YFarmX

Tools Crypto Exploit Tracker exploit-0127

Exploit record

Bybit Multisig Cold-Wallet Hack

Loss
$1.40bn
Attack vector
Access Control
Chain
Ethereum
Sector
Exchange

What happened

On February 21, 2025, Bybit suffered the largest single crypto theft on record after a phished multisig flow led to $1.4B in ETH being drained. The FBI attributed the attack to North Korea's Lazarus Group (TraderTraitor).

The key lesson was brutal and simple: a multisig is only as safe as the signing environment and the humans using it. The interface showed one thing, the underlying permission change did another, and the largest single crypto theft on record followed. The FBI publicly attributed the hack to the DPRK-linked threat actor known as TraderTraitor (Lazarus Group / APT38) and issued a formal PSA. Bybit published a detailed incident timeline and committed to full transparency throughout the recovery process.

On-chain references

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026