5Q Quadrants·of·Risk

Risk register · entry

Q-F · Fraud

Bybit hack

A wallet-UI supply-chain attack redirected the largest crypto theft ever.

The fifth quadrant, where the thing was never real. The tell is that the story is too clean.

Quadrant
Q-F Fraud
Year
2025
Impact
$1.5B
Sector
Crypto exchange
Region
Global
Category
Technological

Why this quadrant

The signers saw a normal transaction and approved it. They were looking at a compromised Safe{Wallet} interface, injected two days earlier and armed only for Bybit's address, which switched the operation type so that approving it handed over the wallet's logic rather than moving funds. 401,347 ETH left, about 1.5 billion dollars. The same compromise sat under every other Safe{Wallet} client.

The record

  • 401,347 ETH stolen, ~$1.5 billion at time of hack (February 21, 2025)certain
  • Attack attributed by FBI to North Korea's Lazarus Group / TraderTraitor / APT38certain
  • Malicious JavaScript injected into Safe{Wallet}'s app on February 19, 2025, activated only for Bybit's walletlikely
  • Transaction parameter switched from operation 0 (call) to operation 1 (delegatecall) to hijack the proxy's logic addresslikely
  • FBI published 51 Ethereum addresses tied to the stolen fundscertain
  • Bybit secured bridge-loan/emergency funding covering roughly 80% of stolen ETH within about 72 hourslikely
  • At least $500 million withdrawn by customers in the days following the hacklikely
  • By March 2025, about 86% of stolen ETH laundered into Bitcoin across 35,000+ wallets, largely via THORChainuncertain
  • North Korea-linked actors stole a reported $1.34 billion across 47 incidents in 2024, for comparisonlikely
  • Specific bridge-loan lenders (Galaxy Digital, FalconX, Wintermute, Binance) named in some secondary reporting but not confirmed in directly fetched primary sourceuncertain

Sources

  1. BleepingComputer
  2. Dfns
  3. DL News
  4. CSIS
  5. Ben Zhou (Bybit CEO), X/Twitter

The newsletter

One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.

No spam, one email a week.