Bybit $1.5B Hack event
Overview
In February 2025 the cryptocurrency exchange Bybit lost roughly $1.5 billion in ETH and stETH — over 400,000 tokens — in what is recognised as the largest single crypto theft on record. The attackers compromised the development environment of Safe{Wallet}, the multi-signature smart-contract wallet Bybit used, and manipulated a routine cold-to-hot wallet transfer so the funds were routed to addresses they controlled. The FBI attributed the attack to the North Korea-linked Lazarus Group (also tracked as TraderTraitor and APT38). Analysts estimated that at least $160 million was laundered within the first 48 hours as the funds were converted and dispersed across thousands of addresses.
Within the DeFi Intel graph, Bybit $1.5B Hack connects to 2 tracked entities, most strongly to Bybit, Bybit.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 2 of 2 total).
| Relation | Connected entity | Confidence |
|---|---|---|
victim_of | Bybit | 85% |
affected | Bybit | 70% |
Frequently asked questions
How much was stolen from Bybit?
Approximately $1.5 billion, consisting of more than 400,000 ETH and stETH, making it the largest single cryptocurrency theft recorded to date.
Who was responsible?
The FBI confirmed the North Korea-linked Lazarus Group — also known as TraderTraitor and APT38 — was behind the theft.
How did the attackers get in?
Rather than breaking the exchange's own systems, they compromised the development environment of Safe{Wallet}, the smart-contract wallet Bybit used, and intercepted a scheduled cold-to-hot wallet transfer to redirect funds to attacker-controlled addresses.
Sources
Facts on this page were verified against the following sources.