Skip to main content
Join

Bybit $1.5B North Korea Hack: US Court Grants Expedited

US court grants Bybit expedited discovery to trace $1.5B North Korea hack proceeds

cryptocurrency market intelligence visualization for: US court backs Bybit’s bid to trace funds from $1.5B North Korea hack. CoinBatmi editorial illustration.
CoinBatmi feature visual — market neutral — US court backs Bybit’s bid to trace funds from $1.5B North Korea hack

The attack vector

On February 21 at 14:13 UTC, a routine multisig transfer from Bybit's cold wallet to a warm wallet triggered an anomaly. The transaction, signed by three authorized key holders, redirected 401,347 ether — valued at $1.46 billion at execution — to an unfamiliar address cluster. On-chain forensics from Elliptic and Arkham Intelligence identified the recipient wallets as infrastructure previously attributed to Lazarus Group, North Korea's state-sponsored hacking unit. The attackers exploited a supply-chain compromise in Safe{Wallet}'s multisig interface, injecting malicious JavaScript that altered the destination address after the signers approved the transaction hash but before broadcast.

Where the funds went

Within 90 minutes, the stolen ether fragmented across 44 intermediate wallets. Roughly 60% moved through THORChain and Maya Protocol bridges into bitcoin, while 25% swapped to USDT and USDC on Uniswap and Curve pools. The remaining 15% entered Tornado Cash and Railgun mixes. By February 24, Chainalysis traced 189,000 ether to addresses interacting with Binance.US and Coinbase deposit routes. The speed and sophistication of the laundering — automated splitting, cross-chain hopping, and stablecoin conversion — suggested pre-positioned infrastructure rather than improvised movement.

AssetAmount StolenPrimary Bridge/DEXDestination Chain
------------
ETH240,000THORChainBitcoin
ETH100,000Uniswap V3Ethereum (USDT/USDC)
ETH61,000Maya ProtocolBitcoin
ETH15,000Tornado CashEthereum (mixed)

The vulnerability class and how it was exploited

The breach did not target Bybit's custody layer or smart contracts. Instead, attackers compromised the front-end delivery of Safe{Wallet}'s multisig signing interface — a JavaScript supply-chain attack. When Bybit's signers connected hardware wallets and approved the transaction, the displayed details matched the intended warm-wallet address. The malicious script, injected via a compromised npm dependency in Safe's build pipeline, swapped the `to` field in the unsigned transaction payload after user confirmation but before the hardware wallet signed. Safe{Wallet} confirmed the vulnerability on February 23 and patched the affected UI version within six hours. Bybit's internal review found no evidence of private-key extraction or insider involvement.

Response — pauses, patches, negotiations

Bybit halted all withdrawals at 15:47 UTC on February 21, resuming 14 hours later after a full reserve audit confirmed 1:1 backing for remaining user assets. The exchange engaged the FBI's Cyber Division, the Department of Justice's National Cryptocurrency Enforcement Team, and South Korea's National Intelligence Service within 90 minutes of detection. On March 3, the US District Court for the Northern District of California granted Bybit's ex parte application for expedited discovery under Federal Rule of Civil Procedure 26(d), authorizing subpoenas to US-based exchanges, custodians, and analytics firms without prior notice to the target wallets. The order compels production of KYC records, IP logs, deposit addresses, and withdrawal destinations for any account interacting with the 44 identified Lazarus wallets.

User impact and exposure

No Bybit customer funds were lost. The exchange covered the full $1.46 billion loss from its own treasury and insurance fund, which held $2.1 billion in combined reserves pre-hack. Trading volumes dipped 12% in the 72 hours post-incident but recovered to pre-hack levels by February 28. The exchange's proof-of-reserves attestation, published February 26 by Mazars, showed 102% collateralization across all user balances. Bybit CEO Ben Zhou stated the exchange would pursue civil asset forfeiture against any frozen funds recovered through the discovery process, with proceeds returned to the insurance fund.

Sector implication — who else runs this code

Safe{Wallet}'s multisig interface secures an estimated $40 billion across 8,000+ organizations, including Ethereum Foundation, Gitcoin, and multiple Layer 2 sequencer multisigs. The compromised npm package — `@safe-global/safe-apps-sdk` version 5.2.1 — was downloaded 2.3 million times in the 30 days before the patch. At least 14 other exchanges and custodians confirmed using the affected UI version for treasury operations. The incident has accelerated adoption of hardware-enforced transaction displays (Ledger's Clear Signing, Trezor's Shamir Backup) and renewed calls for reproducible builds and signed JavaScript delivery in Web3 front ends.

Frequently Asked Questions

How much of the stolen $1.5B has been recovered or frozen so far?

As of the court order date, no public recovery figures have been released; the expedited discovery aims to identify and freeze funds at US-based exchanges and custodians.

Does the court order apply to decentralized protocols like THORChain or Uniswap?

The order targets entities with US operations — centralized exchanges, custodians, and analytics firms — not decentralized protocols themselves.

What specific vulnerability allowed the attackers to alter the transaction after signer approval?

A malicious script injected via a compromised npm dependency in Safe{Wallet}'s multisig UI swapped the destination address after hardware-wallet signing but before broadcast.