In February 2025, Bybit, a cryptocurrency exchange based in Dubai, experienced a significant security breach resulting in the theft of approximately $1.5 billion worth of Ethereum. This incident is considered the largest cryptocurrency theft to date.
Details of the Hack:
Method of Breach: The attackers exploited vulnerabilities during a routine transfer from Bybit's offline "cold" wallet to a "warm" wallet used for daily trading. They manipulated security controls to redirect the funds to an unidentified address.
Stolen Assets: Approximately 400,000 Ethereum tokens, valued at around $1.5 billion at the time, were stolen.
Perpetrators:
Investigations by blockchain analytics firms Arkham Intelligence and Elliptic, along with the U.S. Federal Bureau of Investigation (FBI), have attributed the attack to the Lazarus Group, a North Korean state-sponsored hacking organization. This group has been implicated in previous significant cyberattacks, including the 2014 Sony Pictures hack and various cryptocurrency thefts.
Bybit's Response:
User Assurance: Bybit's CEO, Ben Zhou, assured users that all client assets are backed 1-to-1 and that the company remains solvent despite the loss. He emphasized that user funds are secure and that operations continue as usual.