Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedConfirmed

Bybit's $1.5B loss: signers approved a masked transaction on a poisoned Safe UI

Bybit · Cryptocurrency · United Arab Emirates · February 21, 2025

Funds lost
$1,500,000,000
Money actually taken from, or wired out by, the victim.
Approximately 401,000 ETH and stETH, valued between roughly $1.4 billion and $1.5 billion at the time depending on the analysis. It is the largest cryptocurrency theft on record.

What happened

On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.

How the deception worked

The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.

AI involvement · No AI reported

No AI involvement was reported.

The control that would have caught it· our reading, not a claim from the sources

Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.

Sources (5)

  1. Lazarus hacked Bybit via breached Safe{Wallet} developer machine
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. In-Depth Technical Analysis of the Bybit Hack
    NCC Group·nccgroup.comOpen ↗
  3. Sygnia's Investigation into the Bybit Hack: What We Know So Far
    Sygnia·sygnia.coOpen ↗
  4. Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B Hack
    CoinDesk·coindesk.comOpen ↗
  5. How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.