La firma ciega de 1.500 millones: Cómo Bybit sobrevivió al mayor ciberatraco de la historia
En febrero de 2025, el grupo Lazarus manipuló la interfaz de firma en frío de Bybit, sustrayendo 1.460 millones de dólares en Ethereum en una sola transacción. La gestión de crisis de Ben Zhou, la cobertura total con reservas corporativas y el bloqueo coordinado de fondos con Tether evitaron el colapso del mercado.

Resumen clave en 3 puntos
- El detonante / ParadojaIn February 2025, Lazarus Group breached Bybit's cold storage signing UI, siphoning 400,000+ ETH ($1.46B) in the largest single cyber theft in history.
- El punto de inflexiónUnlike historical exchange collapses, Bybit CEO Ben Zhou held transparent live briefings within hours, proving 1:1 asset backing and absorbing the entire loss from reserves.
- El legado históricoA global coalition of security researchers, whitehat hackers, and Tether quickly blacklisted attacker addresses, containing the macro contagion across DeFi.
Cronología de los hechos
Lazarus injects malicious code into Bybit's Safe multi-sig UI, altering recipient addresses during a routine cold storage transfer.
Security firms detect 401,346 ETH moving into an unauthorized address; Bybit freezes bridge contracts.
Bybit's CEO goes live on X/YouTube, declaring all user funds safe and committing full institutional reserves.
Tether and major exchanges freeze tens of millions in swapped stablecoins as hackers attempt to launder funds across Thorchain.
Independent third-party audits verify Bybit's 100%+ reserve ratio, completing the most successful crisis turnaround in crypto history.
1. The 1.46 Billion Dollar Single Click
On February 20, 2025, an ordinary security maintenance routine at Bybit—the world's second-largest cryptocurrency derivatives exchange—turned into the most staggering cyberattack in financial history [3]. Operations engineers were conducting a standard internal rebalancing of funds between cold storage vaults and operational liquidity pools [3].
Unbeknownst to the team, North Korea's state-backed Lazarus Group had achieved a surgical, persistent infiltration of the developer environment months earlier [1]. Rather than attempting the impossible task of cracking the cryptographic private keys of Bybit's Safe multi-signature contract, the attackers poisoned the web front-end interface used by executives to review and sign transactions [1, 3]. La sofisticada manipulación del código en la interfaz web de firma representó un salto cualitativo en las tácticas de ciberguerra patrocinadas por estados contra infraestructuras financieras.
When the authorized signers verified the prompt on their screens, the UI displayed a routine internal transfer [3]. But beneath the visual layer, the malicious script had swapped the destination address and call data. In a single on-chain block, 401,346 Ether (valued at over $1.46 billion) was routed straight into a hacker-controlled address [1].
2. The Alarm: 15 Minutes of Chaos
Within fifteen minutes of the transaction confirmation, automated alerts across blockchain analytics firms like Arkham and Lookonchain lit up with red banners [1]. The transfer represented the largest single theft of cryptocurrency by monetary value in human history, eclipsing the 2022 Ronin Network heist ($625M) and Mt. Gox ($460M) combined [1, 3].
Across Twitter and Telegram, panic spread like wildfire. Retail traders rushed to withdraw billions in capital, fearing that Bybit was on the verge of an FTX-style insolvency collapse [3]. Order book spreads widened dramatically across global exchanges as market makers pulled liquidity [3]. La detección instantánea del desvío de más de 400.000 ETH evidenció la trascendencia de los sistemas automatizados de supervisión y alerta temprana en la cadena de bloques.
3. The CEO Who Chose Radical Truth
At the critical juncture where previous exchange executives concealed losses or delayed announcements, Bybit co-founder and CEO Ben Zhou chose an unprecedented path: total, unvarnished transparency [3].
Less than two hours after the breach, Zhou appeared live on a global video stream, visibly exhausted but composed [3]. He walked viewers through the exact technical mechanics of the front-end poisoning attack, revealed the full hacker wallet address, and made a historic pledge: Bybit held over $20 billion in client assets, and the exchange would absorb the entire $1.46 billion loss out of its own corporate balance sheet and equity reserves without touching a single dollar of user funds [2, 3]. La determinación del consejero delegado Ben Zhou de mantener los retiros operativos y asumir la totalidad del quebranto con fondos propios neutralizó de raíz el riesgo de pánico bancario.
