SubscribeBTCSCAMWallet Test
Scam Database / Bybit Hack (Lazarus Group / TraderTraitor)
othercriticalStaff-verifiedethereumbitcoinmulti-chain

Bybit Hack (Lazarus Group / TraderTraitor)

DPRK's TraderTraitor (Lazarus) stole ~$1.5B in ETH from Bybit on Feb 21, 2025 via a compromised Safe{Wallet} developer machine — the largest crypto theft on record; under 4% of funds frozen.

First seen JAN 1, 2025Last seen 4d ago0 verified
Summary

On February 21, 2025, attackers drained roughly 401,000 ETH (about $1.46B at the time; the FBI cites ~$1.5B) from Bybit during a routine cold-to-warm wallet transfer — the largest cryptocurrency theft on record. Forensics showed the attackers had socially engineered a Safe{Wallet} developer, stolen AWS session tokens, and injected malicious JavaScript into the Safe front-end so Bybit's multisig signers approved what looked like a legitimate transaction while the underlying logic redirected funds to attacker wallets.

On February 26, 2025, the FBI (IC3 alert I-022625-PSA) officially attributed the theft to North Korea's "TraderTraitor" activity (Lazarus Group, tied to the Reconnaissance General Bureau) and published attacker ETH addresses, urging exchanges, bridges, and node operators to block them. Bybit replenished reserves within days, stayed solvent, and launched a "LazarusBounty" program offering 10% of recovered funds (up to $140M).

Laundering was rapid: TRM Labs tracked $400M moved by Feb 26, and by late March roughly 86% of the ETH had been swapped to Bitcoin, largely via THORChain, then dispersed across tens of thousands of wallets. Per Bybit CEO Ben Zhou's April 21, 2025 update, 68.57% remained traceable, 27.59% had "gone dark" through mixers (Wasabi, Tornado Cash, CryptoMixer, Railgun) and P2P/OTC channels, and only 3.84% was frozen (Chainalysis and partners froze $40M+). Figures conflict slightly — Bybit cites ~$1.4B, Elliptic $1.46B, the FBI ~$1.5B; the FBI figure is used here. As of early 2026, frozen funds remain under 4%, no perpetrators have been charged, and the operators remain at large in North Korea. On November 4, 2025, OFAC sanctioned DPRK banks (including Cheil Credit Bank, with 53 crypto addresses) and bankers laundering North Korean cybercrime proceeds; Elliptic estimates DPRK stole over $2B in crypto in 2025, driven chiefly by this hack.

Sources: [FBI IC3 PSA I-022625-PSA](https://www.ic3.gov/psa/2025/psa250226), [Chainalysis](https://www.chainalysis.com/blog/bybit-exchange-hack-february-2025-crypto-security-dprk/), [TRM Labs](https://www.trmlabs.com/resources/blog/the-bybit-hack-following-north-koreas-largest-exploit), [Elliptic](https://www.elliptic.co/blog/ofac-lists-53-crypto-addresses-of-sanctioned-north-korean-cheil-credit-bank), [CoinDesk](https://www.coindesk.com/markets/2025/04/21/over-usd380m-worth-of-crypto-stolen-during-bybit-s-usd1-4b-hack-has-gone-dark)

**Official action:** FBI IC3 PSA I-022625-PSA (Feb 26, 2025) officially attributing theft to DPRK TraderTraitor/Lazarus; OFAC sanctions on DPRK cybercrime-laundering banks and bankers (Nov 4, 2025)

Linked wallets

No addresses recorded yet.

Verify every address independently before acting · Not financial advice