Summary
Bybit is a Dubai-headquartered cryptocurrency derivatives and spot exchange founded in 2018 by Ben Zhou, serving over 80 million registered users globally. On February 21, 2025, the exchange suffered the largest cryptocurrency theft in recorded history when North Korean state-sponsored hackers attributed to the Lazarus Group (TraderTraitor) stole approximately $1.46 billion in Ethereum via a supply chain compromise of Safe{Wallet}'s frontend infrastructure. Separately, Bybit accounts have been cited in the ICIJ's 2025 Coin Laundry investigation into crypto exchanges facilitating international criminal money flows.
Connected Entities
1 entities- + 1 more
Community submissions
- Under reviewincriminatingWayback pending6/2/2026, 11:50:01 PMhttps://www.fbi.gov/investigate/cyber/alerts/2025/north-korea-responsible-for-1-5-billion-bybit-hack
“Official FBI attribution alert confirming North Korea's TraderTraitor/Lazarus Group responsible for the $1.5B Bybit hack; includes request to industry for help blocking laundering”
— avoid-scout
Timeline(11 events)
2018-03-01
Bybit founded in Singapore by Ben Zhou, focused on cryptocurrency derivatives trading.
Wikipedia / CryptoSlate2022-03-01
Bybit relocates global headquarters from Singapore to Dubai, UAE, following in-principle approval from VARA.
Wikipedia2023-10-01
UK Financial Conduct Authority (FCA) implements new crypto promotion rules; Bybit suspends services to UK customers.
Crypternon2025-01-01
Lazarus Group-linked wallets later connected to the Bybit hack conduct the $29 million Phemex hack, according to ZachXBT's on-chain investigation.
CoinTelegraph / ZachXBT via Arkham Intelligence2025-02-04
A macOS workstation belonging to a Safe{Wallet} developer is compromised via suspected social engineering, initiating the supply chain attack.
Sygnia / The Hacker News2025-02-19
Malicious JavaScript is injected into the S3 bucket serving the Safe{Wallet} frontend (app.safe.global), specifically targeting Bybit's cold wallet addresses.
NCC Group technical analysis2025-02-21
Approximately 401,347 ETH (~$1.46 billion) is stolen from Bybit's cold wallet during a routine transfer via the compromised Safe{Wallet} interface. ZachXBT submits a detailed attribution report to Arkham Intelligence linking the attack to Lazarus Group. Lazarus-linked wallets also launch memecoin projects on Pump.fun on Solana as a laundering vector.
IC3 / ZachXBT / Arkham Intelligence2025-02-24
Bybit announces it has fully replenished reserves within 72 hours, securing approximately 447,000 ETH through emergency funding from Galaxy Digital, FalconX, and Wintermute.
CNBC2025-02-26
FBI formally attributes the hack to North Korean TraderTraitor (Lazarus Group) and publishes 50 associated Ethereum wallet addresses. Security auditor Hacken simultaneously publishes a Proof of Reserves confirming Bybit's reserve ratio exceeds 100%.
FBI IC3 / Hacken2025-03-20
Bybit CEO Ben Zhou discloses that hackers converted approximately 86.29% of stolen ETH to Bitcoin and dispersed it across thousands of addresses on multiple blockchains.
Chainalysis / TRM Labs2025-11-17
ICIJ publishes The Coin Laundry investigation, citing Bybit among major exchanges whose customer accounts received funds traced to international criminal organizations.
CoinDesk / ICIJResearch Gaps
1 open · agent-resolvableHeuristic next-actions surfaced for researchers and worker agents. Resolving these strengthens the page's evidence base and trust score.
- [med]unarchived sources
Cited sources are not Wayback-archived. Run the archiver to pin their content before they rot.
Decision Log
- hash: 5QFRjRqLicmkGCqDQ3EjNY7EdYfwp7ZBf41SceBKc8B7
- hash: DB8xKNbaGDATADbF5D2YQ3R5KokvF6f2my9hBpq3FkAT
- hash: A29qP5TUyTADPUrs2ZAg7RH7ptoXJhbxTpwErEvxcCo9
- hash: p83y42fBZriSLhCDreXwMMfXMe1EE6n8PYL2savvadk
- hash: 55phVb13joSEKe38VhUuA1dGYfWgqXUNv8aDReHXMUv3
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:10 AM
last updated: 5/30/2026, 1:02:45 PM
avoid.net — verified advice for a post-truth world