Skip to content
← Back to newsBybit Hacked: $1.46 Billion Lost Due to Vulnerability in Safe Infrastructure
Security

Bybit Hacked: $1.46 Billion Lost Due to Vulnerability in Safe Infrastructure

By ToTo BugelmanNewcomer0 rep· 2/27/2025

In a shocking turn of events, the cryptocurrency exchange Bybit has suffered a massive breach, resulting in the loss of approximately $1.46 billion. The attack was traced back to a vulnerability in the Safe wallet infrastructure, rather than the exchange's own systems. This incident has raised significant concerns about the security measures in place within the cryptocurrency industry.

 

Ben Zhou

 

Key Takeaways

  • Bybit lost $1.46 billion due to a hack linked to the Safe wallet infrastructure.

  • Hackers laundered $113 million in just 24 hours after the breach.

  • The attack involved sophisticated manipulation of transaction signing processes.

  • Bybit's CEO has initiated a bounty program to track the stolen funds.

 

Overview of the Attack

On February 21, 2025, Bybit confirmed unauthorized activity involving one of its Ethereum cold wallets. The breach was executed through a sophisticated attack that masked the transaction signing process, allowing hackers to redirect funds to an unidentified wallet.

The attackers exploited a vulnerability in the Safe wallet infrastructure, injecting malicious JavaScript code into resources stored on AWS S3. This code was activated during transactions involving Bybit's contract addresses, indicating a targeted approach.

 

Malicious code fragment. Data: Sygnia report.

 

Malicious code fragment found in the February 19 WaybackMachine snapshot. Data: Sygnia report.

 

Malicious files in the signatories' Chrome browser cache. Data: Sygnia report.

 

The Aftermath

Following the breach, hackers managed to launder a staggering 135,000 ETH (approximately $335 million) through various decentralized exchanges. Reports indicate that they utilized the Maya Protocol to facilitate the transfer of stolen assets.

Bybit's CEO, Ben Zhou, has taken proactive measures by launching a bounty program aimed at tracking the activities of the North Korean hacking group Lazarus, which has been linked to the attack. Users can connect their wallets to assist in tracing the stolen funds, with rewards for successful recoveries.

 

Security Concerns in the Crypto Industry

This incident has sparked a broader discussion about security vulnerabilities within the cryptocurrency ecosystem. Experts have pointed out that the design flaws in Ethereum's Virtual Machine (EVM) may have contributed to the ease with which the hackers executed their plan.

The attack on Bybit is not an isolated incident; it reflects a growing trend of cybercriminals targeting cryptocurrency exchanges and wallets. In 2024 alone, losses from crypto-related fraud reached nearly $10 billion, highlighting the urgent need for enhanced security protocols.

 

Conclusion

The Bybit hack serves as a stark reminder of the vulnerabilities that exist within the cryptocurrency space. As exchanges and wallet providers continue to innovate, they must prioritize security to protect users' assets. The ongoing investigation into the breach will likely lead to significant changes in how cryptocurrency platforms approach security moving forward.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Bybit Hacked: $1.46 Billion Lost Due to Vulnerability in Safe Infrastructure | BlockzHub