15億ドルのブラインド署名:バイビット(Bybit)は史上最大のハッキングからどう生還したか
2025年2月、北朝鮮ラザルスがBybitのコールドウォレット署名UIを偽装し、単一トランザクションで14.6億ドル(約2,200億円)のETHを強奪。ベン・ジョウCEOの迅速なライブ配信とテザー社との連携により、顧客資産100%保全を成し遂げた危機管理の実話。

3点クイック要約
- 発端 / 逆説In February 2025, Lazarus Group breached Bybit's cold storage signing UI, siphoning 400,000+ ETH ($1.46B) in the largest single cyber theft in history.
- 決定的瞬間Unlike historical exchange collapses, Bybit CEO Ben Zhou held transparent live briefings within hours, proving 1:1 asset backing and absorbing the entire loss from reserves.
- 歴史的結末A global coalition of security researchers, whitehat hackers, and Tether quickly blacklisted attacker addresses, containing the macro contagion across DeFi.
出来事のタイムライン
Lazarus injects malicious code into Bybit's Safe multi-sig UI, altering recipient addresses during a routine cold storage transfer.
Security firms detect 401,346 ETH moving into an unauthorized address; Bybit freezes bridge contracts.
Bybit's CEO goes live on X/YouTube, declaring all user funds safe and committing full institutional reserves.
Tether and major exchanges freeze tens of millions in swapped stablecoins as hackers attempt to launder funds across Thorchain.
Independent third-party audits verify Bybit's 100%+ reserve ratio, completing the most successful crisis turnaround in crypto history.
1. The 1.46 Billion Dollar Single Click
On February 20, 2025, an ordinary security maintenance routine at Bybit—the world's second-largest cryptocurrency derivatives exchange—turned into the most staggering cyberattack in financial history [3]. Operations engineers were conducting a standard internal rebalancing of funds between cold storage vaults and operational liquidity pools [3].
Unbeknownst to the team, North Korea's state-backed Lazarus Group had achieved a surgical, persistent infiltration of the developer environment months earlier [1]. Rather than attempting the impossible task of cracking the cryptographic private keys of Bybit's Safe multi-signature contract, the attackers poisoned the web front-end interface used by executives to review and sign transactions [1, 3]. 北朝鮮のサイバー部隊ラザルスによるフロントエンド署名UIの改ざん攻撃は、スマートコントラクトの安全性だけに頼っていたセキュリティ業界に深刻な衝撃を与えました。
When the authorized signers verified the prompt on their screens, the UI displayed a routine internal transfer [3]. But beneath the visual layer, the malicious script had swapped the destination address and call data. In a single on-chain block, 401,346 Ether (valued at over $1.46 billion) was routed straight into a hacker-controlled address [1].
2. The Alarm: 15 Minutes of Chaos
Within fifteen minutes of the transaction confirmation, automated alerts across blockchain analytics firms like Arkham and Lookonchain lit up with red banners [1]. The transfer represented the largest single theft of cryptocurrency by monetary value in human history, eclipsing the 2022 Ronin Network heist ($625M) and Mt. Gox ($460M) combined [1, 3].
Across Twitter and Telegram, panic spread like wildfire. Retail traders rushed to withdraw billions in capital, fearing that Bybit was on the verge of an FTX-style insolvency collapse [3]. Order book spreads widened dramatically across global exchanges as market makers pulled liquidity [3]. 単一の送金で約40万ETHが流出した直後、リアルタイムのオンチェーン監視網が即座に異常を検知したことで、さらなる被害拡大を阻止することができました。
3. The CEO Who Chose Radical Truth
At the critical juncture where previous exchange executives concealed losses or delayed announcements, Bybit co-founder and CEO Ben Zhou chose an unprecedented path: total, unvarnished transparency [3].
Less than two hours after the breach, Zhou appeared live on a global video stream, visibly exhausted but composed [3]. He walked viewers through the exact technical mechanics of the front-end poisoning attack, revealed the full hacker wallet address, and made a historic pledge: Bybit held over $20 billion in client assets, and the exchange would absorb the entire $1.46 billion loss out of its own corporate balance sheet and equity reserves without touching a single dollar of user funds [2, 3]. ベン・ジョウCEOが自らライブ配信を行い、出金を一切止めることなく自社準備金での全額補填を宣言した迅速な対応は、危機管理の新たな模範となりました。
All user funds are 100% safe. We made an operational mistake on the UI layer, but our balance sheet is rock solid. We will not halt withdrawals for a single second.[1][3]— Ben Zhou, Bybit CEO Emergency Live Stream
By refusing to freeze withdrawals and continuing to process over $3 billion in outbound client requests without delay, Bybit single-handedly crushed the emerging bank run [3].
