#1 ranked: CoinbaseLearn and Earn rewards plus $10 for your first $100 traded (new customers only)Check offer →
CryptoRanking
Crypto News

Bybit Suffers $1.5 Billion Hack, the Largest Crypto Theft in History

On February 21, 2025, the Dubai-based cryptocurrency exchange Bybit disclosed that attackers had stolen approximately $1.5 billion in Ethereum and staked ETH (stETH) from one of its cold wallets, instantly making it the largest single theft in the history of cryptocurrency exchanges, surpassing the 2022 Ronin Network hack (roughly $625 million) and the 2021 Poly Network exploit (roughly $611 million).

Investigators determined that the breach did not stem from a flaw in Bybit's own code, but from a compromise of the infrastructure behind Safe Wallet, the third-party multisignature wallet interface Bybit used to manage its cold storage. Attackers reportedly manipulated the transaction-signing interface so that Bybit's authorized signers approved what appeared to be a routine transfer, while the underlying transaction data had been altered to redirect the funds to wallets controlled by the attackers — a technique often described as exploiting "blind signing."

On February 26, 2025, the U.S. Federal Bureau of Investigation issued a public service announcement formally attributing the theft to North Korea's Lazarus Group, a state-linked hacking operation the FBI and blockchain-analytics firms have tied to years of cryptocurrency theft used to fund the Democratic People's Republic of Korea's weapons programs. Firms including Elliptic and Chainalysis corroborated the attribution through wallet-clustering analysis and similarities to previous DPRK-linked operations.

Stolen funds were rapidly dispersed through decentralized exchanges, cross-chain bridges, and mixing services in an effort to obscure the trail; blockchain investigators estimated that a meaningful share of the funds became untraceable within the first day or two. Bybit co-founder and CEO Ben Zhou stated that the exchange remained solvent and that no customer funds were lost, covering the shortfall through bridge loans and reserves, and the exchange launched a bounty program offering a percentage of any recovered or frozen funds to individuals and firms assisting in the tracing effort.

The incident triggered renewed industry-wide scrutiny of multisignature wallet security practices and the risks of "blind signing" in transaction approval workflows. The hack remains, as of this writing, the largest crypto exchange theft on record.

← All news