The biggest crypto theft in history
On February 21, 2025, the most severe attack in the history of cryptocurrencies took place. The Bybit exchange, the second largest in the world by volume after Binance and based in Dubai, suffered a theft of approximately 1.5 billion dollars in digital assets held in an Ethereum cold wallet. No blockchain was breached. No cryptographic bug was exploited. The weak point was human, infrastructural, and systemic. The attack revealed the inadequacy of the current hybrid Web3 architecture, founded on a paradox: decentralized tools built on centralized infrastructure.
February 21, 2025
At 13:30 UTC on February 21, Bybit performed a routine operation: the transfer of 30,000 ETH from one of its multi-signature cold wallets to a more accessible wallet, a so-called “warm wallet.” The movement, seemingly harmless, turned into a historic breaking point: 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH were stolen within a few minutes.
Estimated total damage:
- 401,347 ETH ≈ 1.12 billion dollars
- 90,375 stETH ≈ 253 million
- 15,000 cmETH ≈ 44 million
- 8,000 mETH ≈ 23 million
Total: ≈ 1.5 billion dollars
Comparison with previous hacks
| Hack | Date | Value stolen |
|---|---|---|
| Bybit | Feb 2025 | 1.5 billion USD |
| Ronin (Axie Infinity) | Mar 2022 | 620 million USD |
| Poly Network | Aug 2021 | 610 million USD |
| Mt.Gox (Tokyo) | 2014 | 850,000 BTC (~450M) |
| KuCoin | Sep 2020 | 275 million USD |
The attack on Bybit not only exceeds all previous ones in scale, but shifts the battlefield from internal blockchain vulnerabilities to a new level: the Web3 infrastructure supply chain.
Why this attack is “systemic-level”
The exploit did not target vulnerable smart contracts. It targeted the signing infrastructure that connected humans, software wallets, and cloud environments. It is a failed stress test for the entire crypto ecosystem, and in particular for the alleged invulnerability of multi-signature cold wallets, which have always been considered the gold standard of digital custody.
The dynamics of the attack: the “routine” transfer that wasn’t
The fraudulent transaction camouflaged itself as a routine operation. The signers saw—in the Safe{Wallet} GUI—a legitimate transfer. On-chain, however, the funds were being directed toward contracts controlled by the attackers. The interface showed a correct address, but the JavaScript code executed in the browser had modified the underlying logic of the signing package, altering the to, operation, and data parameters.
The role of Safe{Wallet} and the Web2 supply chain
Safe (formerly Gnosis Safe) is the most widely used multisig in the industry. Bybit used it to manage the 3-level signing of its cold wallets. The entry point of the attack was the compromise of a Safe developer’s machine, from which the attackers gained access to the AWS S3 bucket that hosted Safe’s public frontend.
By modifying the safe-transaction.js file, the attackers injected a JavaScript payload capable of recognizing when a Bybit signer was approving a transaction and modifying its content on the fly. The modified code was then served as if it were legitimate through AWS CloudFront.
This is the paradox: a solution designed to be decentralized and trustless that depended on a centralized CDN and unhardened cloud storage.
Lazarus Group: the “cyber arm” of North Korea
The attribution has been confirmed by the FBI and blockchain analysis firms such as Chainalysis and Elliptic. The group responsible is Lazarus, an elite unit of North Korea linked to the Reconnaissance General Bureau (RGB), a military intelligence agency.
Previous attacks: Lazarus’s trajectory, from espionage to crypto theft
The Lazarus group, identified as an operational unit under the Reconnaissance General Bureau (RGB), has transitioned in little more than a decade from information sabotage operations to sophisticated financial cybercrime campaigns. The progression shows a clear evolution: from targeting U.S. entities with geopolitical goals to building an industrial infrastructure for cryptocurrency theft.
Sony Pictures (2014): sabotage as a diplomatic weapon
The 2014 attack against Sony Pictures Entertainment marked Lazarus’s entry into the global cyber landscape. The motive was political: the distribution of the film The Interview, a satire on the Kim Jong-un regime. Lazarus penetrated the company’s internal network, destroyed 70% of internal servers and devices, and exfiltrated terabytes of confidential data, including private emails, payrolls, unreleased content, and personal employee information. The attack cost Sony tens of millions of dollars. It was proof that Lazarus operated not as a group of activists, but as a strategic state tool.
Bangladesh Central Bank (2016): the shift to financial theft
In February 2016, Lazarus exploited compromised SWIFT credentials of the Bangladesh Bank to attempt a $951 million theft from the Federal Reserve of New York. Only a typo in the beneficiary’s name (“Fundation” instead of “Foundation”) prevented complete success. However, $81 million was successfully transferred, largely laundered through Philippine casinos. It is the first documented case of a direct attack on an international banking system with a purely financial objective, marking the transition from sabotage to economic exploitation on a global scale.
