SubscribeBTCSCAMWallet Test
Front page / News
criticalNews

How North Korea stole $1.46 billion from Bybit — and why the signature looked normal

A compromised Safe{Wallet} developer machine let attackers rewrite a transaction after it left the screen. Bybit's signers approved what they saw, not what they actually signed.

LV
Lena Vogt
Threat Intel Correspondent · JUL 22, 2026 · 5 min read
Painting: Renaissance archive · Source: FBI/IC3 Public Service Alert I-022625

On February 21, 2025, the Dubai-based exchange Bybit lost roughly $1.46 billion in Ethereum from a single cold wallet — the largest crypto theft on record. The FBI puts the figure at about $1.5 billion. What made it historic was not the size alone, but how ordinary the theft looked to the people who authorized it.

The stolen assets — more than 400,000 ETH plus staked-ETH derivatives — sat in a multisignature cold wallet, the kind of setup meant to be the safest place an exchange can keep money. Multiple trusted signers must each approve a transaction before funds can move. On paper, that is a strong defense. The attack was built to defeat it anyway.

The supply-chain compromise

Forensic reports commissioned by Bybit, from the firms Sygnia and Verichains, concluded that the attackers never breached Bybit itself. Instead they compromised a developer machine at Safe{Wallet}, the third-party provider whose interface Bybit's signers relied on, and injected malicious JavaScript into the live app at app.safe.global.

The tampered interface showed each signer a normal, expected transaction — while secretly altering the destination address and the contract logic behind it. The signers reviewed what looked correct and approved it. What they actually authorized routed the funds to attacker-controlled addresses. Investigators found no compromise of Bybit's own infrastructure.

This is the failure known as blind signing: approving a transaction you cannot fully verify, trusting the screen to tell the truth. When the screen itself is compromised, every human check downstream is defeated. A cold wallet did not help here, because the signers were confirming a transaction that had already been rewritten upstream.

Attribution and the laundering race

On February 26, 2025, the FBI's IC3 issued public service alert I-022625, attributing the theft to North Korea and tracking the activity as "TraderTraitor," linked to the Lazarus Group. The alert listed 50 Ethereum addresses and urged exchanges, bridges, node operators, and blockchain-analytics firms to block related flows.

The laundering began almost immediately. According to the FBI, the attackers converted ETH to Bitcoin and dispersed it across thousands of addresses using mixers and cross-chain bridges. Bybit said on February 24 that it had fully replenished its reserves, so customer funds were made whole — but chasing the money was another matter.

Recovery has been limited. In April 2025, Bybit CEO Ben Zhou reported that about 27.6% of the funds had "gone dark," with the majority still traceable at that point. By September, the exchange's LazarusBounty tracker showed more than $73 million frozen and just under $30 million recovered, with only about $102 million still traceable and more than $1 billion gone dark and unlikely to be recovered.

There have been pressure points. Per Chainalysis, Greece issued its first-ever crypto freezing order in July 2025, tracing funds with Chainalysis Reactor. On November 4, 2025, the U.S. Treasury's OFAC sanctioned North Korean financial facilitators; Treasury cited more than $3 billion in North Korean crypto theft over three years. The perpetrators remain at large.

What it means if you sign transactions

The Bybit lesson is uncomfortable: the weak point was not a password or a private key, but the trust placed in a signing interface. Whether you manage a multisig treasury or simply approve a transaction in a single wallet, the defenses are the same.

  • Verify the raw transaction data, not just the interface. Confirm the destination address and calldata independently, ideally on a separate device or through a second tool.
  • Treat blind signing as a red flag. If your wallet cannot show you exactly what you are approving, do not approve it.
  • Assume the software you sign through can be tampered with. Cross-check critical transfers against a known-good address list that you control.
  • Watch for supply-chain risk. A breach of a vendor, a library, or a developer's machine can reach you without ever touching your own systems.
  • For large or recurring transfers, use address allowlists and out-of-band confirmation so a single altered screen cannot move funds.

No signer in the Bybit case did anything visibly wrong. That is the point. The most dangerous transaction is the one that looks exactly like the one you meant to sign.

— Sources: [FBI/IC3 PSA I-022625](https://www.ic3.gov/psa/2025/psa250226) · [BleepingComputer](https://www.bleepingcomputer.com/news/security/lazarus-hacked-bybit-via-breached-safe-wallet-developer-machine/) · [Chainalysis](https://www.chainalysis.com/blog/greece-first-ever-crypto-seizure-bybit-hack-2025/) · [TRM Labs](https://www.trmlabs.com/resources/blog/us-treasury-sanctions-dprk-bankers-and-front-companies-laundering-proceeds-from-cybercrime-and-it-worker-operations)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING