Skip to main content

Crypto Like This

Bitcoin Bitcoin (BTC) $79,770.00 ▲ 0.26%
Ethereum Ethereum (ETH) $2,498.49 ▼ 0.77%
BNB BNB (BNB) $708.45 ▼ 0.07%
XRP XRP (XRP) $1.42 ▼ 0.21%
Solana Solana (SOL) $106.54 ▲ 3.54%
Hyperliquid Hyperliquid (HYPE) $84.66 ▲ 3.40%
Gram (prev. Toncoin) Gram (prev. Toncoin) (GRAM) $1.41 ▲ 0.30%

What Happens When a Crypto Exchange Gets Hacked? Lessons From Bybit's $1.5B Breach

By Adrian, [TITLE FROM SITE BIO] – Last updated August 2026

The most useful thing about the Bybit hack explained properly is that it was not a hack of Bybit. No key was stolen, no server was breached, and the cold wallet worked exactly as designed. What failed was the screen the signers were looking at. Understanding that distinction matters more than the headline number, because it changes what you should conclude about where to hold funds. Here is the documented mechanism, the recovery position as of 2026, and what it does and does not imply for ordinary holders.

Key Takeaways

  • On 21 February 2025, roughly 401,000 ETH left a Bybit cold wallet, valued at about $1.46 billion by Elliptic and nearly $1.5 billion by Chainalysis.
  • The attackers compromised a Safe developer’s machine and inserted malicious JavaScript into the wallet interface Bybit’s signers used.
  • Any Bybit hack explained accurately starts here: the signers approved what looked like a routine transfer, but the underlying instruction was different.
  • Elliptic and Chainalysis both attributed the theft to North Korea, an assessment later confirmed by the FBI.
  • By February 2026 Elliptic reported the vast majority of the stolen funds had been processed through laundering channels.

The Bybit hack explained: what actually happened

Chainalysis published a step-by-step account on 24 February 2025, updated three days later. The sequence has five stages.

First, the compromise. The attackers gained access to a Safe developer’s computer and used it to control the Safe user interface specifically serving Bybit’s transactions, adding a malicious JavaScript snippet to the frontend so a malicious transaction would display as a legitimate one.

Second, the transfer. During what appeared to be a routine movement from Bybit’s Ethereum cold wallet to a hot wallet, the signers approved the transaction they could see. The instruction they actually authorised handed control to the attackers, who moved roughly 401,000 ETH to their own addresses.

Third, dispersion through a web of intermediary addresses. Fourth, conversion: significant portions were swapped into BTC and DAI using decentralised exchanges, cross-chain bridges and a no-KYC instant swap service. Fifth, patience. Chainalysis noted a deliberate choice to leave a notable portion dormant, outlasting the scrutiny that follows a high-profile breach.

NCC Group’s technical analysis records the precise figure as 401,347 ETH and notes Bybit’s setup required at least three signers. Multiple signatures did not help, because every signer was shown the same falsified screen.

Why the cold wallet did not protect anything

This is the part worth internalising. Cold storage protects a private key from being extracted remotely. It does nothing about a validly signed transaction, because from the blockchain’s perspective a signature obtained by deception is indistinguishable from one given willingly.

The attack surface was the interface between the human and the key. Bybit did not use a compromised exchange. It used a compromised view of what it was approving, and the security model collapsed at exactly the point where a person reads a screen and decides. Any Bybit hack explained without that emphasis misses why it happened.

Attribution and what followed

Elliptic attributed the theft to North Korea within days, based partly on laundering patterns, an assessment the FBI later confirmed. Chainalysis reached the same conclusion independently, noting that funds from the exploit consolidated in addresses already holding proceeds from other DPRK-linked attacks. Two named firms working from separate evidence is what makes this attribution unusually solid.

Recovery was partial. Chainalysis reported helping freeze more than $40 million in the immediate aftermath, and Bybit launched a bounty offering up to 10% of recovered amounts. Against $1.46 billion, that is a small fraction.

The longer arc is documented in Elliptic’s twelve-month review, published 16 February 2026. Over $1 billion had been laundered within six months, much of it through suspected Chinese over-the-counter services, and by the first anniversary the vast majority of the stolen funds had been processed. Roughly $200 million, close to 15%, went through eXch, a no-KYC service that refused Bybit’s requests to block the activity and shut down on 1 May 2025.

What it means for where you hold funds

The tempting conclusion from any Bybit hack explained is that exchanges are unsafe and self-custody is the answer. That is too simple, and the evidence points somewhere more specific.

Bybit covered customer losses and continued operating, so users did not lose money. The failure was in an institutional signing workflow, not in the exchange’s obligation to its customers. Meanwhile the same class of attack, showing a signer something other than what they are approving, works identically against an individual using a hardware wallet with a compromised front end. Owning your keys does not remove this risk. It transfers it to you.

What actually reduces it is narrower: verify transaction details on a device screen rather than a browser, treat wallet interfaces as attack surface, and split holdings so a single compromised approval cannot take everything. Our overview of the exchanges defining the industry and our piece on centralization versus decentralization cover the trade-offs.

Disclaimer: This article is for informational and educational purposes only and is not financial, investment or security advice. Crypto assets carry risk including total loss, and no custody arrangement removes that risk. Details of this incident are drawn from published analyses by named firms and may be updated as investigations continue. Do your own research and consider speaking to a qualified professional. See our editorial policy for how we source and verify our reporting.

Final Thoughts

The Bybit incident remains the largest confirmed crypto theft on record, and the reason it happened is more mundane than its scale suggests. Sophisticated attackers did not break cryptography. They changed what a handful of people saw on a webpage and waited for the approvals.

That should shift how the industry talks about security. Key storage is a solved problem in the sense that hardware and multi-signature setups work when used correctly. Transaction verification is not solved, because it still depends on a human reading an accurate representation of what they are signing. Until that gap closes, the Bybit hack explained above is a template rather than an anomaly, and the defence is the unglamorous habit of confirming details somewhere the attacker cannot rewrite.

Data Sources

bybit hack explained

Recommended

Bitcoin price
Bitcoin Slips to $64K After Fed's Hawkish 9-3 Hold Vote
Bitcoin price
Best Crypto to Buy in Bear Market: 7 Picks & Strategy for 2026
Ethereum price
Ethereum Slips to $1,874 as ETH ETFs Break 5-Day Streak
Michael Saylor Ethereum Price Prediction: Confidence Collapsed?
What Are the Best Crypto to Buy in 2026? A Data-Driven Guide
Stablecoin Usage Surges as Traders Seek Lower-Risk Crypto Exposure in 2026

Trending

best layer 2 crypto network 2026
Layer 2 Networks Compared: Arbitrum vs Base vs Optimism in 2026
chainlink price prediction 2026
crypto margin trading
What Is Crypto Margin Trading and Who Should Actually Use It
how to buy xrp without kyc
How to Buy XRP Without KYC in 2026: What's Actually Possible
best crypto backed loans
Best Crypto-Backed Loans in 2026: How They Actually Work
crypto taxes 2026
Crypto Tax Basics in 2026: What US Traders Actually Owe

Don’t miss the next 100x trend. Get daily crypto news, market movers, memecoin alerts, and breaking Web3 updates before everyone else.