Skip to content
Incident record

Bybit Cold Wallet Compromise, February 2025: What Happened & What to Check

Around $1.5 billion in ETH was moved out of a Bybit cold wallet on 21 February 2025 during a routine transfer. The FBI attributed the theft to North Korea.

Resolved Discovered Disclosed
Share X in @
Schematic of the Bybit incident showing the signing interface compromise stage as the failure point.
Schematic of the Bybit incident showing the signing interface compromise stage as the failure point.

At a glance

AFFECTED ENTITY
Bybit
CHAIN(S)
Ethereum
REPORTED LOSS
approx. US$1.5 billion(FBI (IC3 Public Service Announcement), 26 Feb 2025)
OFFICIAL RESPONSE
learn.bybit.com

What the attack actually defeated

It is worth being precise about this one, because the headline figure has obscured the mechanism. The Bybit cold wallet was not broken into in the sense people usually imagine — nobody guessed a key or extracted one from hardware. The signers were shown one thing and approved another.

That distinction matters for anyone running a treasury. Multi-signature schemes and hardware wallets both rest on an assumption that is rarely tested: that the transaction displayed for approval is the transaction that will execute. Where the interface producing that display can be influenced, the number of signers is irrelevant. Each one approves the same misrepresentation.

Why the class of failure recurs

Signing-interface compromise has appeared repeatedly in large custody incidents, and it defeats controls that look strong on paper. Key material stored offline is only as trustworthy as the pipeline that constructs and displays what is being signed. Independent verification — decoding the raw payload on a separate device, simulating the call, and confirming the destination out of band — is the control that addresses it, and it is operationally expensive enough that it is often skipped.

Attribution

Conisec does not attribute attacks on its own analysis. The attribution here is the FBI’s, published on 26 February 2025 in an IC3 public service announcement naming North Korea and the activity cluster the Bureau calls TraderTraitor. That announcement also published addresses holding the assets. Where you see an attribution on Conisec, it is because an official body made it, and we say which one.

Customer impact

Bybit stated that it remained solvent, that it covered the shortfall through its own reserves and a bridge loan, and that withdrawals continued through the incident. Conisec reports that as the company’s own statement, because that is what it is; the authoritative record of what any individual account experienced is Bybit’s own communication.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Bybit detects unauthorised movement of ETH from a cold wallet during a routine transfer and publicly confirms the incident. Bybit
  2. The FBI publicly attributes the theft to North Korean actors, referring to the activity as "TraderTraitor", and publishes addresses holding the stolen assets. FBI IC3

What to check

Read the FBI IC3 public service announcement for the official attribution and the published list of addresses. Bybit's own incident timeline and status updates are the authoritative record of customer impact.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. FBI Internet Crime Complaint Center, North Korea Responsible for $1.5 Billion Bybit Hack (PSA 250226) (26 Feb 2025)
  2. Bybit, Bybit Security Incident: Timeline of Events and FAQs (21 Feb 2025)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.