CoinYQ
Heists & Mysteries4 min readEthereum (ETH)

The $1.5 Billion Blind Signature: How Bybit Survived the Largest Cyber Heist in Human History

In February 2025, North Korea's elite state-sponsored cyberwarfare unit, the Lazarus Group, executed the most daring attack in digital finance history. By poisoning the Safe multi-signature user interface of Bybit's infrastructure, the hackers swapped out transfer parameters during a routine rebalancing, siphoning an astronomical $1.46 billion in Ethereum in a single transaction. Instead of collapsing like Mt. Gox or FTX, CEO Ben Zhou hosted live emergency livestreams, guaranteed 100% customer solvency from corporate reserves, and coordinated a global coalition with Tether to freeze stolen assets—setting a new benchmark for crisis leadership in Web3.

The $1.5 Billion Blind Signature: How Bybit Survived the Largest Cyber Heist in Human History

3-Minute Fast Briefing

  • The ParadoxIn February 2025, Lazarus Group breached Bybit's signing UI, siphoning 400,000+ ETH ($1.46B) in the largest single cyber theft in history.
  • The Turning PointUnlike historical exchange collapses, Bybit CEO Ben Zhou held transparent live briefings within hours, proving 1:1 asset backing and absorbing the entire loss from reserves.
  • The LegacyA global coalition of security researchers, whitehat hackers, and Tether quickly blacklisted attacker addresses, containing the macro contagion across DeFi.

Chronological Timeline

February 20, 2025The Blind Signature Exploit

Lazarus injects malicious code into Bybit's Safe multi-sig UI, altering recipient addresses during a routine transfer.

15 Minutes LaterOn-Chain Alarms & Confirmation

Security firms detect 401,346 ETH moving into an unauthorized address; Bybit freezes bridge contracts.

Hour 2Ben Zhou's Emergency Live Broadcast

Bybit's CEO goes live on X/YouTube, declaring all user funds safe and committing full institutional reserves.

Day 2The Tether Blacklist Alliance

Tether and major exchanges freeze tens of millions in swapped stablecoins as hackers attempt to launder funds across Thorchain.

Day 7Proof-of-Reserves Audit & Recovery

Independent third-party audits verify Bybit's 100%+ reserve ratio, completing the most successful crisis turnaround in crypto history.

1. The 1.46 Billion Dollar Single Click

On February 20, 2025, an ordinary security maintenance routine at Bybit—the world's second-largest cryptocurrency derivatives exchange—turned into the most staggering cyberattack in financial history [3]. Operations engineers were conducting a standard internal rebalancing of funds between vaults and operational liquidity pools [3].

Unbeknownst to the team, North Korea's state-backed Lazarus Group had achieved a surgical, persistent infiltration of the developer environment months earlier [1]. Rather than attempting the impossible task of cracking the cryptographic private keys of Bybit's Safe multi-signature contract, the attackers poisoned the web front-end interface used by executives to review and sign transactions [1, 3]. The sophisticated injection of malicious code into the front-end signing user interface represented a paradigm shift in state-sponsored cyber warfare against financial institutions.

When the authorized signers verified the prompt on their screens, the UI displayed a routine internal transfer [3]. But beneath the visual layer, the malicious script had swapped the destination address and call data. In a single on-chain block, 401,346 Ether (valued at over $1.46 billion) was routed straight into a hacker-controlled address [1].

2. The Alarm: 15 Minutes of Chaos

Within fifteen minutes of the transaction confirmation, automated alerts across blockchain analytics firms like Arkham and Lookonchain lit up with red banners [1]. The transfer represented the largest single theft of cryptocurrency by monetary value in human history, eclipsing the 2022 Network heist ($625M) and Mt. Gox ($460M) combined [1, 3].

Across Twitter and Telegram, panic spread like wildfire. Retail traders rushed to withdraw billions in capital, fearing that Bybit was on the verge of an FTX-style insolvency collapse [3]. Order book spreads widened dramatically across global exchanges as market makers pulled liquidity [3]. The rapid detection of the unauthorized 400,000 ETH transfer demonstrated the critical importance of real-time on-chain monitoring and automated anomaly alerts.