Upbit (2019): Lazarus enters the crypto world
In November 2019, Lazarus breached the South Korean exchange Upbit, stealing 342,000 ETH (≈ $41 million at the time). The theft occurred from a hot wallet, compromised via a targeted attack. Unlike the Bangladesh case, the permissionless nature of blockchains allowed for faster execution and almost instantaneous dispersion of funds. The attack marks the group’s official entry into crypto-native crime: low risk, high speed, maximum liquidity.
KuCoin (2020): decentralized theft, but funds partially recovered
In September 2020, Lazarus hit the KuCoin exchange, based in the Seychelles but operating primarily in the Asian market. Approximately $275 million was stolen in a multitude of ERC-20 tokens and other assets on compatible blockchains. The difference compared to previous attacks was the partial recovery: over 80% of the funds were returned thanks to the collaboration between token developers, who froze contracts or re-deployed assets. The episode highlights two elements: Lazarus’s speed in attacking crypto infrastructure and, at the same time, the vulnerability of fungible assets to controls by the original teams.
Ronin / Axie Infinity (2022): the largest attack until 2025
On March 23, 2022, Lazarus hit the Ronin Network, an Ethereum sidechain developed for the game Axie Infinity. The group compromised five of the nine validators required to authorize transactions on the chain, managing to transfer 173,600 ETH and 25.5 million USDC, for a total of approximately $620 million. The attack is a lesson on the systemic risk of semi-centralized validation schemes disguised as decentralization. It is also the first case in which the U.S. Office of Foreign Assets Control (OFAC) sanctioned an Ethereum wallet directly, recognizing it as a North Korean state tool.
Atomic Wallet (2023): exploit outside the exchange
In June 2023, Lazarus compromised Atomic Wallet, non-custodial self-custody software used by millions of users. The exploit did not target an exchange, but private user devices. The group exploited a vulnerability in the wallet’s code to steal approximately $100 million in various cryptocurrencies. The attack shows a new frontier: targeting the individual user layer, bypassing all institutional controls. No coverage, no refunds. The identification of the exploit and the mitigation occurred too late for any significant recovery.
Lazarus is not a “normal” criminal group: it acts as a financial foreign policy tool for North Korea, converting crypto thefts into funding for nuclear weapons and ballistic missiles.
Laundering and fragmentation: phase 2 of the operation
As soon as the theft was concluded, the second phase of the operation began immediately: the systematic dispersion of the stolen funds. Those responsible for the attack, identified as members of the Lazarus group, activated a high-efficiency laundering plan, fragmenting and concealing the digital assets on a massive scale.
To convert the stolen Ethereum into Bitcoin, a series of decentralized exchanges (DEXs) and cross-chain bridges known for their lack of KYC (Know Your Customer) checks were used. These include THORSwap, Chainflip, Uniswap, and eXch, the latter already the subject of controversy for its initial lack of cooperation in blocking funds. The lack of mandatory identification allowed the attackers to move capital quickly without regulatory obstacles.
The process involved over 4,400 distinct crypto addresses, used to fragment the funds and make tracking more difficult. The strategy aimed to saturate on-chain surveillance tools and exchange compliance teams, making a timely response impractical. This tactic, known as “flood the zone,” is now part of Lazarus’s recurring modus operandi in large-scale thefts.
According to combined analyses by Elliptic and Bybit, approximately 90% of the stolen funds were converted into Bitcoin in the first days following the attack. Once transformed, the BTC were further routed through mixers, intermediary wallets, and cross-chain transactions on alternative blockchains.
At least 20% of the total funds are considered “gone dark,” meaning they are no longer traceable with current blockchain investigation tools. This segment includes coins already converted into cash, cryptocurrencies obfuscated via tumblers, or assets frozen in inactive wallets.
Despite the high sophistication of the plan, some countermeasures produced partial results: only 42.89 million dollars were frozen thanks to the coordinated intervention of some industry partners, including Tether, ChangeNOW, THORchain, and other operators who collaborated in identifying and blocking the compromised addresses. However, the recovered portion remains marginal compared to the total amount stolen.
Bybit’s LazarusBounty
On February 25, Bybit launched LazarusBounty, the first structured bounty program against a state-sponsored cybercriminal group. Up for grabs: 10% of the stolen funds, approximately $140 million for anyone who helps in tracing and blocking the funds.
As of March 10, 2025, the LazarusBounty program launched by Bybit has begun to produce the first concrete results. The initiative, designed to incentivize the tracking of stolen funds through the collaboration of the crypto community, has allowed for significant progress in mapping suspicious transactions.
In total, over 4 million dollars in rewards have already been distributed to subjects who provided useful information for the identification and blocking of approximately 40 million dollars in stolen assets. These reports allowed some exchanges and intermediary services to interrupt transactions or freeze funds before they were fully laundered.