4. The Global Counteroffensive: Freezing Lazarus
While Bybit fortified its internal reserves, an unprecedented industry-wide defense coalition mobilized to hunt the stolen assets [1, 2]. Security researchers, whitehat developers, and compliance desks from rival exchanges (Binance, OKX, Coinbase) formed a 24/7 war room to track Lazarus's movement [1].
As the hackers attempted to swap tranches of stolen stETH into USDT and route them through decentralized cross-chain protocols like Thorchain, Tether executed emergency smart-contract blacklisting commands, freezing over $80 million in illicit stablecoins within minutes of transfer [2]. テザー社による迅速な数十億円規模のUSDTブラックリスト凍結と競合取引所の協力は、国家ハッカーによる資金洗浄の道を強力に遮断しました。
Blockchain forensic teams saturated the mempools with front-running bots, making it extraordinarily costly and slow for the North Korean operatives to bridge or mix the remaining funds without detection [1, 3].
5. The New Benchmark for Web3 Crisis Leadership
Within one week of the largest heist in digital history, third-party cryptographic Proof-of-Reserves audits confirmed that Bybit's client asset collateralization ratio remained above 102% across all major tokens [3]. Instead of triggering a market-wide liquidity contagion, Bybit's transparent handling earned praise across Wall Street and the crypto ecosystem [2, 3].
The 2025 Bybit incident marked the end of the era where major exchange hacks inevitably meant insolvency and multi-year bankruptcy litigation. It demonstrated that modern Web3 infrastructure has developed the institutional scale, reserve depth, and collaborative defense mechanisms necessary to withstand even the most sophisticated nation-state cyberattacks [1, 3]. 2,000億円を超える巨額の損失を外部の救済なしに自社資本で完全に吸収したことは、大手暗号資産取引所の強固な財務体質と業界の成熟を証明しました。
この事件から学ぶ重要教訓(Key Takeaways)
Front-end UI poisoning is the ultimate blind spot
Hardware wallets and multi-sigs cannot protect assets if the signing interface displays spoofed transaction data; air-gapped terminal verification is mandatory.
Radical transparency halts bank runs
Immediate, unscripted live communication from leadership prevents market panic and preserves counterparty confidence during catastrophic security events.
The maturity of the industry defense grid
The coordinated response between rival exchanges, stablecoin issuers, and on-chain investigators proved that Web3 has evolved robust immunities against state-level attackers.
この人物・事件と繋がる関連ストーリー
歴史のバタフライ効果で結びついた、もう一つのドラマを探求する。

3,000億円の狂乱「HEY HEY HEEEY!」:ビットコネクトと怪演カルロス・マトスの不滅の喜劇と悲劇
3,000億円のビットコネクト崩壊、伝説の3分パタヤ絶叫スピーチ、そして恥を乗り越え講師となったカルロス・マトスの復活劇。
ストーリーを読む →
ウォール街のワニ・ラズルカーン:12万ビットフィネックスBTCと米司法省史上最大の5,000億円押収事件
フォーブス執筆者とラッパーの二重生活、12万BTCの資金洗浄、そして米政府史上最大の5,000億円押収劇。
ストーリーを読む →
30億ドルの怪物プラストークン(PlusToken):中韓300万人を飲み込んだポンジと19万BTC売り圧力の真実
300万人を巻き込んだ30億ドルのプラストークン崩壊、19万BTCの市場投下と2019年暴落の舞台裏。
ストーリーを読む →出典・参考文献
- [1]出典 1: Lazarus Group (Cyberwarfare Group) Cryptocurrency Operations and State-Sponsored TheftWikimedia Foundation · 2024-02-20
- [2]出典 2: Tether Official Transparency & Emergency Blacklist ProtocolTether Operations Limited · 2024-03-01
- [3]出典 3: Ethereum Protocol Architecture and Smart Contract Security SpecificationsEthereum Foundation · 2024-01-15