 About $1.5 billion, per the FBI’s February 26, 2025 announcement; Chainalysis estimated approximately 401,000 ETH. Bybit’s August 7, 2026 announcement described an ongoing civil case and an injunction over identified assets; it did not give a comprehensive recovery total.
Poly Network, 2021 $611 million, as cited by Elliptic in its 2025 analysis. Elliptic said most of the stolen funds were eventually returned.

FBI public service announcement, February 26, 2025; Chainalysis, February 24, updated February 27, 2025; Elliptic, February 23, updated March 5, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How was the Bybit hack carried out?

Chainalysis’s account says the attackers gained access to a Safe developer’s computer and inserted malicious JavaScript into the Safe interface Bybit used. Safe is the transaction-signing interface involved in the transfer. During a transfer that appeared to move funds from Bybit’s Ethereum cold wallet to its hot wallet, the compromised interface caused signers to approve a malicious transaction. The assets then moved to addresses controlled by the attackers.

  1. Compromise the interface. The attackers altered the software interface used to prepare or review the transfer, according to Chainalysis.
  2. Exploit a routine approval. Signers believed they were authorizing an ordinary cold-to-hot-wallet transfer. The interface instead led them to approve a transaction that redirected the funds.
  3. Move the assets to attacker-controlled addresses. Once the transaction was approved and executed, the stolen crypto could be shifted and split across other addresses.

Sygnia’s June 18, 2026 investigation summary describes a more detailed sequence: social engineering against a developer workstation, stolen session tokens used to access AWS resources, an attempted fraudulent multi-factor authentication registration, and JavaScript injected into Safe’s AWS-hosted frontend. That is Sygnia’s investigation account; the FBI announcement does not independently set out those operational details.

Chainalysis’s account of the Bybit hack; Sygnia’s investigation summary, June 18, 2026.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

Why didn’t cold storage and multiple signers stop it?

A cold wallet keeps its signing keys offline or otherwise separated from the systems used for routine, always-online hot-wallet operations. A multisignature arrangement requires approval from more than one signer. Those controls can reduce the risk of an attacker simply taking a key or draining a hot wallet, but they do not guarantee that an approved transaction is safe.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In this case, the reported weak point was what the human signers saw and approved. If the interface used to inspect a transaction is compromised, multiple people can approve the same deceptive request. The approvals may be valid under the wallet’s rules even though the signers were misled about the transaction’s destination or effect. Ars Technica’s contemporaneous explanation discusses both the multiple-signature process and the human and interface risks.

This distinction matters: the public accounts describe a compromise of the signing workflow and transaction interface. They do not establish that Ethereum’s consensus mechanism or the underlying blockchain was broken.

Ars Technica’s February 24, 2025 technical explanation.

When was North Korea blamed?

Attribution developed in stages. Early reports and analyst accounts on February 24, 2025, described North Korea as suspected or likely responsible, based on observed tactics and laundering patterns. Elliptic said it attributed the theft to North Korea based on its analysis of the laundering. Two days later, the FBI publicly stated that the DPRK was responsible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI announcement is the U.S. government’s public attribution. The detailed technical descriptions cited here come from the named analytics and investigation firms; the FBI notice does not provide the same step-by-step account of the interface compromise.

Ars Technica, February 24, 2025; Elliptic’s analysis; FBI, February 26, 2025.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did the stolen crypto move afterward?

Elliptic reported that the stolen tokenized assets were rapidly swapped into ETH. Unlike some tokens issued by a company that can freeze tokens under its control, ETH has no central issuer that can freeze it in the same way. In its March 5, 2025 update, Elliptic said that within two hours the funds had been distributed among 50 wallets holding about 10,000 ETH each, then moved through services including decentralized exchanges, bridges and centralized exchanges.

Those figures describe Elliptic’s time-specific tracing observations, not a complete account of every later movement or a current total of funds recovered. The Japanese Financial Services Agency’s March 2025 research paper summarized rapid coordination among exchanges, stablecoin issuers, investigators and analytics vendors. Its timeline records the FBI’s address list, a Bybit bounty, and early freezes and blocklisting efforts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Elliptic’s March 5, 2025 update; Japanese Financial Services Agency research paper, March 2025.

What is the latest recovery and legal update?

On August 7, 2026, Bybit announced that it had filed a civil lawsuit in the U.S. District Court for the District of Columbia against the DPRK, its Reconnaissance General Bureau and Lazarus Group. Bybit said it had secured a preliminary injunction freezing identified stolen assets while the litigation continues. A preliminary injunction is not a final judgment, and the announcement does not establish that the named defendants have been found liable in a final ruling.

Bybit’s announcement did not publish a comprehensive amount recovered. The available update therefore supports saying that identified assets were subject to an injunction as of August 7, 2026—not that a stated share of the overall theft has been recovered. Bybit said it continues to cooperate with agencies including the FBI and share blockchain intelligence. In the same release, Bybit co-founder and CEO Ben Zhou said, “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable.”

Bybit’s civil lawsuit and injunction announcement, August 7, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.