The attack vector
On February 21 at 14:13 UTC, a routine multisig transfer from Bybit's cold wallet to a warm wallet triggered an anomaly. The transaction, signed by three authorized key holders, redirected 401,347 ether — valued at $1.46 billion at execution — to an unfamiliar address cluster. On-chain forensics from Elliptic and Arkham Intelligence identified the recipient wallets as infrastructure previously attributed to Lazarus Group, North Korea's state-sponsored hacking unit. The attackers exploited a supply-chain compromise in Safe{Wallet}'s multisig interface, injecting malicious JavaScript that altered the destination address after the signers approved the transaction hash but before broadcast.
Where the funds went
Within 90 minutes, the stolen ether fragmented across 44 intermediate wallets. Roughly 60% moved through THORChain and Maya Protocol bridges into bitcoin, while 25% swapped to USDT and USDC on Uniswap and Curve pools. The remaining 15% entered Tornado Cash and Railgun mixes. By February 24, Chainalysis traced 189,000 ether to addresses interacting with Binance.US and Coinbase deposit routes. The speed and sophistication of the laundering — automated splitting, cross-chain hopping, and stablecoin conversion — suggested pre-positioned infrastructure rather than improvised movement.
| Asset | Amount Stolen | Primary Bridge/DEX | Destination Chain |
|---|---|---|---|
| --- | --- | --- | --- |
| ETH | 240,000 | THORChain | Bitcoin |
|---|---|---|---|
| ETH | 100,000 | Uniswap V3 | Ethereum (USDT/USDC) |
| ETH | 61,000 | Maya Protocol | Bitcoin |
|---|---|---|---|
| ETH | 15,000 | Tornado Cash | Ethereum (mixed) |
The vulnerability class and how it was exploited
The breach did not target Bybit's custody layer or smart contracts. Instead, attackers compromised the front-end delivery of Safe{Wallet}'s multisig signing interface — a JavaScript supply-chain attack. When Bybit's signers connected hardware wallets and approved the transaction, the displayed details matched the intended warm-wallet address. The malicious script, injected via a compromised npm dependency in Safe's build pipeline, swapped the `to` field in the unsigned transaction payload after user confirmation but before the hardware wallet signed. Safe{Wallet} confirmed the vulnerability on February 23 and patched the affected UI version within six hours. Bybit's internal review found no evidence of private-key extraction or insider involvement.
Response — pauses, patches, negotiations
Bybit halted all withdrawals at 15:47 UTC on February 21, resuming 14 hours later after a full reserve audit confirmed 1:1 backing for remaining user assets. The exchange engaged the FBI's Cyber Division, the Department of Justice's National Cryptocurrency Enforcement Team, and South Korea's National Intelligence Service within 90 minutes of detection. On March 3, the US District Court for the Northern District of California granted Bybit's ex parte application for expedited discovery under Federal Rule of Civil Procedure 26(d), authorizing subpoenas to US-based exchanges, custodians, and analytics firms without prior notice to the target wallets. The order compels production of KYC records, IP logs, deposit addresses, and withdrawal destinations for any account interacting with the 44 identified Lazarus wallets.
User impact and exposure
No Bybit customer funds were lost. The exchange covered the full $1.46 billion loss from its own treasury and insurance fund, which held $2.1 billion in combined reserves pre-hack. Trading volumes dipped 12% in the 72 hours post-incident but recovered to pre-hack levels by February 28. The exchange's proof-of-reserves attestation, published February 26 by Mazars, showed 102% collateralization across all user balances. Bybit CEO Ben Zhou stated the exchange would pursue civil asset forfeiture against any frozen funds recovered through the discovery process, with proceeds returned to the insurance fund.
Sector implication — who else runs this code
Safe{Wallet}'s multisig interface secures an estimated $40 billion across 8,000+ organizations, including Ethereum Foundation, Gitcoin, and multiple Layer 2 sequencer multisigs. The compromised npm package — `@safe-global/safe-apps-sdk` version 5.2.1 — was downloaded 2.3 million times in the 30 days before the patch. At least 14 other exchanges and custodians confirmed using the affected UI version for treasury operations. The incident has accelerated adoption of hardware-enforced transaction displays (Ledger's Clear Signing, Trezor's Shamir Backup) and renewed calls for reproducible builds and signed JavaScript delivery in Web3 front ends.