Cyb3rius
@cyb3rius
· Sep 5
How did hackers drain $1.5 billion from Bybit?Attackers tricked signers into approving a malicious transaction through a disguised Safe Wallet interface, allowing them to take complete control of an Ethereum cold wallet.What happened: On Feb 21, 2025, Bybit, a top-tier exchange, saw 401,347 ETH siphoned from a single multisig cold wallet when a spoofed Safe({Wallet}) UI blinded the signers. Researchers at Elliptic and ZachXBT attributed the heist to North Korea’s Lazarus Group, which used a malicious contract to replace the wallet’s logic before moving funds.Key numbers: $1.5 billion stolen in one attack, the largest in crypto history.401,347 ETH taken in a single unauthorised transfer.Over 70% of assets were laundered through bridges like Ren and Thorchain within the first 48 hours.Why it matters: This shows that even audited multisig infrastructure fails when the human signer cannot verify what they are approving, and nation-state groups now operate with exchange-grade speed.Bottom line: The weakest link in any wallet is
0