The Federal Bureau of Investigation attributed the approximately $1.5 billion theft from cryptocurrency exchange Bybit to North Korea on February 26, 2025, turning an already exceptional custody failure into an active state-linked cybercrime and sanctions concern for the digital-asset industry.
In a public-service announcement, the FBI identified the operation as TraderTraitor, its name for specific North Korean malicious cyber activity. The bureau said the theft occurred on or about February 21, 2025, and that the perpetrators had already converted some of the stolen assets into bitcoin and other virtual assets distributed across thousands of addresses and multiple blockchains.
That assessment was an official U.S. government attribution, not a judicial finding. The FBI described the stolen value as approximately $1.5 billion, so the figure should be understood as the agency’s event-period estimate rather than a fixed dollar loss independent of cryptocurrency prices.
From a wallet breach to a laundering response
Bybit had previously said an attacker manipulated a routine transfer from an Ethereum cold wallet to a warm wallet. The compromise did not depend on breaking Ethereum’s consensus rules. Instead, the surviving forensic record indicated that malicious code altered what human signers were shown while changing the underlying transaction they authorized.
A Sygnia interim investigation dated February 25, 2025, reported finding malicious JavaScript in a resource served through Safe{Wallet} infrastructure. According to that commissioned review, the code was designed to modify transaction contents during signing and was activated only when the transaction originated from one of two specified contract addresses. The report said replacement resources without the malicious code appeared approximately two minutes after the unauthorized transaction was published.
Sygnia found no indication at that stage that Bybit’s own infrastructure had been compromised, but explicitly described its investigation as ongoing. That distinction matters: an interim root-cause assessment can identify the apparent delivery mechanism without resolving every question about credential theft, access controls, organizational responsibility or the attacker’s complete preparation.
The FBI asked the industry to intervene
The February 26 announcement was operational as well as declarative. The FBI urged node operators, centralized exchanges, cross-chain bridges, blockchain-analytics companies, decentralized-finance services and other virtual-asset providers to block transactions involving or derived from addresses used to launder the stolen property. It also published a list of Ethereum addresses it said held or had held proceeds connected to TraderTraitor.
Bybit separately said on February 26 that forensic work by Sygnia and Verichains pointed to compromised credentials belonging to a Safe developer, which allegedly allowed unauthorized access to Safe infrastructure and deceived Bybit’s signers. That was Bybit’s account of preliminary findings, supported by investigators it retained; it was not an independent regulatory determination.
The response illustrated a central tension in public blockchains. Investigators can trace funds and distribute indicators quickly, but stopping transfers depends on intermediaries recognizing those indicators and controlling the relevant chokepoints. A blockchain address list is therefore a compliance and investigative tool, not proof that every listed asset can be frozen or recovered.
Why the attribution mattered
By February 26, 2025, the incident was no longer only a question of whether one exchange could absorb a large balance-sheet loss. The FBI’s attribution connected the theft to a state-linked campaign and warned that rapid conversion across assets, chains and services was already underway. That raised immediate exposure for exchanges, bridges and liquidity providers receiving contaminated funds.
The record does not establish that the breach caused any particular same-day move in bitcoin, ether or the broader market. Crypto trades continuously across venues, and isolating the price effect of one security event would require venue-specific data, a defined UTC window and controls for concurrent macroeconomic news. No such causal calculation is asserted here.
What was verifiable on February 26 was narrower and consequential: the FBI had attributed the Bybit theft to North Korea, published laundering indicators and asked the digital-asset industry to help obstruct the movement of approximately $1.5 billion in stolen virtual assets.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

