Skip to content

News · Security

The Bybit theft was a company wallet. The chain did what signatures do.

About $1.5 billion in ether left an exchange cold wallet on 21 February 2025. Valid approvals moved it. That is custody, not a broken ledger.

ECGBy EasyCryptoGuides · Editor · Published · Updated · 2 min read

Rows of illuminated servers in a data centre
Photo on Unsplash
In this article

On 21 February 2025 ether and staked ether — on the order of four hundred thousand tokens, worth about $1.5 billion at the time — moved out of a Bybit wallet. It was widely described as the largest exchange theft on record. Customers watching a withdrawal queue, and everyone else watching a chart, were invited to treat those as the same story. They are not.

Public reconstructions pointed at a poisoned signing interface on a multisig setup: people who were supposed to authorise a routine transaction approved something else because the screen they trusted was lying. The network then did the only thing a public chain is good at. It executed valid signatures. Ethereum did not “get hacked”. A company wallet did.

What happened

Bybit is an exchange. The coins sat in addresses the firm’s processes controlled. Once the malicious transaction confirmed, the thief had coins on a ledger, not a login to unwind. Mixing, bridges, and thousands of onward addresses followed, as they do. On 26 February the FBI said North Korea was responsible, under the activity name TraderTraitor, and asked the industry to block related flows. Attribution is an intelligence claim with a press page. It does not move the coins back.

If you did not have a balance at Bybit, this is a lesson with someone else’s logo. If you did, it is a creditor-and-reimbursement story, and you should read Bybit’s own notices rather than a screenshot.

Why it matters

Multisig and “cold” are process words. They fail when the human sees a fake summary, when a vendor’s frontend is the actual root of trust, or when enough keys are in the wrong room. That is the same family as Ronin (validator keys) and FTX (a company database), not the family of a consensus bug. See how crypto wallets actually work and the practical checklist for keeping crypto safer — especially the part about not blindly signing what a website draws.

An exchange can promise to make customers whole and still have taught the market, again, that a balance in an app is a claim on an operator.

What happens next

Tracing, sanctions lists, and whatever Bybit publishes about customer balances. Treat “largest hack ever” as a ranking, not a strategy. Nothing here is an instruction to buy, sell, or withdraw in a panic.

Updated, August 2026

Bybit said it had sued the Democratic People’s Republic of Korea, the Reconnaissance General Bureau, and the Lazarus Group in the US District Court for the District of Columbia, with unnamed John Doe holders of traceable proceeds. Unsealed timeline reporting put a sealed filing in June 2026 and a preliminary injunction freezing some identified assets by late July; Bybit’s public statement on the suit and freeze was 7 August 2026. A freeze is a court order about specific wallets, not a protocol patch and not a recovery of $1.5 billion. We are recording it here rather than spinning a second URL.

Topics

This article is for information only and is not financial advice. Cryptoassets are volatile and you can lose money. See our disclaimer.

Comments

Keep it civil. First comments wait for an editor. This is not financial advice, and we remove spam or “DM me for signals” posts.

No comments yet. Be the first — keep it civil, and skip the tips.

Sign in to comment. Reading never requires an account.

Back to top

Continue reading

Stay a little clearer on crypto

Guides, reviews, and the news that actually matters. Unsubscribe anytime.

By subscribing you agree to our privacy policy.

More news

View all