On 21 February 2025, one signature made $1.5 billion vanish from the world's second-largest crypto exchange — the biggest theft in the history of money. This is how North Korea pulled it off, and why not a single customer ended up losing a cent.
The routine transfer
It is an ordinary Thursday afternoon. At Bybit, a routine job is on the schedule: move ether from a cold wallet — offline, the vault — to a hot wallet. Several executives have to sign off; it is a multisig, exactly the setup everyone calls safe.
The signers look at their screens. They see the right address, the right amount. They sign. And while they believe they are approving an ordinary transfer, what they are really signing is something else entirely: a change to the logic of the smart contract that controls the vault.
All the signers saw the “musked” UI which showed the correct address.Ben Zhou, CEO of Bybit
Within minutes, the vault drains into 39 unknown addresses.
What disappeared
The haul is staggering: 401,347 ETH, plus stETH, cmETH and mETH — roughly 499,000 ether in total, worth about $1.46 billion. Not a bug in some obscure DeFi protocol. The largest, best-defended vault of a top exchange, emptied in one transaction. The dogma that “cold storage = safe” died in a single afternoon.
The false signature
How? The attackers had not hacked Bybit — they had hacked the supply chain. Weeks earlier, around 4 February, they compromised the laptop of a developer at Safe{Wallet}, the multisig software Bybit used. On 19 February they injected malicious JavaScript into Safe's infrastructure — code that only woke up for Bybit's own contract address, faking the interface so the signers saw the right thing and signed the wrong one. Two minutes after the strike, the code was gone again.
It is the most treacherous form of “blind signing”: your hardware says yes, your eyes say yes, and still you sign your own vault away.
The first twelve hours
And then something happens that sets this story apart from FTX and Mt. Gox. Bybit CEO Ben Zhou does not go underground. Within ninety minutes he tweets that the vault has been cracked. Within hours he goes live on stream to explain it.
Bybit is solvent even if this hack loss is not recovered.Ben Zhou, 21 February 2025 proven
What follows is a bank run and its counter-movement at the same time. More than 350,000 withdrawal requests pour in; Bybit processes 99.994% of them within ten hours. Competitors come running: Bitget sends over 40,000 ether — interest-free, no collateral. Galaxy Digital, FalconX and Wintermute supply the rest. Within roughly 72 hours the $1.23 billion hole is plugged, and an audit confirms that every customer is once again backed 100%. The loan to Bitget is repaid three days later.

The trail to North Korea
While Bybit puts out the fire, the hunt begins. On-chain investigator ZachXBT makes the connection in about five hours: the addresses overlap with earlier hacks of Phemex and BingX — the fingerprint of Lazarus, North Korea's hacking group. Five days later the FBI makes it official.
North Korea was responsible for the theft of approximately $1.5 billion.FBI, public warning, 26 February 2025 proven
Where the money went
Here the success story ends. The hackers laundered the entire haul in roughly ten days, converting most of it to bitcoin through the THORChain protocol and scattering it across nearly 7,000 wallets. By mid-2025 some 62% — $868 million — had gone “dark”: untraceable. Only a fraction was frozen. Germany took the mixer eXch offline and seized 34 million euro; America's FinCEN cut off a laundering network. But the bulk of it is gone — on its way to the regime in Pyongyang.
What it means
The Bybit hack is two stories in one. It is a warning that a “cold wallet” is not enough when the humans and the software around it can be cracked — the front line moved from the vault to the signature. And it is a rare example of crisis management done right: through transparency, solvency and help from the industry, not a single customer ended up losing anything, despite the biggest heist ever.
That last part is exactly the point for anyone choosing where to park their crypto. A hack is not a question of if, but when. The real question is: does the exchange have the reserves, the transparency and the will to keep you whole when it goes wrong? Bybit did. Not every exchange has proved that.
Sources
FBI attribution (IC3 PSA); Bybit incident timeline with all X posts (Bybit Learn); forensic root cause at Safe{Wallet} (Bleeping Computer); reserves restored within 72h (CNBC); Bitget loan repaid (Cointelegraph); 62% dark (The Defiant).