CryptoReal
CASE FILE — Feb 22, 2025

Lazarus Group's Fake Safe UI Nets $1.43 Billion From Bybit Cold Wallet

A $1.43 billion theft from Bybit has become the largest single loss in the history of the crypto industry, instantly topping the Rekt Leaderboard and pushing every prior exchange breach into second place.

In a matter of minutes, attackers drained 401,346 ETH (worth roughly $1.11 billion), 90,375 stETH (about $250.8 million), 15,000 cmETH (around $44 million), and 8,000 mETH (approximately $23.5 million) from the exchange. Rather than breaking cryptographic keys, the intruders relied on interface deception: multisig signers were shown a legitimate-looking transaction while a different, malicious one was actually being authorized. The stolen assets were immediately fragmented across more than 40 wallet addresses, and the total loss came in at more than double the amount taken in the previous record-setting hack, the Ronin Network breach of $624 million.

Credit for tracking and analysis throughout the incident goes to ZachXBT, SlowMist, Peckshield, Bybit, Ben Zhou, MetaSleuth, BitMEX Research, Nanak Nihal, Derek Silva, Meir Dolev, Adam Cochran, Arkham Intel, Tayvano, SEAL, Abbas Khan, Vladimir S, and Chainflip.

01How the alarm was raised

The first public signal came from ZachXBT on Telegram on a Friday, flagging that he was "currently monitoring suspicious outflows from Bybit." Within minutes, security firms SlowMist and Peckshield had corroborated that Bybit was actively losing funds at an extraordinary pace. By the time the exchange itself confirmed the incident, the assets were already gone. The exchange's Ethereum cold wallet had been emptied while the signers responsible for approving transactions had no idea what they were actually authorizing — every interface they saw appeared entirely routine.

Bybit co-founder and CEO Ben Zhou confirmed that this was not a straightforward key theft: "It appears that this specific transaction was masked, all the signers saw the masked UI which showed the correct address and the URL was from Safe."

02Mechanics of the exploit

Peckshield's XJ described the exact method. Attackers presented signers with what looked like an ordinary cold-to-hot wallet transfer. In reality, the transaction they were approving was a wallet implementation upgrade that installed malicious code, including a concealed function labeled sweepERC20(). Once that unverified implementation was live, the attackers had unrestricted ability to empty the wallet whenever they chose.

The address that became the operational hub for the theft was 0x47666Fab8bd0Ac7003bce3f5C3585383F09486E2. The compromised Bybit cold wallet was 0x1Db92e2EeBC8E0c075a02BeA49a2935BcD2dFCF4. The decisive moment arrived when the attacker invoked the sweep function against Bybit's hot wallet, executing a transaction that moved 401,346.76 ETH in one action: 0xb61413c495fdad6114a7aa863a00b2e3c28945979a10885b12b30316ea9f072c.

Immediately afterward, the funds were dispersed. ZachXBT tracked 10,000 ETH being split across 39 separate addresses, followed by another 10,000 ETH sent to 9 more addresses — a rapid fragmentation effort meant to complicate tracing.

Fund-tracking resources: MetaSleuth's tracker and the attacker profile on Arkham.

03The response

Bybit moved fast to reassure users. Ben Zhou announced on Twitter shortly after the breach that "Bybit is Solvent even if this hack loss is not recovered, all of clients assets are 1 to 1 backed, we can cover the loss." He followed with a livestream reiterating several points: only the Ethereum cold wallet was impacted; all user funds remained safe; Bybit's treasury could absorb the entire loss; a bridge loan was being arranged with partners (80% committed at the time); and withdrawals, though slower, continued to function. Communication of this speed and clarity is unusual for a crisis of this size, particularly given it broke on a Friday evening.

BitMEX Research estimated that approximately 75% of Bybit's ETH user deposits had been stolen, and its rough solvency calculation, based on Bybit's published reserve ratios, indicated the exchange could still remain solvent despite the massive loss.

Sums referenced in this case file

04The blind-signing problem

The incident underscores a structural weakness that persists even in well-resourced crypto operations: blind signing. As Nanak Nihal put it, "There is a name for this and it's BLIND SIGNING. Please please please stop using hardware wallets and multisigs and thinking you are safe." The core issue is that hardware wallets and multisig setups still depend on signers trusting that their device's display accurately reflects the transaction being approved — and once that display can be manipulated, every other safeguard becomes irrelevant.

