The encyclopedia · Trading & Investing · Technical decision · 2025
Bybit's signers approved a transaction they couldn't see — $1.5B gone
Hackers hijacked the multisig signing screen Bybit used. Signers approved what looked like a routine transfer; 401,000 ETH left the cold wallet.
Bybit · 2025-02-21
What happened
Bybit, founded in 2018, had grown into one of the world's largest crypto exchanges by volume, holding tens of billions of dollars in client assets. Its main Ethereum cold wallet — the offline vault holding the exchange's own ether — was a multisig that signed transactions through Safe{Wallet}, a third-party signing interface.
On 19 February 2025, attackers who had compromised Safe{Wallet}'s infrastructure injected malicious code into its frontend. Two days later, when Bybit initiated a routine transfer from the cold wallet, the hijacked interface showed the three signers a disguised version of the transaction. They approved what they thought was normal; 401,000 ETH — about $1.5 billion — moved to addresses controlled by the attackers, the largest theft in crypto history.
Bybit kept withdrawals running, covered the hole with bridge loans from investors, and launched a Lazarus Bounty programme to trace the funds. Forensics by Sygnia and Verichains, alongside blockchain analysis from Elliptic and Arkham, attributed the theft to North Korea's Lazarus Group. Within days at least $300 million had been laundered beyond recovery, and roughly a fifth of the total was written off as unrecoverable.
Why it happened
- Multisig is only as strong as what signers can verify. A compromised signing interface can show one transaction and submit another, and the approvals follow the screen.
- Bybit concentrated roughly $1.5B in a single Ethereum cold wallet behind one signing workflow. One spoofed screen emptied the whole vault.
- The attackers went through the wallet vendor's infrastructure, not Bybit's. The trust boundary quietly extended to a third-party frontend nobody at the exchange controlled.
The lesson
Multi-signature protects only what signers can verify — treat the signing interface as untrusted and confirm the actual transaction, not the screen that displays it.
Sources
- CNBC — Hackers steal $1.5 billion from exchange Bybit, biggest crypto heist, 21 Feb 2025
- BBC — North Korean hackers cash out hundreds of millions from $1.5bn Bybit hack
- The Hacker News — Bybit Hack Traced to Safe{Wallet} Supply Chain Attack, Feb 2025
spotted an error? The club wants to know.
More like this
Hyperliquid's HLP vault took a $4M hit when a whale's 50x ETH position unwound
One tariff post met $217B of open interest — $19B liquidated in a day
Tsingshan's short squeeze broke the LME — $19.7B in margin calls, 9,000 trades cancelled
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.