Skip to content

Bybit Cryptocurrency Exchange Hit by Historic $1.5 Billion Ethereum Hack

Table of Contents

Bybit, one of the world’s largest cryptocurrency exchanges, has confirmed a massive security breach, resulting in the theft of $1.5 billion in Ethereum (ETH). The hack, which occurred during a routine wallet transfer, is now being labeled as one of the biggest crypto heists in history.

Security analysts suggest the North Korean hacking group Lazarus may be behind the attack, given its past involvement in high-profile cryptocurrency thefts (Wired).

How the Hack Happened

Bybit revealed that the breach occurred during a cold wallet to hot wallet transfer, a typically secure process. However, hackers exploited a vulnerability in the transfer mechanism, potentially through an inside source or a supply chain attack.

Key Details of the Breach

  • The attack was detected on February 21, 2025, during a scheduled wallet maintenance process.
  • Over 350,000 unauthorized withdrawal requests flooded Bybit’s network in minutes, triggering security alarms.
  • Hackers immediately laundered the funds through decentralized exchanges (DEXs) and crypto mixers like Tornado Cash, making them difficult to trace (Blockchain.com).

Who is Behind the Attack?

Cybersecurity experts believe Lazarus Group, a North Korean state-backed hacking unit, orchestrated the breach. The group has been linked to previous attacks, including:

  • The $620 million Axie Infinity hack (2022) (BBC)
  • The $100 million Harmony Bridge exploit (2023) (CoinDesk)

Bybit’s Response and Customer Impact

Bybit CEO Ben Zhou reassured users that:

  • All affected customers will be reimbursed in full from Bybit’s emergency fund.
  • The exchange is working with law enforcement agencies and blockchain analytics firms to trace the stolen assets.
  • A $150 million bounty has been announced for information leading to the recovery of funds (Bybit Blog).

Lessons for the Crypto Industry

This attack exposes vulnerabilities in crypto exchange security. Experts recommend:

  1. Stronger multi-signature authentication for wallet transfers
  2. Routine penetration testing and real-time threat monitoring
  3. Encouraging self-custody—users should keep assets in personal cold wallets rather than centralized exchanges (Ledger).

Latest

ExpressVPN Pro vs. Surfshark One+: The Ultimate 2026 Privacy Suite Showdown
VPN

ExpressVPN Pro vs. Surfshark One+: The Ultimate 2026 Privacy Suite Showdown

In 2026, the battle for your digital privacy has moved beyond simple encryption. Both ExpressVPN and Surfshark have evolved into comprehensive security ecosystems, launching multi-product "suites" that target every corner of your online identity. If you are trying to decide between the high-octane ExpressVPN Pro and the feature-packed

Members Public
ExpressVPN launches ExpressMailGuard: The "VPN for Your Email"
VPN

ExpressVPN launches ExpressMailGuard: The "VPN for Your Email"

ExpressVPN has officially launched ExpressMailGuard, a dedicated email aliasing and inbox protection service designed to shield one of your most exposed digital identifiers: your email address. Launched in February 2026, the service acts as a "VPN for your email," allowing you to generate disposable aliases that mask your

Members Public
ExpressVPN Launches ExpressKeys Password Manager App
VPN

ExpressVPN Launches ExpressKeys Password Manager App

ExpressVPN has officially launched ExpressKeys, a standalone password manager app designed to help users store, generate, and manage passwords securely across devices. The new app replaces the built-in “Keys” feature that previously existed inside the ExpressVPN app, marking a clear move by the company to expand beyond VPN services and

Members Public
Private Browsing vs VPN: What Actually Changes

Private Browsing vs VPN: What Actually Changes

Private browsing modes and VPNs are often mentioned together as privacy tools, but they operate in very different ways and protect against different types of visibility. Many users assume that opening a private or incognito window hides activity from websites, ISPs, or employers in the same way a VPN does.

Members Public