All user funds are 100% safe. We made an operational mistake on the UI layer, but our balance sheet is rock solid. We will not halt withdrawals for a single second.[1][3]— Ben Zhou, Bybit CEO Emergency Live Stream
By refusing to freeze withdrawals and continuing to process over $3 billion in outbound client requests without delay, Bybit single-handedly crushed the emerging bank run [3].
4. The Global Counteroffensive: Freezing Lazarus
While Bybit fortified its internal reserves, an unprecedented industry-wide defense coalition mobilized to hunt the stolen assets [1, 2]. Security researchers, whitehat developers, and compliance desks from rival exchanges (Binance, OKX, Coinbase) formed a 24/7 war room to track Lazarus's movement [1].
As the hackers attempted to swap tranches of stolen stETH into USDT and route them through decentralized cross-chain protocols like Thorchain, Tether executed emergency smart-contract blacklisting commands, freezing over $80 million in illicit stablecoins within minutes of transfer [2]. La inmediata intervención de Tether y de las principales plataformas globales para bloquear decenas de millones en activos del atacante demostró la eficacia de la defensa coordinada.
Blockchain forensic teams saturated the mempools with front-running bots, making it extraordinarily costly and slow for the North Korean operatives to bridge or mix the remaining funds without detection [1, 3].
5. The New Benchmark for Web3 Crisis Leadership
Within one week of the largest heist in digital history, third-party cryptographic Proof-of-Reserves audits confirmed that Bybit's client asset collateralization ratio remained above 102% across all major tokens [3]. Instead of triggering a market-wide liquidity contagion, Bybit's transparent handling earned praise across Wall Street and the crypto ecosystem [2, 3].
The 2025 Bybit incident marked the end of the era where major exchange hacks inevitably meant insolvency and multi-year bankruptcy litigation. It demonstrated that modern Web3 infrastructure has developed the institutional scale, reserve depth, and collaborative defense mechanisms necessary to withstand even the most sophisticated nation-state cyberattacks [1, 3]. La absorción íntegra de un impacto de 1.460 millones de dólares mediante reservas corporativas acreditó la solidez patrimonial alcanzada por la industria de activos digitales.
Lecciones clave para inversores y creadores
Front-end UI poisoning is the ultimate blind spot
Hardware wallets and multi-sigs cannot protect assets if the signing interface displays spoofed transaction data; air-gapped terminal verification is mandatory.
Radical transparency halts bank runs
Immediate, unscripted live communication from leadership prevents market panic and preserves counterparty confidence during catastrophic security events.
The maturity of the industry defense grid
The coordinated response between rival exchanges, stablecoin issuers, and on-chain investigators proved that Web3 has evolved robust immunities against state-level attackers.
Historias conectadas con este personaje o suceso
Explora las repercusiones históricas y los vínculos entre figuras y momentos clave.

El frenesí de 2.600 millones 'HEY HEY HEEEY!': BitConnect y Carlos Matos en la comedia-tragedia definitiva
El colapso de 2.600 millones de BitConnect, el legendario grito de Pattaya y la insólita resurrección de Carlos Matos como coach.
Leer historia →
El cocodrilo de Wall Street: Razzlekhan, los 119.754 Bitcoin de Bitfinex y la incautación récord de 3.600 millones
La doble vida de una columnista de Forbes y rapera cómica que blanqueó 120.000 Bitcoin robados, terminando en una histórica incautación de 3.600 millones.
Leer historia →
El leviatán de 3.000 millones: Dentro de PlusToken y el terremoto de los 190.000 Bitcoin en el mercado
La macroestafa de 3.000 millones de PlusToken, la captura de la cúpula en Vanuatu y el desplome del mercado por la venta masiva de 194.000 BTC.
Leer historia →Fuentes y referencias
- [1]Fuente 1: Lazarus Group (Cyberwarfare Group) Cryptocurrency Operations and State-Sponsored TheftWikimedia Foundation · 2024-02-20
- [2]Fuente 2: Tether Official Transparency & Emergency Blacklist ProtocolTether Operations Limited · 2024-03-01
- [3]Fuente 3: Ethereum Protocol Architecture and Smart Contract Security SpecificationsEthereum Foundation · 2024-01-15