North Korean Hackers Steal $1.5 Billion in Crypto from Bybit: The Largest Heist in History
In one of the most audacious cyberattacks in cryptocurrency history, North Korean state-backed hackers stole approximately $1.5 billion from the Dubai-based exchange Bybit in February 2025. The operation, attributed to the notorious Lazarus Group (also referred to as TraderTraitor by the FBI), marked the single largest crypto theft ever recorded and contributed heavily to North Korea’s record-breaking $2.02 billion in crypto heists for the year. Cumulatively, the regime has allegedly stolen around $6.75 billion in digital assets since 2017, funds believed to support its nuclear and ballistic missile programs in defiance of international sanctions.
How the Hack Unfolded
The breach occurred on or around February 21, 2025, during what was intended to be a routine internal transfer of Ethereum (ETH) from Bybit’s secure cold wallet (offline storage) to a warm wallet (online but protected). Instead of a straightforward move, the funds—roughly 400,000 ETH—were diverted to addresses controlled by the attackers.
Investigations revealed that the hackers had compromised a third-party tool used by Bybit for managing Ethereum operations, specifically linked to Safe, a popular smart contract wallet platform. Bybit later traced the initial breach to this vector. The attack was not a traditional smart contract exploit or brute-force wallet crack but a sophisticated supply-chain style operation.
Hackers likely gained access through classic but highly refined techniques:
- Phishing or social engineering campaigns targeting employees or developers.
- Malware delivered via fake job offers, malicious GitHub repositories, coding challenges, or apps shared on Telegram and Discord.
- Compromise of developer workstations or internal systems that allowed manipulation of multi-signature approvals and transaction signing processes.
Once inside, the attackers altered the transfer destination or intercepted the approval process. When an authorized Bybit executive signed off on what appeared to be a legitimate transaction, the funds were redirected in a matter of minutes—some reports indicate the core drainage happened within as little as 2 to 12 minutes.
Laundering the Stolen Funds
Stealing such a massive sum is only half the challenge; converting it into usable money without triggering alarms is where North Korean operators have demonstrated exceptional expertise. In the Bybit case, the stolen ETH was rapidly dispersed across thousands of addresses and multiple blockchains.
The laundering process followed a well-honed playbook:
- Immediate use of cross-chain bridges and decentralized exchanges (DEXs) to swap ETH into Bitcoin, Solana, Avalanche, or Tron-based USDT.
- Layering transactions in smaller amounts (often under $500,000) to avoid detection.
- Reliance on mixers, privacy protocols, and lesser-regulated services.
- Heavy use of Chinese-language over-the-counter (OTC) brokers and underground banking networks with weak compliance—sometimes referred to as the “Chinese Laundromat.”
Blockchain analytics firms reported that hundreds of millions were moved and converted within the first few weeks, with at least $160 million laundered in the initial 48 hours and over $300 million successfully cashed out shortly thereafter. North Korean hackers typically operate on a roughly 45-day laundering cycle, gradually integrating funds into exchanges with lax Know-Your-Customer (KYC) policies.
Broader Context: Lazarus Group’s Crypto Campaign
The Lazarus Group, linked to North Korea’s Reconnaissance General Bureau, has a long track record of high-profile operations, including the 2014 Sony Pictures hack and numerous crypto thefts such as the $620 million Ronin Network breach. Their tactics often involve posing as remote IT workers or recruiters to infiltrate target organizations, deploying custom malware for credential theft, and exploiting wallet management systems.
In 2025, their attacks were fewer in number but significantly larger in scale, with the Bybit heist dwarfing other incidents. This reflects increasing operational sophistication and possibly improved security practices on their part.
The stolen funds serve a strategic purpose for the isolated regime: evading sanctions, financing weapons development, and sustaining its economy. Cryptocurrency’s borderless and pseudonymous nature makes it an attractive target compared to traditional financial systems.
Aftermath and Industry Implications
Recovery efforts have been limited. While blockchain transparency allowed firms like Chainalysis, TRM Labs, and Elliptic to track the flows and confirm the Lazarus Group’s involvement, once the funds pass through mixers, bridges, and OTC networks, they become extremely difficult to seize. Only a small fraction of the stolen assets has been frozen or recovered.
The incident caused brief volatility in Ethereum and Bitcoin prices and prompted heightened scrutiny of exchange security practices. Bybit’s CEO publicly acknowledged the breach, and the exchange collaborated with law enforcement and blockchain analytics companies.
In response, the crypto industry has accelerated improvements in:
- Multi-factor authentication and hardware security modules.
- Stricter vetting of third-party tools and services.
- Real-time transaction monitoring and anomaly detection.
- Greater reliance on cold storage for large holdings.
Geopolitically, the United States, South Korea, Japan, and other nations continue to impose sanctions and work with private analytics firms to disrupt North Korean laundering networks. However, the regime’s closed system and dedicated hacking infrastructure make complete disruption challenging.
The Bybit hack serves as a stark reminder of cryptocurrency’s dual-edged nature: a revolutionary financial technology that remains highly vulnerable to well-resourced nation-state actors who operate with little regard for international norms. While retail users and smaller platforms face risks from scams and personal wallet compromises, large centralized exchanges continue to be prime targets for groups like Lazarus due to the enormous scale of assets under their custody.
As blockchain analytics continue to evolve, reports from firms such as Chainalysis and TRM Labs remain essential for understanding the on-chain movements and future patterns of such sophisticated threats.