Bybit Suffers $1.4 Billion Crypto Hack in One of the Largest Breaches

Bybit Hack: $1.4 Billion Crypto Theft Linked to Lazarus Group
TL;DR
- Bybit suffered a crypto hack worth more than $1.4 billion on February 21, 2025.
- The attacker stole Ether, stETH, mETH, and other ERC-20 tokens after compromising an ETH cold wallet transaction.
- Onchain investigator ZachXBT linked the attack to North Korea's Lazarus Group.
- Bybit CEO Ben Zhou said customer assets remained 1:1 backed and the exchange could cover the loss.
- Crypto firms including Tron, OKX, KuCoin, Aave, and Coinbase figures publicly supported Bybit or assisted with the investigation.
Bybit suffered one of the largest crypto exchange hacks on record after attackers stole more than $1.4 billion in digital assets from the platform on February 21, 2025.
The stolen assets included Ethereum (ETH), liquid-staked Ether such as stETH, mETH, and other ERC-20 tokens.
Onchain security researcher ZachXBT first flagged suspicious outflows from Bybit and later linked the attack to North Korea's Lazarus Group.
Despite the size of the theft, Bybit said its other wallets remained secure, withdrawals continued to operate, and customer assets remained fully backed.
What Happened in the $1.4 Billion Bybit Hack?
ZachXBT first reported unusual transactions leaving Bybit shortly after the attack.
He said a source confirmed that Bybit was dealing with a “security incident.”
The stolen ETH was later split across 39 addresses, making the movement of the funds more difficult to track.
Attackers also began swapping liquid staking tokens such as stETH and mETH into ETH through decentralized exchanges.
Onchain intelligence platform Arkham separately flagged large ETH and stETH outflows from Bybit, supporting early reports about the scale of the breach.
ZachXBT later urged exchanges and other crypto businesses to blacklist addresses connected to the attacker as the stolen funds continued moving.
How Was Bybit's Cold Wallet Compromised?
Bybit co-founder and CEO Ben Zhou confirmed that the attack involved one of the exchange's ETH cold wallets.
The exploit occurred while Bybit's multisignature cold wallet was making a transfer to a warm wallet.
According to Bybit, the signing interface displayed the correct destination address. However, the underlying transaction had been manipulated.
The malicious transaction changed the smart contract logic controlling the cold wallet.
This allowed the attacker to gain control of the wallet and transfer its assets to an unidentified address.
In simple terms, the transaction looked legitimate to the people approving it, while the code behind it performed something different.
The attack highlighted an important crypto security risk: multisignature wallets cannot protect funds if signers are shown misleading transaction information.
Bybit Says Customer Funds Remain Backed
The size of the hack quickly raised questions about whether Bybit could absorb a loss exceeding $1.4 billion.
Zhou said the exchange remained solvent.
“Bybit is solvent even if this hack loss is not recovered, all of the client's assets are 1-to-1 backed — we can cover the loss.”
Bybit also said its other cold wallets remained secure and withdrawals continued operating.
Coinbase executive Conor Grogan said Bybit still held more than $20 billion in assets and argued that the incident should not be compared with the collapse of FTX.
“Bybit is not an FTX situation. If it was, I would be screaming it out. They will be fine,” Grogan said.
Aave founder Stani Kulechov also publicly expressed confidence in Bybit's ability to handle the crisis.
Ethereum Falls After Bybit Hack
The breach also affected the broader crypto market.
ETH fell more than 3% after the incident was confirmed before beginning to stabilize.
The price reaction reflected concerns about the scale of the stolen Ethereum and the possibility that attackers could sell or move large amounts of ETH through decentralized markets.
Lazarus Group Linked to the Bybit Hack
Later on February 21, ZachXBT submitted blockchain evidence linking the Bybit attack to Lazarus Group, the North Korean state-backed hacking organization.
Arkham Intelligence accepted the findings and awarded ZachXBT a bounty of 50,000 ARKM, worth roughly $31,500 at the time.
The attribution placed the Bybit breach among a series of major crypto attacks associated with Lazarus Group.
The size of the theft also made the incident one of the largest cryptocurrency hacks recorded at the time.
Crypto Companies Help Track the Stolen Funds
Bybit received support from several major crypto companies following the breach.
Tron founder Justin Sun said his team was helping track the stolen assets.
OKX also said its security team was directly assisting Bybit with the investigation.
KuCoin publicly backed Bybit and CEO Ben Zhou, arguing that crypto security requires cooperation across the industry.
The coordinated response was important because stolen cryptocurrency can move rapidly across:
- Centralized exchanges
- Decentralized exchanges
- Cross-chain bridges
- Multiple wallets
- Other blockchain protocols
Rapid identification and blacklisting of suspicious addresses can make laundering stolen assets more difficult.
What the Bybit Hack Revealed About Crypto Wallet Security
The attack renewed debate about how exchanges protect large cryptocurrency reserves.
Yuga Labs Vice President of Blockchain, known as Quit, recommended several security measures after the incident.
These included:
- Multisignature authentication
- Hardware wallets for transaction signing
- Transaction simulations before transfers
- Careful verification of smart contract interactions
KuCoin also recommended basic account security measures such as:
- Two-factor authentication
- Strong and unique passwords
- Passkeys
- Careful verification of transactions
The Bybit attack showed that simply labeling a wallet as “cold storage” does not eliminate every security risk.
Human signers, transaction interfaces, smart contracts, and the software used to approve transfers can all become attack surfaces.
Bybit Hack Adds to February 2025 Crypto Exploits
The Bybit breach came during a month marked by several other crypto security incidents.
On February 14, ZkLend, a money-market protocol on Starknet, was exploited for about $9.5 million.
Cybersecurity firm Cyvers said the stolen assets were moved through Ethereum and Railgun, although Railgun later returned the assets.
Social-media accounts also became attack targets.
On February 5, accounts connected to Jupiter, a Solana-based DEX, and former Malaysian Prime Minister Mahathir Mohamad were compromised and used to promote fake memecoins.
Eliza Labs founder Shaw Walters also reported that his X account was hacked despite having two-factor authentication enabled. The compromised account was used to distribute scam links.
What the Bybit Hack Means for Crypto Exchanges
The $1.4 billion Bybit hack showed that even major exchanges using cold storage and multisignature systems can remain vulnerable to sophisticated attacks.
The breach did not appear to result from a simple theft of private keys. Instead, the attacker reportedly manipulated the transaction-signing process so that an apparently legitimate transfer changed the underlying wallet logic.
That distinction matters.
Crypto exchanges must protect more than wallets. They also need secure signing interfaces, transaction simulation, smart contract verification, strong operational controls, and systems capable of detecting abnormal activity before funds move.
Bybit said it remained solvent and that customer assets continued to be backed 1:1. Meanwhile, investigators and other crypto companies moved quickly to track the stolen assets.