What the attack actually defeated
It is worth being precise about this one, because the headline figure has obscured the mechanism. The Bybit cold wallet was not broken into in the sense people usually imagine — nobody guessed a key or extracted one from hardware. The signers were shown one thing and approved another.
That distinction matters for anyone running a treasury. Multi-signature schemes and hardware wallets both rest on an assumption that is rarely tested: that the transaction displayed for approval is the transaction that will execute. Where the interface producing that display can be influenced, the number of signers is irrelevant. Each one approves the same misrepresentation.
Why the class of failure recurs
Signing-interface compromise has appeared repeatedly in large custody incidents, and it defeats controls that look strong on paper. Key material stored offline is only as trustworthy as the pipeline that constructs and displays what is being signed. Independent verification — decoding the raw payload on a separate device, simulating the call, and confirming the destination out of band — is the control that addresses it, and it is operationally expensive enough that it is often skipped.
Attribution
Conisec does not attribute attacks on its own analysis. The attribution here is the FBI’s, published on 26 February 2025 in an IC3 public service announcement naming North Korea and the activity cluster the Bureau calls TraderTraitor. That announcement also published addresses holding the assets. Where you see an attribution on Conisec, it is because an official body made it, and we say which one.
Customer impact
Bybit stated that it remained solvent, that it covered the shortfall through its own reserves and a bridge loan, and that withdrawals continued through the incident. Conisec reports that as the company’s own statement, because that is what it is; the authoritative record of what any individual account experienced is Bybit’s own communication.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
What to check
Read the FBI IC3 public service announcement for the official attribution and the published list of addresses. Bybit's own incident timeline and status updates are the authoritative record of customer impact.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- FBI Internet Crime Complaint Center, North Korea Responsible for $1.5 Billion Bybit Hack (PSA 250226) (26 Feb 2025)
- Bybit, Bybit Security Incident: Timeline of Events and FAQs (21 Feb 2025)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.