Tools Crypto Exploit Tracker exploit-0127
Exploit record
Bybit Multisig Cold-Wallet Hack
- Loss
- $1.40bn
- Attack vector
- Access Control
- Chain
- Ethereum
- Sector
- Exchange
What happened
On February 21, 2025, Bybit suffered the largest single crypto theft on record after a phished multisig flow led to $1.4B in ETH being drained. The FBI attributed the attack to North Korea's Lazarus Group (TraderTraitor).
The key lesson was brutal and simple: a multisig is only as safe as the signing environment and the humans using it. The interface showed one thing, the underlying permission change did another, and the largest single crypto theft on record followed. The FBI publicly attributed the hack to the DPRK-linked threat actor known as TraderTraitor (Lazarus Group / APT38) and issued a formal PSA. Bybit published a detailed incident timeline and committed to full transparency throughout the recovery process.
On-chain references
Sources
- FBI PSA - Lazarus attributionwww.fbi.gov/investigate/cyber/alerts/2025/north-korea-respon…
- Bybit incident timelinelearn.bybit.com/en/this-week-in-bybit/bybit-security-inciden…
- Rekt Newsrekt.news/bybit-rekt
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
