Bybit Hack: The Largest Crypto Theft in History & Its Impact on the Industry

The cryptocurrency industry has just witnessed the largest hack in its history, with over $1.4 billion in Ethereum (ETH) stolen from Bybit’s cold wallet. The attack, allegedly linked to North Korea’s Lazarus Group, raises serious concerns about security vulnerabilities in multi-signature wallets and how exchanges should handle security breaches.

Despite the staggering loss, Bybit has reassured customers that all withdrawals are being processed as usual, and the exchange has launched a Recovery Bounty Program, offering 10% of recovered funds to ethical hackers who assist in retrieving the stolen assets.

What Happened? A Sophisticated Exploit

According to blockchain security analysts, the hack was executed through a deceptive transaction that manipulated Bybit’s Ethereum cold wallet using Safe (formerly Gnosis Safe) multi-signature smart contract technology. The attackers tricked the signers into approving a malicious contract change, effectively giving them control over the wallet.

This advanced method of social engineering and contract manipulation highlights a growing trend of sophisticated exploits targeting crypto exchanges. Binance founder CZ noted that similar attacks have been carried out on other platforms like Phemex, WazirX, and Radiant Capital, raising concerns about the security of multi-sig wallet solutions.

Bybit’s Response: No Withdrawal Halts, But Full Transparency

Bybit’s CEO, Ben Zhou, has emphasized that the exchange never halted withdrawals, as the breach did not affect its internal systems or hot wallets. Instead, the attack was limited to a specific ETH cold wallet, allowing Bybit to continue processing withdrawals while investigating the breach.

Despite concerns from some industry leaders, including CZ, about the decision not to freeze withdrawals, Bybit defended its approach, stating that it was able to ensure client security without causing panic. Zhou reassured users:

“Even today, we can cover all client withdrawals, even from our own treasury. No matter what, we will make sure all client funds remain safe.”

The Aftermath: Unprecedented Withdrawals & Market Reaction

  • Over 350,000 withdrawal requests were processed within 12 hours, marking Bybit’s highest withdrawal volume in history.
  • 99.994% of withdrawals have been completed, with only a few remaining in queue.
  • Despite the scale of the attack, the crypto market has remained relatively stable, with no significant impact on Ethereum’s price action.

While some in the community called for a rollback of the Ethereum blockchain to recover stolen funds, industry leaders, including Ethereum co-founder Vitalik Buterin, dismissed the idea, emphasizing the immutability and decentralization of blockchain networks.

Who Is Behind the Attack? The Lazarus Group Strikes Again

On-chain analysis by ZachXBT and Arkham Intelligence has linked the Bybit hack to the North Korean cybercrime syndicate Lazarus Group, which has been responsible for some of the largest crypto heists in history.

  • The same hacker wallets used in the $29 million Phemex hack in January were directly tied to the Bybit exploit.
  • North Korean hackers stole over $1.34 billion in 2024 alone, accounting for 61% of all crypto thefts this year.
  • Past attacks include the $600 million Ronin Network hack and the $230 million WazirX breach.

These large-scale cyberattacks have prompted the United States, Japan, and South Korea to issue warnings about North Korea’s growing state-sponsored hacking operations, which allegedly fund the regime’s nuclear weapons program.

The Bigger Picture: What This Means for Crypto Security

This incident has reignited discussions about the security of multi-signature wallets and the need for better institutional safeguards in the industry.

Some key takeaways:

  • Multi-sig wallets are not foolproof – Even with multiple signers, attackers can still exploit vulnerabilities in transaction signing interfaces.
  • Cold storage isn’t always safe – While keeping funds offline protects against direct online hacks, social engineering and smart contract exploits remain a significant risk.
  • Exchanges must prioritize security investments – Bybit has committed to fundamentally transforming its security infrastructure following this attack.

Bybit’s Recovery Plan: The Recovery Bounty Program

As part of its damage control efforts, Bybit has launched a Recovery Bounty Program, pledging 10% of any recovered funds to ethical hackers who assist in retrieving the stolen assets.

Bybit CEO Ben Zhou expressed gratitude for the industry-wide support and vowed to use this “difficult lesson” to improve security:

“We have shared a dark moment in crypto history, but we’ve proven we are better than the malicious actors. Bybit is determined to rise above this setback and be a steadfast partner to our friends in the crypto community.”

Final Thoughts: Is Bybit Safe Moving Forward?

Despite suffering the largest crypto hack in history, Bybit’s quick response, transparency, and ability to maintain full operations have prevented an FTX-style collapse.

However, this incident serves as a stark reminder that no exchange is immune to attacks. Users are encouraged to practice self-custody whenever possible and remain vigilant about exchange security.

What’s next for Bybit? The full incident report and enhanced security measures are expected to be released in the coming days, providing further insight into how the exchange plans to prevent future breaches.


