Bybit $1.4 Billion Hack: Impact on the Market

June 10, 2026 6 min
Daniel Bennett Twitter
Daniel Bennett
0Shares
1KReads
Bybit $1.4 Billion Hack: Impact on the Market
Table of contents
  • Bybit Hack: How it Happened. Timeline.
    • Timeline of Events
  • Lazarus Group: How They Stole $1.5B from Bybit
    • How The Bybit Hack Unfolded
    • Lazarus Group Moves $140M in Stolen Bybit Funds
  • How Bybit Has Responded to the Hack
  • Immediate Aftermath: How the Market Reacted to the Hack
    • Support from Industry and Enhanced Security Measures
    • What’s Next for Bybit? Recovery and Legal Action
    • Could the Buyback Plan Fuel a Bullish Momentum for Ethereum?
Table of contents
  • Bybit Hack: How it Happened. Timeline.
    • Timeline of Events
  • Lazarus Group: How They Stole $1.5B from Bybit
    • How The Bybit Hack Unfolded
    • Lazarus Group Moves $140M in Stolen Bybit Funds
  • How Bybit Has Responded to the Hack
  • Immediate Aftermath: How the Market Reacted to the Hack
    • Support from Industry and Enhanced Security Measures
    • What’s Next for Bybit? Recovery and Legal Action
    • Could the Buyback Plan Fuel a Bullish Momentum for Ethereum?
Share this blog post

Bybit Hack: How it Happened. Timeline.

On February 21, 2025, Bybit, one of the world's leading cryptocurrency exchanges, suffered an unprecedented security breach. Hackers stole approximately $1.4 billion worth of digital assets, marking it as the largest cryptocurrency heist in history. The holdings of the Bybit hacker entity can be tracked using the Arkham Intelligence platform. The attack primarily affected Ethereum (ETH), causing its price to drop as low as $2,619 in the past week. However, Bybit’s response, including a massive ETH buyback, has started to restore market confidence.

Timeline of Events

  • February 19, 07 AM: The attacker deploys a malicious smart contract (address: 0xbDd077f651EBe7f7b3cE16fe5F2b025BE2969516) in preparation for the attack.
  • February 21, 2 PM: The attacker uses a fake Safe multi-signature wallet UI to deceive signers into signing malicious transactions.
  • February 21, 9 PM: The attacker exploits the malicious contract to transfer 401,347 ETH and equivalent stETH, cmETH, and mETH, valued at approximately $1.5 billion.
  • February 21, 11 PM: Bybit CEO Ben Zhou confirms the incident, stating that only one ETH cold wallet was affected.
  • February 21, 7 PM: @zachxbt, an anonymous blockchain investigator, submitted definitive proof that this attack on Bybit was performed by the LAZARUS GROUP. Here’s the full thread
  • February 22, 09 AM: Bybit CEO announces that 99.994% of withdrawals have been completed and platform services are back to normal.
  • February 23: Security experts urge the industry to improve security measures to prevent similar breaches.

Lazarus Group: How They Stole $1.5B from Bybit

Lazarus Group, a North Korean state-backed hacking syndicate, executed the Bybit hack using advanced deception and fund-laundering techniques. The attack specifically targeted Bybit’s multi-signature ETH cold wallet, tricking signers through a fake interface that secretly altered transaction details. This allowed hackers to siphon off approximately 400,000 ETH, worth $1.5 billion, before dispersing the assets across multiple wallets.

Lazarus Group: A Decade of Cyber Heists

Lazarus Group has been one of the most prolific hacking collectives since 2010, responsible for some of the largest crypto heists in history. Their past attacks include:

  • Axie Infinity’s Ronin Bridge ($625M, 2022) – The largest crypto hack to date, involving sophisticated social engineering and private key theft.
  • Atomic Wallet ($100M, 2023) – A targeted attack on crypto wallets that resulted in massive losses for users.
  • Harmony Bridge ($100M, 2022) – An exploit on the cross-chain protocol that enabled Lazarus to siphon funds undetected.

The group employs a strategic approach to laundering stolen funds, often waiting years before attempting to cash out. Chainalysis reported that as of 2022, Lazarus still held at least $55 million from previous hacks.

How The Bybit Hack Unfolded

Lazarus used a combination of deception and rapid fund movement to execute the attack:

  • Blind Signing Attacks: By tricking Bybit signers into approving fraudulent transactions, hackers gained full control over the multi-signature wallet.
  • Fake UI Exploit: A deceptive interface manipulated transaction details, making it appear as though legitimate transfers were occurring.
  • Mass Fund Dispersal: The stolen ETH was rapidly distributed across 53 different wallets, complicating tracking efforts.

