Case file · BYBIT 2025

How the Bybit hack happened: a vendor's laptop and a screen that lied

Published 2026-09-29 · 5 min read · Missing control: Independently verify what signers approve

Bybit, one of the world's largest crypto exchanges, lost about $1.5 billion in a single transaction that its own executives approved. The screen they signed on had been quietly rewritten from inside another company.[1][2] This case file covers how a vendor's hacked laptop led to a $1.5 billion theft, what it cost, and the one control that was missing.

What happened

Bybit kept most of its ether in a "cold" wallet, one meant to stay offline and move money only when several authorized people each approve. To manage that wallet it used software from Safe, a widely used wallet provider whose web app lets a group of signers review and approve transfers.[2][4]

On February 4, 2025, a Safe developer's Mac was compromised through social engineering, according to the forensic report Safe released with the incident response firm Mandiant.[3][5] Attackers used access from that machine to get into the cloud storage that served Safe's web app, and about 2 days before the theft they swapped in altered code. It was built to stay dormant for everyone except a specific high-value target.[2][3]

On February 21, 2025, Bybit's signers sat down to move ether from the cold wallet to a "warm" wallet used for daily business. The screen showed the right addresses and the familiar Safe web address. What they actually approved changed the rules of the cold wallet itself and handed control to the attackers. More than 400,000 ether, worth about $1.5 billion, drained out. About 2 minutes later, the altered code was replaced with clean files.[2][4][6]

How they got in

The attackers never needed to break into Bybit. The forensic firm Bybit hired found no sign that its own systems were compromised.[2] Instead, they went after a supplier whose software sat in the middle of Bybit's most sensitive process.

A crypto approval is a signature on a block of technical data. People rarely read that data directly; they trust a web page to translate it into plain terms such as "send X to Y." The altered Safe page displayed an ordinary transfer while passing the signers something quite different underneath. Bybit's chief executive, Ben Zhou, who was the final signer, said afterward that he looked at the details but that the real destination was hidden inside the code he was approving.[4][6] Analysts call this blind signing: approving a transaction whose full effect you cannot see.[6]

Safe said its core smart contracts, the on-chain code that holds the money, were not affected. The weakness was in the web interface people used to read and approve transactions.[5] In other words, several careful people checked the same lie, because they were all looking at it through the same compromised window.

How it was caught

The theft was obvious within minutes, since the funds moved on a public blockchain. Bybit went public the same day, and Zhou held a livestream saying the exchange could cover the loss and that other wallets were untouched. The company said it had lined up bridge loans for most of the missing ether and kept processing withdrawals.[4][6]

On February 26, 2025, the FBI attributed the theft to North Korea, naming the group it tracks as TraderTraitor. It said the thieves were moving fast, converting the ether to bitcoin and other assets spread across thousands of addresses, and it published those addresses so exchanges could block them.[1]

What it cost

Bybit offered a 10% bounty to anyone who helped trace or freeze the funds, and by the time of the FBI alert more than $40 million had been frozen.[1] By early March, most of the stolen ether had already been converted to bitcoin across thousands of wallets, and only a small share had been frozen.[3] Safe said it put additional safeguards in place.[5]

The missing control

The missing control: independent verification of what signers actually approve. Every signer relied on the same web page to tell them what they were signing, and no separate check confirmed that the transaction matched the transfer they intended.

Multiple signatures are meant to stop one mistake or one bad actor. But if every approver reads the request through one shared screen, a single compromise fools them all at once. A check on a separate device or system, one that decodes the raw request and confirms the destination and action before anyone signs, would have flagged that this "transfer" was actually a change of control. Treating a vendor's web page as trusted, rather than verified, turned a supplier's breach into Bybit's loss.

What to do in your business

Watch the case
How a vendor's hacked laptop cost Bybit $1.5 billionDrops 2026-10-28
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Register: FBI officially fingers North Korea for $1.5B Bybit crypto-burglary
  2. BleepingComputer: Lazarus hacked Bybit via breached Safe{Wallet} developer machine
  3. The Hacker News: Safe{Wallet} confirms North Korean hackers stole $1.5 billion in Bybit heist
  4. The Record: Hackers drained Bybit crypto exchange
  5. Cointelegraph: Safe Wallet releases Bybit hack post-mortem
  6. American Banker: How hackers stole $1.5 billion in crypto from Bybit's cold wallet