Bybit disclosed on February 21, 2025 that an attacker had taken control of one of the cryptocurrency exchange’s Ethereum cold wallets during a routine transfer to a warm wallet. An Ethereum transaction recorded 401,346.768858 ETH leaving the affected wallet at 14:16:11 UTC. Contemporaneous reporting put the combined value of the stolen ETH and related assets at about $1.5 billion, making the incident one of the largest online thefts reported by that date.
The loss mattered beyond its size. Cold wallets and multisignature approval processes are intended to separate institutional reserves from continuously connected systems and prevent any one operator from moving funds. Bybit’s preliminary account indicated that those controls were defeated at the transaction-approval layer: signers were shown an expected destination while the underlying smart-contract instructions had been altered.
What the public record established
Bybit’s incident chronology says the exchange began a routine transfer from an Ethereum multisignature cold wallet at 13:30 UTC on February 21, initially moving 30,000 ETH. It places the malicious intervention at approximately 14:13 UTC and says the compromised transaction changed the wallet’s smart-contract logic, enabling the remaining assets to be transferred and divided among numerous addresses.
The Ethereum record independently confirms a central portion of that account. Transaction `0xb61413c495fdad6114a7aa863a00b2e3c28945979a10885b12b30316ea9f072c` succeeded at 14:16:11 UTC and produced an internal transfer of precisely 401,346.768858404671846374 ETH from the address labeled as Bybit’s cold wallet to an address labeled as the exploiter.
That transaction verifies the asset movement, timestamp and quantity. Address labels and the characterization of the movement as theft depend on attribution supplied to the explorer and corroborating records. The transaction alone does not establish who operated the recipient address, how the signing environment was compromised or the complete dollar value of all affected assets.
Bybit later itemized the loss as 401,347 ETH, 90,375 stETH, 15,000 cmETH and 8,000 mETH, valued by the company at a combined $1.46 billion. Those dollar figures were valuation snapshots, not proceeds realized in a sale. They depended on token prices around the incident and should not be treated as a fixed accounting value.
An immediate test of exchange liquidity
Chief executive Ben Zhou publicly acknowledged the incident at 15:44 UTC on February 21. Bybit said only the identified Ethereum cold wallet had been compromised and maintained that its other wallets and platform services remained operational.
The Associated Press reported on February 21 that withdrawal requests surged after the disclosure and that Bybit warned customers processing could be delayed. Zhou asserted that the exchange remained solvent, that customer assets were backed one-to-one and that Bybit could absorb the loss even if none of the stolen assets were recovered.
Those were consequential management claims, not an independently audited balance-sheet finding available on February 21. The observable withdrawal pressure turned the breach into a broader institutional question: whether Bybit could continue meeting customer demands while replacing or financing an unusually large gap in its Ethereum holdings.
What remained unresolved on February 21
The event-day evidence did not establish a verified attacker, a final technical root cause or the exchange’s complete financial position. Bybit described a spoofed signing interface and altered smart-contract logic, but a completed third-party forensic report was not yet public. Early private-sector attribution to North Korea’s Lazarus Group was therefore an allegation rather than an official conclusion.
The defensible February 21 conclusion was narrower. A transaction approved through an institutional multisignature workflow transferred more than 401,000 ETH from Bybit’s cold wallet, while the exchange faced heavy withdrawal demand and asserted that it could cover the loss.
Later context
On February 26, 2025, the FBI attributed the approximately $1.5 billion theft to North Korea and called the activity TraderTraitor. That government attribution strengthened the subsequent record, but it was not available when Bybit disclosed the breach on February 21 and does not belong in the event-day assessment of responsibility.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

