Cryptech Today
  • News
    • Market Watch
    • Policy & Regulation
    • Geopolitics & Economy
    • Security & Risks
  • Blockchain & Web3
  • Finance & Fintech
    • Cryptocurrency
    • Fintech & Digital Finance
  • Voices
    • Events & Interviews
    • People & Companies
No Result
View All Result
tokenomist ai
Cryptech Today
  • News
    • Market Watch
    • Policy & Regulation
    • Geopolitics & Economy
    • Security & Risks
  • Blockchain & Web3
  • Finance & Fintech
    • Cryptocurrency
    • Fintech & Digital Finance
  • Voices
    • Events & Interviews
    • People & Companies
No Result
View All Result
Cryptech Today
No Result
View All Result
Home Cryptocurrency

The Bybit hack: How the $1.4 bn attack happened and who is responsible

Pranav Joshi by Pranav Joshi
February 26, 2025
in Cryptocurrency, Ethereum
0
The $1.4 Billion Bybit Hack: How It Happened and Who Is Responsible
84
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

On February 21, 2025, the cryptocurrency world was shocked by the largest hack in history, where Bybit, a major crypto exchange, lost $1.4 billion worth of digital assets. The attack targeted Bybit’s cold wallets and resulted in the theft of Ethereum-based assets, including 401,000 ETH (Ethereum) and liquid-staked ETH tokens like stETH and mETH.

Table of Contents

Toggle
  • You might also like
  • Is Bitcoin Going to Reach Its Top in 2026? A Market That No Longer Moves on Tweets
  • Capitulation or Opportunity? Why Bitcoin’s Fall to $94K Changes the Playbook — $19B Liquidated, Whales Buying $4.6B
  • Trump’s Crypto Empire: How Policy, Family, and Foreign Alliances Built a Fortune
  • What is Bybit?
  • Bybit is a cryptocurrency exchange that allows users to buy, sell, and trade digital assets like Bitcoin, Ethereum, and Stablecoins. It has millions of users and is considered one of the largest platforms in the industry. To protect user funds, Bybit stores most of its assets in cold wallets, which are offline storage solutions that are harder to hack.
  •  
  • How did the Bybit hack happen?
    • Phishing attack – Tricking Bybit executives
    • Unauthorized transfer of funds
    • Laundering the stolen crypto
  • Who is Behind the Attack?
    • Lazarus Group – North Korean Hackers
  • Impact of the Bybit hack
    • Significant shake-up in investor confidence
    • Solana blockchain faces scrutiny
  •  What is Bybit doing to recover the stolen funds?
  • The Bybit hack and the lessons for crypto users

You might also like

Is Bitcoin Going to Reach Its Top in 2026? A Market That No Longer Moves on Tweets

Capitulation or Opportunity? Why Bitcoin’s Fall to $94K Changes the Playbook — $19B Liquidated, Whales Buying $4.6B

Trump’s Crypto Empire: How Policy, Family, and Foreign Alliances Built a Fortune

The primary suspect behind this massive hack is Lazarus Group, a well-known North Korean hacking organization responsible for several high-profile crypto thefts in recent years. But how did they manage to steal such a huge amount? Let’s break it down step by step.

What is Bybit?

Bybit is a cryptocurrency exchange that allows users to buy, sell, and trade digital assets like Bitcoin, Ethereum, and Stablecoins. It has millions of users and is considered one of the largest platforms in the industry. To protect user funds, Bybit stores most of its assets in cold wallets, which are offline storage solutions that are harder to hack.

Despite these security measures, hackers exploited a vulnerability in Bybit’s security system and stole funds from the exchange’s cold wallet.

 

Bybit detected unauthorized activity involving one of our ETH cold wallets. The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing…

— Bybit (@Bybit_Official) February 21, 2025

How did the Bybit hack happen?

Phishing attack – Tricking Bybit executives

According to security researchers, hackers use phishing attacks, which are techniques used to trick people into revealing their login credentials or approving malicious transactions.

  1. The attackers created a fake version of Bybit’s wallet management platform.
  2. They sent this fake interface to Bybit’s executives and security team, which looked like a real Bybit login page.
  3. Bybit employees logged in and unknowingly approved a fraudulent transaction, giving control of the exchange’s cold wallets to the hackers.

