Article Details

Scrape Timestamp (UTC): 2025-02-22 07:07:52.906

Source: https://thehackernews.com/2025/02/bybit-confirms-record-breaking-146.html

Original Article Text

Click to Toggle View

Bybit Confirms Record-Breaking $1.46 Billion Crypto Heist in Sophisticated Cold Wallet Attack. Cryptocurrency exchange Bybit on Friday revealed that a "sophisticated" attack led to the theft of over $1.46 billion worth of cryptocurrency from one of its Ethereum cold (offline) wallets, making it the largest ever single crypto heist in history. "The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing interface, displaying the correct address while altering the underlying smart contract logic," Bybit said in a post on X. "As a result, the attacker was able to gain control of the affected ETH cold wallet and transfer its holdings to an unidentified address." In a separate statement posted on the social media platform, Bybit's CEO Ben Zhou emphasized that all other cold wallets are secure. The company further said it has reported the case to the appropriate authorities. While there is no official confirmation from Bybit yet, Elliptic and Arkham Intelligence confirmed that the digital theft is the work of the infamous Lazarus Group. The incident makes it the biggest-ever cryptocurrency heist reported to date, dwarfing that of Ronin Network ($624 million), Poly Network ($611 million), and BNB Bridge ($586 million). Independent researcher ZachXBT said they "connected the Bybit hack on-chain to the Phemex hack," the latter of which took place late last month. The North Korea-based threat actor is one of the most prolific hacking groups, orchestrating dozens of cryptocurrency heists to generate illicit revenue for the sanctions-hit nation. Last year, Google described North Korea as "arguably the world's leading cyber criminal enterprise." In 2024, it's estimated to have stolen $1.34 billion across 47 cryptocurrency hacks, accounting for 61% of all ill-gotten crypto during the time period, according to blockchain intelligence firm Chainalysis. "Cryptocurrency heists are on the rise due to the lucrative nature of their rewards, the challenges associated with attribution to malicious actors, and the opportunities presented by nascent familiarity with cryptocurrency and Web3 technologies among many organizations," Google-owned Mandiant said last month.

Daily Brief Summary

CYBERCRIME // Bybit Suffers Historic $1.46 Billion Crypto Theft by Lazarus Group

Cryptocurrency exchange Bybit was the victim of a record $1.46 billion heist, targeting an Ethereum cold wallet.

The theft was executed via a sophisticated attack during a transfer from a cold wallet to a warm wallet, involving manipulation of the signing interface’s smart contract logic.

Bybit's CEO confirmed that the rest of their cold wallets remain secure, and the incident has been reported to authorities.

Security firms Elliptic and Arkham Intelligence attribute the theft to North Korea's Lazarus Group, making it the largest crypto heist in history.

Independent researcher ZachXBT linked the Bybit attack to a recent hack at Phemex, suggesting a pattern or connection in the incidents.

The Lazarus Group has become a dominant force in crypto heists, stealing an estimated $1.34 billion in 2024 from various sources.

Google and Mandiant emphasize the increasing threat of cryptocurrency heists, highlighting challenges in preventing and tracing such attacks.