Bybit hack: details of the largest attack in cryptocurrency history
On 21 February 2025, cryptocurrency exchange Bybit suffered a massive hacking attack in which attackers stole $1, 46 billion in Ethereum (ETH) from one of the platform’s cold wallets.
The attack occurred during a routine transaction to transfer funds from a cold wallet (offline storage) to a warm wallet (used for daily transactions). Hackers were able to interfere with this process by gaining control of the cold wallet and transferring 401,000 ETH to an unknown address.
Bybit’s response and restoration of reserves
Bybit CEO Ben Zhou confirmed the incident and assured customers that the exchange remains solvent and users’ assets are fully secured at a 1:1 ratio. Even if the stolen funds are not recovered, Bybit is ready to cover the losses with its own reserves of $20 billion.
The exchange has also asked cybersecurity experts to assist in the investigation and announced a reward of 10 per cent of the recovered funds for those who help recover them.
Investigation and charges
The FBI has accused North Korean hacking group Lazarus of orchestrating the attack. The group is known for its cybercrimes aimed at funding North Korea’s nuclear programme. According to the FBI, the stolen assets were partially converted into bitcoins and distributed to various blockchain addresses for later legalisation and exchange into fiat currency.
Impact on the cryptocurrency market
The hack of cryptocurrency exchange Bybit had a notable impact on the cryptocurrency market.
The market reaction in the first two days after the hack:
Bitcoin (BTC): The bitcoin price reached $99.475 on the day of the incident, but pulled back after the news of the Bybit hack, remaining in a consolidation phase.
Etherium (ETH): The etherium exchange rate fell nearly 4%, dropping below $2,700.
Despite the initial price decline, Bybit’s swift action to replenish lost funds and partner support helped stabilise the market, preventing more serious consequences.
Forecast and implications
Experts predict that the cryptocurrency market will be able to recover within a few weeks as investor confidence in Bybit remains high. The exchange successfully passed an audit and received regulatory approval, confirming that its reserves have been fully restored.
The incident has emphasised the need for increased security in the cryptocurrency industry. In the wake of the attack, exchanges are expected to revise their asset storage strategies with a greater focus on protecting cold wallets.
The Bybit hack was one of the largest attacks on cryptocurrency exchanges, leaving a significant mark on the industry. This case not only exposed vulnerabilities in the asset storage system, but also demonstrated how sound crisis management can minimise the impact. Several key conclusions can be drawn from this incident:
Cyber threats to cryptocurrency exchanges remain relevant
The Bybit cold wallet hack showed that even the largest exchanges with high security standards can fall victim to hackers. This emphasises the need to continuously improve protection measures.
2. Bybit’s swift action saved the situation
The exchange was able to quickly restore reserves and prove its financial strength, which helped minimise panic selling and stabilise the market.
3. The market adapted quickly
Despite a significant drop in cryptocurrency prices after the attack, the recovery started within a few days. This shows that investors retain confidence in the major players in the industry.
4. Increased focus on cold wallet security
Exchanges will be forced to rethink their approach to protecting cold wallets, implementing additional layers of security and multi-level transaction authorisation.
5. Bybit has strengthened its reputation
Although the attack was one of the largest in the history of cryptocurrencies, the successful recovery of losses and transparent investigation increased trust in the platform, and set a new standard of response to cyberattacks in the Hindu industry.