Derek Silva noted that "a group of Bybit executives, who should have significant OpSec training, blindly signed a transaction without asking any of the other multi-sig owners to confirm what it was for."

05Not the first time — or the fifth

Cyvers founder and CTO Meir Dolev identified that the attackers had run several rehearsal transactions two days before the actual attack, testing their approach with the thoroughness of a planned operation. Security researcher Tayvano pointed to a broader pattern: "They've done this 5 times now. Please start taking it seriously." The same attack methodology has appeared in previous incidents at WazirX, Radiant Capital, and DMM Bitcoin — cases where funds were pulled straight from multisig wallets without the underlying private keys, which were held on separate hardware devices controlled by different individuals, ever being compromised.

Adam Cochran suggested there were only two realistic ways to pull this off: "a shotgun approach of targeting every senior person who works at ByBit until you get the signers, or a malware in network that attaches to internal docs until normal operations have spread to everyone needed." That implies a compromise going well beyond a spoofed interface — potentially sustained access to Bybit's internal systems that let the attackers watch and wait for the ideal moment. Notably, the attackers executed the transaction themselves the instant Ben Zhou signed, rather than letting it go through Bybit's normal processing.

Hours later, ZachXBT solved Arkham Intel's bounty by tying the attack to the Lazarus Group, North Korea's state-backed hacking unit — a conclusion reached in about four hours through analysis of test transactions, linked wallets, and timing patterns.

06Warnings that went unheeded

Security researchers had already been raising alarms about this attack pattern for months. Tayvano's earlier thread laid out the fix plainly: "Your best bet is to not allow them to get your device. That means hardware wallets. But it also means not using your daily computer when signing txns with that hardware wallet. Get an alt device for signing... It's dead simple."

Nanak Nihal's recommendations included using dedicated, transaction-signing-only devices; keeping them offline except when actively needed; considering hardened operating systems such as Qubes; using sandboxed signing environments; and implementing cross-verification procedures among signers.

Vladimir S. outlined additional measures exchanges should adopt: end-to-end encrypted communications, hardware security modules for key storage, independent verification apps to confirm transaction details, biometric physical security keys, and network segregation for signing operations. One commenter summed it up: "Having a separate laptop will get you 99.99% of the way there. Refurbished MacBook Pro, costs $900/pop" — a negligible cost set against a $1.43 billion loss.

07The North Korean playbook

SEAL's advisory on the DPRK threat describes how TraderTraitor — an alias for the Lazarus Group — typically opens with social engineering: fabricated recruiter identities reaching targets through LinkedIn, Telegram, or Twitter. Months of reconnaissance follow, along with malware such as malicious Chrome extensions used to tamper with trusted websites. Targeted employees are identified, given access to private GitHub repositories through live chat channels, and manipulated into running code that contains backdoors.

08Aftermath and recovery efforts

Bybit launched a $140 million recovery bounty program — around 10% of the stolen total — aimed at identifying the perpetrators. The Lazarus Group, meanwhile, had already begun moving funds: the day after the attack, 5,000 ETH was transferred to a new address and laundered through the centralized mixer eXch, with additional funds bridged to Bitcoin via Chainflip. Tether managed to freeze 181,000 USDT tied to the theft, though that represents only a small fraction of the total stolen.

A survey of bug bounty programs across major exchanges found wide disparities: Kraken and Coinbase offer rewards up to $1 million, while Bitget caps its payouts at $3,000. The presence of a dedicated Chief Security Officer is similarly uneven across the industry — Kraken, Binance, and Coinbase have named security leaders, while Bybit has instead relied on third-party security services.

09Closing thoughts

This is now the fifth exchange to fall to essentially the same attack vector, each one believing hardware wallets and multisig arrangements made them secure. As Tayvano summarized: "The pixels that you see on your screen always come from somewhere else. If a threat actor compromises your computer, they can make the pixels display whatever they want. What you see will NOT be an accurate representation of what's actually happening behind the scenes. And you will not know until it's too late." The North Korean approach is now well understood — compromise the device, mask the interface, and wait for the right moment to strike — and there is little reason to think the next billion-dollar target has not already been chosen.

ByBitLazarus
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.