Bybit Suffers Historic $1.4 Billion Hack: Developments Unfold

February 21, 2025, the cryptocurrency world was rocked by news of a massive security breach at Bybit, one of the leading centralized crypto exchanges. Hackers managed to siphon off approximately 401,346 ETH—valued at over $1.4 billion—from one of Bybit’s Ethereum cold wallets, marking it as the largest crypto exchange hack in history. As of today, February 22, 2025, the incident continues to unfold with significant developments, shedding light on the attack’s sophistication and Bybit’s response.
The Attack: A Sophisticated Exploit
The breach occurred during a routine transfer from Bybit’s Ethereum multi-signature cold wallet to its warm wallet, a standard procedure to maintain liquidity. According to Bybit co-founder and CEO Ben Zhou, the hackers executed a highly advanced attack by manipulating the transaction’s signing interface. The user interface (UI) displayed the correct destination address to the signers, masking a malicious alteration in the underlying smart contract logic. This deception allowed the attacker to seize control of the cold wallet and drain its contents.
Blockchain investigator ZachXBT was among the first to flag suspicious outflows, noting that the stolen ETH was quickly split across multiple addresses—initially 39, later expanding to over 53 wallets. Forensic analysis has since revealed that the attacker swapped liquid-staked tokens like mETH and stETH for ETH via decentralized exchanges (DEXs) such as Uniswap and KyberSwap, attempting to obscure the funds’ trail. Early speculation from security researchers, including ZachXBT and Chainalysis, points to the North Korean state-sponsored Lazarus Group as the likely culprit, given similarities to prior attacks like the Phemex hack in January 2025.
Immediate Fallout and Market Reaction
The confirmation of the hack sent shockwaves through the crypto market. Ethereum’s price dropped over 3% within hours, trading at around $2,727 as panic set in. Ethereum futures traders faced mass liquidations, with $76 million wiped out in just four hours, according to CoinGlass. The broader crypto community expressed alarm, with social media platforms like X buzzing with concern over centralized exchange security.
Bybit users initiated a wave of withdrawal requests—described by some as a “bank run”—with volumes reportedly reaching nearly 100 times normal levels. Despite the pressure, Bybit has maintained that its operations remain intact, processing most withdrawals, though some Ethereum-specific requests faced delays due to the breach.
Bybit’s Response: Transparency and Resilience
CEO Ben Zhou swiftly took to X and a livestream to address the crisis, reassuring users that the hack was isolated to one Ethereum cold wallet and that all other cold wallets remained secure. “Bybit is solvent even if this hack loss is not recovered,” Zhou stated, emphasizing that client assets are backed 1:1 and that the exchange’s treasury—estimated at over $20 billion in total assets—could absorb the loss. He clarified that Bybit would not buy ETH on the spot market to cover the shortfall, instead securing bridge loans from partners to cover approximately 80% of the stolen funds.
Bybit’s security team, alongside blockchain forensic experts, launched an immediate investigation. The exchange is collaborating with law enforcement and analytics firms like Arkham Intelligence to track the stolen assets. Arkham has offered a 50,000 ARKM token bounty for information identifying the hacker, with ZachXBT submitting evidence linking the attack to Lazarus Group on February 21 at 19:09 UTC. Bybit has also worked to blacklist the attacker’s addresses across Ethereum Virtual Machine (EVM) chains, aiming to hinder the laundering process.
Developments as of February 22, 2025
As of 11:56 AM CET today, several key updates have emerged:
-
Hacker’s Moves: The attacker, now holding over 500,000 ETH (more than Ethereum co-founder Vitalik Buterin’s 240,000 ETH), has liquidated around $245 million in stETH and begun bridging some funds to Solana. However, the flagged wallets are under intense scrutiny, making large-scale liquidation challenging.
-
Lazarus Group Connection: ZachXBT’s report, corroborated by Arkham, includes test transactions and wallet patterns tying the hack to Lazarus Group, notorious for funding North Korea’s regime through cyber theft. Analysts estimate a 15-30% recovery might be possible, though laundering $1.4 billion remains a daunting task for the perpetrators.
-
Bybit’s Stability: Despite initial panic, Zhou’s proactive updates have calmed some fears. Withdrawals continue, with 70% of the surge processed, though larger requests are undergoing compliance checks. The exchange’s proof of reserves, previously showing $16.2 billion in assets, suggests it can weather the 8.64% loss without systemic risk.
-
Industry Implications: The hack has reignited debates over centralized exchange vulnerabilities. Experts suggest it may push users toward non-custodial wallets and DEXs, while regulators could impose stricter security mandates.
Looking Ahead
The Bybit hack underscores persistent risks in the crypto ecosystem, where 2024 alone saw $2.2 billion in stolen funds—a 21.1% increase from 2023. For Bybit, the focus remains on fund recovery and fortifying defenses. Zhou has promised ongoing updates, with the next likely addressing investigation progress and any recovered assets.
For the broader market, this incident serves as a stark reminder: even robust platforms are not immune to sophisticated threats. As blockchain sleuths and law enforcement pursue the hackers, the crypto community watches closely—hoping for justice and stronger safeguards in an industry still finding its footing.