After the attack, Bybit borrowed ETH and increased liquidity for USDT and USDC to ensure that withdrawals would be processed. The company has since worked to buy back the missing reserves. However, security experts caution that these large-scale breaches highlight the need for stronger multi-signature protections and improved verification protocols.

Lazarus Group Moves $140M in Stolen Bybit Funds

Lazarus Group has continued laundering the stolen assets. On February 22, 2025, blockchain @zachXBT in a Telegram post reported that the hacker had converted 37,900 ETH (worth approximately $106 million) into other assets. The group utilized multiple cross-chain platforms, including Chainflip, THORChain, LiFi, and OKX DEX, to move funds and convert them into non-freezable assets like DAI. Moreover, blockchain security firm Elliptic recently provided insights into the laundering methods used by the Lazarus group. Elliptic observed that this North Korea-backed group frequently employed several tactics to launder its stolen funds.

Countermeasures Taken by Exchanges:

Bybit responded to a $1.4 billion Ethereum hack on February 22, 2025, where the exchange froze $42.89 million in stolen funds within 24 hours through collaboration with multiple crypto platforms like Tether and THORChain. According to the post on X:

  • ChangeNow froze 34 ETH.
  • Avalanche restricted access to 0.38755 BTC.
  • FixedFloat froze $120,000 in stablecoins.
  • THORChain blacklisted Lazarus-linked addresses.
  • Tether froze 181,000 USDT.

@zachXBT revealed in a post on Telegram that the hacker has now shifted assets to Solana, further complicating tracking efforts. In response, Bybit collaborated with pump.fun and Solana Foundation President, Lily Liu, to remove a Solana-based token linked to the hacker.  

How Bybit Has Responded to the Hack

Bybit has taken several measures in response to the recent hack to enhance security and reassure its users:

  • Borrowing ETH from competitors like Binance, HTX, and Bitget to process withdrawals smoothly.
  • Enhancing liquidity for USDT and USDC through strategic partnerships.
  • Securing a bridge loan to cover potential losses.
  • Launching an ETH buyback program and purchasing around $400 million worth of ETH from OTC desks like FalconX and Wintermute.

Bybit confirmed that the team is close to 100% on ETH reserves and that deposits and withdrawals have returned to normal. CEO Ben Zhou announced that a new audited proof-of-reserves report would be released soon, ensuring that client assets remain 1:1 backed through the Merkle tree system. Bybit’s rapid restoration efforts, including loans, whale deposits, and ETH purchases totaling $1.23 billion, reflect a coordinated response involving the crypto community and security experts to rebuild trust and comply with regulatory expectations.

Immediate Aftermath: How the Market Reacted to the Hack

The attack caused ETH’s price to drop over 7% in just seven hours, falling from $2,831 to $2,629. The scale of the hack led to panic withdrawals from Bybit, with over 350,000 users rushing to secure their assets. Bybit’s quick response and proof-of-reserves audit helped stabilize market sentiment, allowing ETH prices to recover above $2,700.

Support from Industry and Enhanced Security Measures

Multiple crypto exchanges and institutions stepped up to support Bybit:

  • Bitget transferred 40,000 ETH to Bybit’s cold wallet.
  • MEXC transferred 12,600 stETH.
  • ABCDE co-founder Du Jun personally transferred 10,000 ETH.

To prevent future attacks, Bybit is now implementing advanced security measures, including:

  • Secondary semantic validation for transactions.
  • Mandatory hardware wallet confirmations.
  • Exchange-wide insurance services.

What’s Next for Bybit? Recovery and Legal Action

Bybit’s recovery efforts are now focused on legal action against the attackers and implementing stricter security protocols. The platform’s ETH buyback plan has already influenced the market by demonstrating resilience and a commitment to user trust. However, concerns remain over whether such buybacks set a precedent that could reduce the urgency of security improvements.

The success of Bybit’s strategy will depend on:

  • Market perception of its long-term security enhancements.
  • Legal actions taken against the Lazarus Group.
  • The effectiveness of its new security measures.

Could the Buyback Plan Fuel a Bullish Momentum for Ethereum?

Bybit’s buyback of 266,694 ETH (worth approximately $742 million) is one of the largest single purchases in recent times. Large-scale acquisitions like this can influence market sentiment, driving up demand and price. If Bybit continues on its recovery path and investor trust remains strong, Ethereum could see further bullish momentum in the coming weeks.

No Comments
No comments yet