3. The CEO Who Chose Radical Truth

At the critical juncture where previous exchange executives concealed losses or delayed announcements, Bybit co-founder and CEO Ben Zhou chose an unprecedented path: total, unvarnished transparency [3].

Less than two hours after the breach, Zhou appeared live on a global video stream, visibly exhausted but composed [3]. He walked viewers through the exact technical mechanics of the front-end poisoning attack, revealed the full hacker wallet address, and made a historic pledge: Bybit held over $20 billion in client assets, and the exchange would absorb the entire $1.46 billion loss out of its own corporate balance sheet and equity reserves without touching a single dollar of user funds [2, 3]. Ben Zhou's decision to maintain 24/7 unhindered withdrawals while publicly disclosing the full extent of the loss prevented panic from escalating into a catastrophic liquidity crisis.

All user funds are 100% safe. We made an operational mistake on the UI layer, but our balance sheet is rock solid. We will not halt withdrawals for a single second.[1][3]
Ben Zhou, Bybit CEO Emergency Live Stream

By refusing to freeze withdrawals and continuing to process over $3 billion in outbound client requests without delay, Bybit single-handedly crushed the emerging [3].

4. The Global Counteroffensive: Freezing Lazarus

While Bybit fortified its internal reserves, an unprecedented industry-wide defense coalition mobilized to hunt the stolen assets [1, 2]. Security researchers, whitehat developers, and compliance desks from rival exchanges (Binance, OKX, Coinbase) formed a 24/7 war room to track Lazarus's movement [1].

As the hackers attempted to swap tranches of stolen stETH into USDT and route them through decentralized cross-chain protocols like Thorchain, Tether executed emergency smart-contract blacklisting commands, freezing over $80 million in illicit stablecoins within minutes of transfer [2]. The rapid intervention by Tether and major global exchanges in freezing tens of millions in attacker-controlled assets highlighted the defensive power of industry cooperation.

Blockchain forensic teams saturated the mempools with front-running bots, making it extraordinarily costly and slow for the North Korean operatives to bridge or mix the remaining funds without detection [1, 3].

5. The New Benchmark for Web3 Crisis Leadership

Within one week of the largest heist in digital history, third-party cryptographic audits confirmed that Bybit's client asset collateralization ratio remained above 102% across all major tokens [3]. Instead of triggering a market-wide liquidity contagion, Bybit's transparent handling earned praise across Wall Street and the crypto ecosystem [2, 3].

The 2025 Bybit incident marked the end of the era where major exchange hacks inevitably meant insolvency and multi-year bankruptcy litigation. It demonstrated that modern Web3 infrastructure has developed the institutional scale, reserve depth, and collaborative defense mechanisms necessary to withstand even the most sophisticated nation-state cyberattacks [1, 3]. The complete absorption of a $1.46 billion loss through corporate equity proved that leading Web3 exchanges can achieve institutional-grade financial resilience.

Key Takeaways for Investors & Builders

Engineering / Product

Front-end UI poisoning is the ultimate blind spot

Hardware wallets and multi-sigs cannot protect assets if the signing interface displays spoofed transaction data; terminal verification is mandatory.

Market / Investor

Radical transparency halts bank runs

Immediate, unscripted live communication from leadership prevents market panic and preserves counterparty confidence during catastrophic security events.

Philosophy / Governance

The maturity of the industry defense grid

The coordinated response between rival exchanges, stablecoin issuers, and on-chain investigators proved that Web3 has evolved robust immunities against state-level attackers.

Connected Lore & Universe

Connected Stories in this Universe

Explore the chain reaction of historical breakthroughs, blunders, and legends.

Sources & References

  1. [1]Source 1: Lazarus Group (Cyberwarfare Group) Cryptocurrency Operations and State-Sponsored TheftWikimedia Foundation · 2024-02-20
  2. [2]Source 2: Tether Official Transparency & Emergency Blacklist ProtocolTether Operations Limited · 2024-03-01
  3. [3]Source 3: Ethereum Protocol Architecture and Smart Contract Security SpecificationsEthereum Foundation · 2024-01-15