Published on March 4, 2025. EST READ TIME: 2 minutes
In a significant cybersecurity breach, the FBI has attributed the $1.5 billion theft from cryptocurrency exchange Bybit to North Korea’s Lazarus Group. The incident, recognized as the largest cryptocurrency heist to date, involved the theft of approximately 400,000 Ethereum (ETH and stETH) from Bybit’s offline wallet. The hackers manipulated the user interface during a transfer from a cold wallet to a warm wallet, altering the underlying smart contract logic to redirect funds to an address under their control. Post-theft, the stolen assets were converted into Bitcoin and dispersed across numerous blockchain addresses, complicating recovery efforts. Bybit has initiated a ‘recovery bug bounty program,’ offering up to 10% of the recovered amount to individuals aiding in the retrieval of the stolen funds. The exchange assures its users of continued solvency and is actively cooperating with international authorities to address the breach and enhance security measures.