Unauthorized transfer of funds

Once the hackers gained access to Bybit’s cold wallets, they:

  1. Created a fake transaction that appeared to be a normal fund transfer.
  2. Disguised their actions to avoid raising suspicion from Bybit’s security team.
  3. Transferred 401,000 ETH and other assets to an external wallet controlled by them.

Laundering the stolen crypto

After stealing the funds, the hackers needed to convert the stolen crypto into cash without being detected. Here’s how they did it:

  1. The stolen Ethereum was sent to multiple wallets to hide its origin.
  2. Some of the funds were converted into Stablecoins (like USDC) and moved to the Solana blockchain.
  3. Hackers used Solana-based memecoin platforms to further launder the money.

Blockchain investigator ZachXBT discovered that some of the stolen funds were linked to previous memecoin scams on the Solana blockchain, strengthening the theory that Lazarus Group was involved.

Who is Behind the Attack?

Lazarus Group – North Korean Hackers

Security firms like Arkham Intelligence and Elliptic have identified Lazarus Group as the likely attacker.

Lazarus Group is a North Korean hacking organization known for stealing billions of dollars from crypto exchanges, banks, and financial institutions. Their goal is to fund North Korea’s government and missile programs. They have been linked to previous attacks, including: the 2022 Ronin Bridge Hack in which $620 million were stolen; the Harmony Bridge Hack that took place the same year in which $100 million were stolen and; the hacking of the Phemex Exchange that took place in January 2025. Around $29 million were reportedly stolen in the last attack.

    In the hacking of Bybit, blockchain traces show that the same wallets used in the Bybit hack were involved in previous Lazarus Group activities.

    Also Read

    Lithium is the new entrant in the Blockchain

    Impact of the Bybit hack

    Significant shake-up in investor confidence

    The Bybit hack has damaged trust in the crypto industry, especially in Centralized Exchanges (CEXs). Many investors are now:

    1. Withdrawing funds from CEXs.
    2. Moving to decentralized finance (DeFi) platforms, which do not rely on centralized wallets.
    3. Demanding stricter security measures from exchanges.

    Solana blockchain faces scrutiny

    The hackers used the Solana blockchain to launder stolen funds, which has raised concerns about security of the Solana network.

    1. Many memecoin projects on Solana have been exposed as scams.
    2. Investor sentiment towards Solana has dropped, leading to a 40% decline in active users.

     What is Bybit doing to recover the stolen funds?

    Bybit has taken several steps to recover the stolen funds and improve security:

    1. Tracking the stolen assets – Bybit is working with blockchain security firms to trace where the stolen crypto is being sent.
    2. Blocking suspicious wallets – Any wallet linked to the hack is being blacklisted to prevent the hackers from cashing out.
    3. Improving security measures – Bybit has promised to implement stronger anti-phishing protections and multi-layer authentication for fund transfers.
    4. Cooperating with law enforcement – International agencies, including Interpol and the FBI, are helping to track down the hackers.

    So far, crypto exchanges and regulators have frozen about $43 million worth of stolen funds.

    The Bybit hack and the lessons for crypto users

    This attack highlights the importance of strong security measures for both individuals and businesses in crypto. Here are some key takeaways:

    1. Always verify URLs – Before logging in to any crypto platform, double-check the URL to avoid phishing scams.
    2. Use hardware wallets – If you hold large amounts of crypto, store it in a hardware wallet instead of an exchange.
    3. Enable multi-signature wallets – Businesses should require multiple approvals for large transactions to prevent unauthorized transfers.
    4. Be cautious with new projects – Avoid investing in new and unverified meme-coins, as many turn out to be scams.

    Also Read

    Could Bitcoin replace gold as a marker of financial stability?

    Tags: Arkham IntelligenceBybitBybit HackCentralized ExchangesCEXsDecentralized FinanceDeFiEthereumHarmony Bridge AttackLazarus GroupmemecoinsmETHPhemex Exchange AttackRonin Bridge HackSolanaSolana blockchainStablecoinsStETHZachXBT
    Share34Tweet21
    Pranav Joshi

    Pranav Joshi

    A blockchain book author and crypto expert, dedicated to making cryptocurrency simple for everyone — byte by byte.

