Bybit Cyberattack Leads to $1.5 Billion Theft in Ethereum Tokens
On February 21, 2025, Bybit experienced a cyberattack resulting in the theft of approximately USD 1.5 billion in Ethereum tokens, marking it as the largest exploit in crypto exchange history.
The FBI confirmed North Korean hackers, specifically the group known as TraderTraitor and Lazarus Group, were responsible for the incident. The attack involved intercepting a transfer from Bybit's cold wallet to a hot wallet.
Key points include:
- North Korea reportedly stole around USD 800 million in digital assets in 2024.
- The FBI advised exchanges and DeFi platforms to block transactions from North Korean addresses to prevent laundering of stolen assets.
- The hackers quickly converted some of the stolen funds into Bitcoin and distributed them across multiple blockchain addresses.
- Bybit's investigation indicated the breach originated from infrastructure managed by Safe{Wallet}, whose developer's machine was compromised.
- U.S. federal law enforcement provided a list of 51 Ethereum addresses related to the laundering of the stolen funds.
Forensic reports from Sygnia and Verichains confirmed these findings. Further analysis traced connections between the stolen funds and previous hacks on exchanges like Phemex and Poloniex.








