Risk register · entry
Q-F · FraudBybit hack
A wallet-UI supply-chain attack redirected the largest crypto theft ever.
The fifth quadrant, where the thing was never real. The tell is that the story is too clean.
Why this quadrant
The signers saw a normal transaction and approved it. They were looking at a compromised Safe{Wallet} interface, injected two days earlier and armed only for Bybit's address, which switched the operation type so that approving it handed over the wallet's logic rather than moving funds. 401,347 ETH left, about 1.5 billion dollars. The same compromise sat under every other Safe{Wallet} client.
The record
- 401,347 ETH stolen, ~$1.5 billion at time of hack (February 21, 2025)certain
- Attack attributed by FBI to North Korea's Lazarus Group / TraderTraitor / APT38certain
- Malicious JavaScript injected into Safe{Wallet}'s app on February 19, 2025, activated only for Bybit's walletlikely
- Transaction parameter switched from operation 0 (call) to operation 1 (delegatecall) to hijack the proxy's logic addresslikely
- FBI published 51 Ethereum addresses tied to the stolen fundscertain
- Bybit secured bridge-loan/emergency funding covering roughly 80% of stolen ETH within about 72 hourslikely
- At least $500 million withdrawn by customers in the days following the hacklikely
- By March 2025, about 86% of stolen ETH laundered into Bitcoin across 35,000+ wallets, largely via THORChainuncertain
- North Korea-linked actors stole a reported $1.34 billion across 47 incidents in 2024, for comparisonlikely
- Specific bridge-loan lenders (Galaxy Digital, FalconX, Wintermute, Binance) named in some secondary reporting but not confirmed in directly fetched primary sourceuncertain
Sources
The newsletter
One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.
No spam, one email a week.