    Recommended For You

    Is Bitcoin Going to Reach Its Top in 2026? A Market That No Longer Moves on Tweets

    by Pranav Joshi
    January 6, 2026
    0
    Is Bitcoin Going to Reach Its Top in 2026? A Market That No Longer Moves on Tweets

    As we move through the first week of January 2026, the air in the crypto market feels different. Gone are the days when a single tweet could send...

    Read moreDetails

    Capitulation or Opportunity? Why Bitcoin’s Fall to $94K Changes the Playbook — $19B Liquidated, Whales Buying $4.6B

    by Pranav Joshi
    November 18, 2025
    0
    Bitcoin price chart showing death cross at $94k support; Fear & Greed Index at extreme fear 10; whale accumulation vs ETF outflows comparison

    Bitcoin plunged below $94,000 on November 17, 2025, erasing most of 2025’s gains and dragging the market into “extreme fear.” The Crypto Fear & Greed Index sits near...

    Read moreDetails

    Trump’s Crypto Empire: How Policy, Family, and Foreign Alliances Built a Fortune

    by Pranav Joshi
    September 16, 2025
    0
    Trump’s Crypto Empire: How Policy, Family, and Foreign Alliances Built a Fortune

    Trump Crypto Empire and Regulatory Capture is becoming one of the most defining forces in global finance. Donald Trump has tied nearly 73% of his wealth to cryptocurrency...

    Read moreDetails

    Shibarium Bridge Hack: $2.4M Stolen as Developers Freeze Staking

    by Pranav Joshi
    September 15, 2025
    0
    Shibarium Bridge Hack: $2.4M Stolen as Developers Freeze Staking

    In one of the most dramatic moments of the year for the Shiba Inu ecosystem, the Shibarium hack on September 13, 2025, sent shockwaves across the crypto world....

    Read moreDetails

    Trump’s $5 Billion Crypto Fortune: Where Personal Business Meets Public Policy

    by Pranav Joshi
    September 9, 2025
    0
    Trump’s $5 Billion Crypto Fortune: Where Personal Business Meets Public Policy

    Donald Trump’s cryptocurrency empire has ballooned into a $5 billion fortune, powered largely by his family’s stake in World Liberty Financial (WLF). What makes this story extraordinary is...

    Read moreDetails
    Next Post
    Chain analysis key to investigate cryptocurrency hacks

    Chain analysis key to investigate cryptocurrency hacks

    Related News

    Arizona state court building with legal documents and a gavel, symbolizing paused prosecution.

    Arizona Pauses Kalshi Prosecution Following Federal Judge Ruling

    April 13, 2026
    Traders monitor financial charts on multiple screens with S&P 500 logos in a digital trading hub.

    New Alternative Trading Platform Enables Round-the-Clock S&P 500 Betting

    March 19, 2026
    An online trading platform graphic with warning signs indicating regulatory action.

    Portugal Bans Polymarket Amid Growing Regulatory Pressure

    January 20, 2026

    Browse by Category

    • BlockBasics
    • Blockchain
    • Blockchain & Web3
    • Central Bank Digital Currency (CBDC)
    • Crypto
    • Crypto Now
    • Cryptocurrency
    • Ethereum
    • Finance
    • Fintech & Digital Finance
    • Geopolitics & Economy
    • GreenLedger
    • Inside CrypTechToday
    • Legal & Business Pages
    • Market Watch
    • People & Companies
    • Policy & Regulation
    • Politics
    • Security & Risks
    • Technology
    • World
    • About Us
    • Tools
    • Privacy Policy
    • Terms of Service
    • Disclosure
    • Cookie Policy
    • Disclaimer
    • Contact Us
    Mail Us @ contactus@cryptech.com

    © 2025 CrypTechToday All rights reserved.

    No Result
    View All Result
    • News
      • Market Watch
      • Policy & Regulation
      • Geopolitics & Economy
      • Security & Risks
    • Blockchain & Web3
    • Finance & Fintech
      • Cryptocurrency
      • Fintech & Digital Finance
    • Voices
      • Events & Interviews
      • People & Companies

    © 2025 CrypTechToday All rights reserved.

    Are you sure want to unlock this post?
    Unlock left : 0
    Are you sure want to cancel subscription?