Analysis: How the $1.4 Billion Bybit hack happened

TLDR;
.
- The $1.4 billion lost by Bybit in a hack is the largest that a cryptocurrency exchange has ever lost to hackers so far
.
- The hack took place on February 21, 2025, and is attributed to the North Korean hacking outfit called the Lazarus Group, also known as TradeTraitor
.
- They compromised a Safe wallet�s developer machine, consequently gaining access to Bybit funds
.
Although Bybit lost $1.4 billion in a hack on February 21, 2025, hackers started knocking on the exchange�s gates as early as February 4. With Bybit having some of the stringent security measures in the industry, the attackers exploited a human weakness by compromising a Safe wallet developer�s machine. But how did the developer�s machine give them entry into Bybit, one of the leading crypto trading platforms?
.
Below is a brief analysis of how the hackers siphoned $1.4 billion without immediate detection.
.
First, let�s get the basics out of the way.
What is the connection between the Safe wallet and Bybit?
The Safe wallet provided Bybit employees with a multi-signature platform to help sign transactions when moving funds from the exchange�s cold storage to its hot wallets. Here�s how this happens. Bybit stores most of its cryptocurrencies in a cold wallet to minimize the chances of hackers getting their fingers into the pot.
.
However, these funds can�t stay in the offline wallet forever, and the exchange needs to move some of them to its hot wallet to ensure a smooth running of its withdrawal process. To prevent one employee from having the sole power to withdraw funds from its wallets, it uses a multi-signature infrastructure.
.
The multi-sig solution is offered by the Safe wallet. Therefore, if you manage to access the Safe wallet, you are ten steps closer to Bybit funds, as you can sign the transactions, authorize withdrawals, or hijack the funds once the authorized entities sign the transactions.
.
Now that we know the connection between the Safe wallet and Bybit, let�s dive deeper.
The A-Z of the Bybit hack
The hackers� first target was the Safe wallet. On February 4, 2025, they managed to enter the wallet by gaining access to the computer of one of the wallet developers. The attackers did this by tricking the developer to install a seemingly �harmless� software package known as a Docker container.
.
Once inside the developer�s PC, they visited the exchange�s code repository hosted by Amazon Web Services, or AWS. However, their knock on the repository was unsuccessful.
.
Undeterred, they spent almost two weeks secretly monitoring how AWS systems work and what they needed to gain access to Safe�s account on the platform. They noticed that AWS sessions are governed by temporary access tokens.
.
These tokens allow developers to save/commit code and access web servers. The hackers gained access to these tokens via a private virtual network or VPN, enabling them to get closer to Bybit's coffers.
.
Armed with AWS� temporary session tokens, they accessed Safe wallet�s code repository and added malicious code into it.
What did Bybit hackers do to the Safe wallet?
The malicious code delivered to the wallet�s AWS repository targeted Safe�s user interface (UI). The code allowed the attackers to silently deflect users' withdrawals for four days without detection. They managed to do this because the user interface remained the same and only compromised the mechanics in the background.
.
Another interesting thing is that they managed to target only transactions initiated by Bybit employees. To explain further, the code allowed the attackers to stand between the source (Bybit cold wallets) and the destination (Bybit hot wallets).
.
Being at the centre, they waited for authorized exchange employees to sign transactions to transfer funds to hot wallets and then change the destination address before the funds were deposited into Bybit�s hot wallets. The hackers also initiated a withdrawal request which the Bybit team signed without knowing it wasn�t a genuine transaction.
After the hack
The funds were originally in Ethereum (ETH). 401,000 ETH to be precise. They traded them for Bitcoin (BTC) and other cryptocurrencies. They then moved them across multiple blockchains in what is called chain hopping to confuse on-chain sleuths. That�s not all, they also used crypto-mixing services and decentralized exchanges to further throw investigators off their tracks.
.
Bybit acknowledged that 20% of the funds are completely untraceable. The exchange is still working with blockchain investigators and law enforcement agencies in an attempt to recover some of the funds. The FBI has confirmed that the Bybit hack was conducted by the state-sponsored North Korean hacking group Lazarus.
Conclusion
The human factor remains the weakest link in securing crypto-based projects. Bybit hackers knew this and went for Safe wallet�s developer machine by first tricking the ddeveloper into installing malware. Their patience in studying the AWS system also indicates their commitment to siphon funds from Bybit.
.
The interconnection between different systems and independent protocols provides a weak point that can be exploited by threat actors to steal funds.