Bybit said on February 22, 2025 that it had processed more than 350,000 withdrawal requests and restored normal withdrawal speeds after a theft from its Ethereum cold wallet triggered an extraordinary run on the exchange.

The claim marked the first operational test following the February 21 attack, in which approximately $1.46 billion of ether and liquid-staking tokens was transferred from a Bybit-controlled wallet. The theft itself occurred on February 21. The consequential development tied specifically to February 22 was that customers continued withdrawing assets and Bybit said it met the queue without closing the withdrawal system.

That distinction mattered. Crypto history contained multiple examples in which withdrawal delays became the first public sign that an exchange lacked liquid assets or could not honor customer balances. Bybit’s ability to keep processing exits did not undo the theft or prove that every liability was covered, but it reduced the immediate risk that a security incident would become an operational freeze.

What Bybit reported

Bybit’s incident timeline records that, at 00:54 UTC on February 22, chief executive Ben Zhou announced that 99.994% of more than 350,000 withdrawal requests had been processed within ten hours of the attack. At 02:51 UTC, Zhou said all pending withdrawals had been processed and normal operating speed had resumed.

Those figures were company claims, not an event-day independent audit. They describe requests processed rather than the dollar value successfully received by customers, and the published record does not provide a token-by-token reconciliation for that ten-hour window.

Bybit also said it was relying on bridge financing from industry partners to manage its ether liquidity. Bitget had transferred 40,000 ETH to Bybit on February 21, according to Bybit’s timeline. On February 22, Bybit launched a recovery-bounty program offering 10% of recovered funds to participants who helped trace and freeze the stolen assets.

The measurable run on the exchange

Contemporaneous CoinDesk reporting used DeFiLlama’s labeled-wallet dataset to estimate that assets associated with Bybit fell from approximately $16.9 billion to $11.2 billion between the attack and the article’s February 22 observation window. CoinDesk characterized the movement as more than $5.5 billion of total outflow, including the stolen assets, with customer withdrawals accounting for more than $4 billion.

That measurement was an estimate, not a balance-sheet audit. DeFiLlama tracked publicly labeled wallets, so the result could be affected by address coverage, internal transfers and changing token prices. It nevertheless showed that the withdrawal response was not a minor queue-management exercise: the exchange was handling a run measured in billions of dollars while replacing lost ether liquidity.

The National separately reported on February 22 that withdrawals remained active and that Zhou said partner bridge loans had secured nearly 80% of the stolen ether requirement. That percentage was attributable to Zhou’s livestream and had not yet received independent event-day verification.

Why the response mattered

The episode exposed two different risks. The first was custody risk: a transaction presented to multisignature signers could be manipulated even when assets were described as being held in cold storage. The second was liquidity risk: an exchange could remain solvent in an accounting sense yet still struggle if many customers demanded particular tokens at once.

Bybit’s bridge financing demonstrated how centralized venues could draw on counterparties during a crisis. It also meant that uninterrupted withdrawals depended partly on private credit and industry relationships, not solely on assets immediately available in the compromised wallet structure.

Safe said during February 22 that it had temporarily paused Safe Wallet functionality while investigating and initially reported no compromise of its codebase or malicious dependencies. The cause therefore remained unsettled on the event date. Claims assigning a definitive technical cause or state sponsor would have exceeded the contemporaneous record.

Later verification

On February 24, Bybit published the results of a Hacken proof-of-reserves review conducted on February 23. The review covered 40 asset types and reported sufficient reserves for the tested customer liabilities after Bybit replenished its ether holdings. That later review supports the recovery account, but it does not independently verify every February 22 withdrawal or establish that proof of reserves was equivalent to a full financial audit.

Primary sourceBybit Security Incident: Timeline of Events and FAQs

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.