logo

Bybit Incident Technical Analysis

ID: 806dc6d1-7f54-5412-96e9-a8b052fe1537

STIX ID: report--806dc6d1-7f54-5412-96e9-a8b052fe1537

Feed Name: CertiK Blog

Threat Score
95/100

Date Published: 2025-02-23

Date Updated: 2026-06-11

...
...

On 2025-02-21 attackers drained Bybit's cold multisig Ethereum wallet (~$1.46B) by compromising a Safe{Wallet} developer environment and presenting a masked transaction to three signers; the signed transaction used a delegatecall to overwrite the GnosisSafe implementation (masterCopy) with a malicious contract exposing sweepETH/sweepERC20 functions. The report documents exploit transactions and addresses, links the incident to similar prior attacks (Radiant Capital), outlines likely vectors (device compromise, phishing, blind signing), provides mitigation recommendations (hardened endpoints, dedicated signing devices, transaction verification and simulations), and notes Arkham's attribution to the DPRK Lazarus Group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.