Addendum: How the Bybit Hack Happened: A Deceptive Smart Contract Exploit

Unlike traditional exchange hacks that typically target hot wallets (which contain assets readily available for withdrawals and trading), this attack was unique—it directly compromised Bybit’s Ethereum cold wallet, a supposedly safer storage mechanism.

Step 1: Targeting Multi-Signature Security Weaknesses

Bybit’s cold wallet relied on Safe (formerly Gnosis Safe), a widely used multi-signature (multi-sig) wallet provider. Multi-sig wallets are designed to enhance security by requiring multiple parties to sign off on transactions before they are executed. In theory, this setup makes it much harder for an attacker to drain funds.

However, the Lazarus Group exploited a critical weakness:

  • Instead of attacking Bybit’s servers or gaining direct access to private keys, the hackers tricked Bybit’s signers into approving a malicious smart contract upgrade.
  • This was done through a deceptive transaction—a “musked” UI exploit, meaning that the transaction details displayed to the signers looked completely normal, while in reality, the underlying code was executing something entirely different.

Step 2: A Trojan Horse Inside the Signing Process

  1. Manipulated Signing Interface:
    • The hackers created a fake transaction that appeared legitimate to Bybit’s team.
    • The signers believed they were approving a routine internal transfer.
  2. Hidden Smart Contract Exploit:
    • The real transaction wasn’t moving ETH to a known Bybit address; instead, it modified the smart contract logic governing the cold wallet.
    • This gave the hackers complete control over the wallet without triggering alarms.
  3. Instant Drain of Funds:
    • As soon as the transaction was approved, the Lazarus Group gained full authority over Bybit’s cold wallet.
    • They immediately transferred all stored ETH to an external address.

Step 3: Laundering the Stolen Crypto

With control of over $1.4 billion in ETH, the next challenge for the hackers was to launder the stolen assets without getting caught.

  • The stolen ETH was quickly moved through crypto mixers like Tornado Cash and cross-chain bridges like Chainflip, making it harder to track.
  • Some funds were converted into Bitcoin (BTC) and other assets, further obfuscating the trail.

On-chain investigators like ZachXBT have been closely monitoring these movements, linking the Bybit hack to the same wallets responsible for the $29 million Phemex hack in January.


How Was This Even Possible? The Risks of Multi-Sig Cold Wallets

This attack exposed a major flaw in multi-sig security—one that many exchanges haven’t fully accounted for.

1. Multi-Sig Wallets Can Be Manipulated

Multi-signature wallets only enhance security if all signers fully understand what they are approving.

  • In this case, Bybit’s team trusted the displayed transaction details without verifying the underlying smart contract logic.
  • This proves that even with multiple layers of security, social engineering and UI deception can still trick experienced teams.

2. Cold Storage Isn’t Bulletproof

The common belief that cold wallets are completely safe from hacks was proven wrong.

  • Even though Bybit’s cold wallet was offline, it was still governed by smart contract rules, which were exploited by the hackers.
  • This shows that cold storage solutions need even more scrutiny—especially when relying on third-party multi-sig solutions like Safe.

3. Crypto Exchanges Need Smarter Transaction Verification

A multi-layer verification process should have been in place:

Manual code review before approving any smart contract changes.
Whitelisting addresses to ensure funds only move between trusted wallets.
Delayed approvals for high-value transfers to allow time for security checks.

2/2

Facebook
Twitter
LinkedIn
Reddit

Subscribe to our Newsletter

All of the latest insights, our experts opinions, trends and changes we think you will want to know about.

Our Story

Welcome to our technical analysis service, launched in 2021 to provide insightful market analysis for traders at all levels. Our service centres around a live Trading Room, where we focus on using the Elliott Wave principle to interpret market trends. We cover a wide range of markets, including U.S. equity indices, stocks, precious metals, cryptocurrencies, energy, and forex, offering insights for both short and long-term trading strategies.

The expertise behind our analysis comes from Dr. Benedikt Burek. While Benedikt only began offering public analysis in 2021, his experience in trading and analysing markets spans over 15 years. This depth of experience ensures that our technical analysis is both insightful and reliable. Supporting Benedikt is a skilled team, working together to consistently provide high-quality technical analysis to our members.

Our roots trace back to a Youtube channel started in 2021, which quickly grew to 100,000 subscribers in about a year, thanks to the quality of our content. This success led us to expand our offerings, adding more channels and developing a range of membership services.

But what really makes our service stand out is our community. With over 3,000 members in our trading room, we offer an interactive space where traders can exchange ideas, ask questions, and contribute their own analysis. This vibrant community aspect enhances the overall experience for all our members.

For a comprehensive overview of our services, head to our Subscriptions page. Whether you’re new to the trading world or an experienced market player, we’re here to equip you with the insights and tools necessary for effective market navigation.