What happened
The signers checked the transaction on screen, saw a routine transfer, approved it, and signed something else entirely.
| When | February 2025 |
| What kind of failure | Cold wallet compromise |
| What it cost | About $1.46 billion, the largest crypto theft on record |
The version the public saw
Bybit is one of the largest exchanges in the world and held the affected ether in a multisig cold wallet, which is close to industry best practice. Several people had to approve each movement, and each of them reviewed the transaction before signing.
Underneath the same period
The interface they reviewed it in had been compromised. Malicious code served through the Safe wallet front end displayed a normal transfer while the data actually being signed changed the logic of the wallet contract itself. Every signature was genuine. Every signer was looking at a lie.
The sequence
The front end is compromised
Attackers placed malicious JavaScript in the path that served the Safe wallet interface, targeted specifically at Bybit.
Signers approve a routine transfer
On 21 February 2025 the signers reviewed what appeared to be an ordinary movement between wallets and approved it.
The contract is replaced instead
The signed transaction upgraded the wallet's implementation to one the attacker controlled, giving them the ability to move everything.
The wallet empties
Around 401,000 ETH plus staked ether derivatives left in minutes. The FBI attributed the theft to North Korea.
The signals, before anybody knew the ending
None of these needed hindsight. Each one was public, or checkable, while the money was still there.
- Signing a transaction whose contents you can only verify on the same screen that produced it
- A cold wallet whose approvals still depend on a web interface
- No independent decoding of the calldata before approval
- A single interface as the common dependency of every signer
The aftermath
Bybit covered the loss within seventy two hours through bridge loans, large deposits and purchases from partners, restoring customer backing above one hundred percent. Customer withdrawals continued throughout. It is the largest theft in the history of crypto and the exchange survived it.
The part that changes what you do
This is the strongest possible argument for the advice on every hardware wallet page here: verify on the device, not on the screen. The whole point of a hardware wallet is that it shows you what you are actually signing, from a machine the website cannot reach. If you approve based on what the website says, you are trusting the website, and the website is exactly what gets compromised.
Common questions
Did Bybit customers lose money?
What is blind signing?
Does multisig still help?
Where to go next
Other cases like this one
Would your setup have survived this?
We go through where your coins actually sit and who is holding them, and what happens to each of those if the company behind it fails. No sales pitch, and usually about an hour.