What happened
On February 21, 2025, Bybit lost around 401,000 ETH and stETH, worth roughly $1.5 billion, from a cold wallet. The Safe Ecosystem Foundation confirmed the attack was achieved through a compromised Safe{Wallet} developer machine, which allowed malicious JavaScript to be injected into app.safe.global. The payload activated only for Bybit's authorised signers. Multiple firms including TRM Labs and Elliptic linked the addresses to prior North Korean thefts.
How the deception worked
The attackers never phished a Bybit employee. They compromised a developer machine at Safe{Wallet}, Bybit's multisig interface provider, and used it to place JavaScript into the web application that Bybit's signers loaded. The payload was conditional, activating only when specific signer addresses interacted with the Bybit Safe, which kept it invisible to everyone else. When the signers reviewed what looked like a routine transfer, the injected code masked the signing interface and altered the underlying EIP-712 message: the approved transaction carried a delegatecall that repointed the Safe proxy's implementation slot at an attacker-controlled contract. Each signer approved in good faith, and the resulting signatures were cryptographically valid.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Transaction data must be verified on an air-gapped device that decodes the raw payload independently of the web interface, and blind approval of delegatecall operations on a treasury Safe should be blocked by policy.
Sources (5)
- Lazarus hacked Bybit via breached Safe{Wallet} developer machineBleepingComputer·bleepingcomputer.comOpen ↗
- In-Depth Technical Analysis of the Bybit HackNCC Group·nccgroup.comOpen ↗
- Sygnia's Investigation into the Bybit Hack: What We Know So FarSygnia·sygnia.coOpen ↗
- Bybit and Safe Custody Are at Odds on Who's to Blame for $1.5B HackCoinDesk·coindesk.comOpen ↗
- How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency HeistSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.