At least 20 distinct collaborators – including independent analysts, forensics groups, and members of the crypto community – have taken an active part in the operation, reporting suspicious movements and mapping transaction paths in real-time. Although the amount recovered represents only a fraction of the total stolen, the operation demonstrates the effectiveness of a distributed and incentivized response against sophisticated state-sponsored attacks.
Impact on the market and users
The attack on Bybit had immediate consequences on the entire crypto market, generating turbulence both in terms of prices and the psychological state of investors. Starting from the day of the theft, market sentiment deteriorated rapidly, triggering a wave of selling that particularly hit the two most relevant assets in the ecosystem.
Bitcoin (BTC), which had reached its all-time high of $109,000 in January 2025, recorded a 20% drop, falling to $87,000 within a few weeks. The downward pressure was amplified by generalized fears regarding the security of crypto infrastructure, aggravated by the realization that even assets held in cold wallets could be compromised by indirect attacks.
Ethereum (ETH) suffered an even more violent contraction. From a price of approximately $6,200, it fell to $5,100 in just 48 hours, wiping out over $100 billion in market capitalization. The collapse was directly linked to the quantity of stolen ETH (over 400,000) and the subsequent on-chain fragmentation, which fueled uncertainty regarding the actual degree of asset traceability.
Paradoxically, despite the theft, activity on Bybit increased. In the days following the attack, the exchange recorded a +25% increase in trading volumes, driven by a massive return of institutional capital. This influx was not accidental: it occurred after the official announcement of the full coverage of the stolen funds and the full operational status of the platform.
To cover the capital hole, Bybit received $1.23 billion in ETH in less than 48 hours, coming from three sources: bridge loans, deposits from “whales,” and OTC (over-the-counter) purchases. The network’s response showed how, despite the attack, the exchange maintained solvency and operational trust from key industry players.
Within 72 hours of the incident, Bybit re-established a 1:1 proof-of-reserves, certified by external audits and validated on-chain. This helped contain the capital flight and stabilize the exchange’s position in the eyes of the market.
The most significant data, however, remains the net flow: $4 billion in funds flowed into Bybit in just 12 hours after the confirmation of capital coverage. It is an unequivocal signal: despite the severity of the attack, the speed and transparency of the response consolidated—rather than eroded—the trust of a significant portion of the user base, especially institutional users.
Why this hack marks a turning point
The attack on Bybit represents a structural fracture in the cryptocurrency security paradigm. The myth of the inviolability of multi-signature cold wallets has collapsed. For years considered the highest security standard, these tools proved vulnerable not in their cryptographic mechanisms, but at the point of human interaction. The transaction signature—considered the element of control—turned into the point of failure. The compromised user interface deceived the signers, inducing them to authorize a fraudulent operation. The result demonstrates that physical isolation (cold storage) is not enough if the signing environment is manipulable.
The second critical element concerns the structural dependence of the Web3 ecosystem on Web2 components. The theoretically decentralized infrastructure still rests on centralized services like AWS S3, CloudFront, and unverifiable JavaScript environments. The malicious code was injected into an S3 bucket and distributed via CDN as “official” content, evading every check. This makes it evident that the decentralization of protocols does not automatically imply resilience of the entire technological supply chain.
The attack also marks a definitive change in the nature of the adversary. It is no longer about individual hackers, but state actors with unlimited resources, strategic motivations, and advanced operational skills. The Lazarus group operates as an extension of North Korean state power, transforming every crypto theft into an act of financial foreign policy. The theft is no longer just an economic loss for an exchange, but a geopolitical issue with an impact on sanctions, international security, and the circulation of digital capital.
Finally, the attack vector abandoned the purely technical plane. It was not a bug in a smart contract or a flaw in a blockchain. The entire operation was based on cognitive and procedural vulnerabilities: social engineering, targeted phishing, runtime environment manipulation, and user blindness in the face of unreadable data. The new attack model no longer exploits mathematics, but the unawareness of the human operator and the absence of independent checks between what is displayed and what is actually signed.
The theft at Bybit is not just an incident. It is a technical and strategic demonstration that Web3, in its current form, is intrinsically exposed to unmitigated systemic risks.
The future of Web3
The Bybit hack is not just a theft, but an attack on the very architecture of modern decentralization. The blind trust in the security of multisigs and cold wallets is being dismantled not by a zero-day vulnerability or a cryptographic bug, but by a signature approved by a human being deceived by a falsified interface.
Web3, if it wants to survive, must reform itself starting from its foundations: code transparency, infrastructure resilience, and the ability to reduce human error to zero. Otherwise, the narrative of decentralization will remain an illusion on top of a vulnerable stack.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
