Bybit’s February 2025 loss of roughly $1.4 billion was tied to a compromise in the transaction-signing flow rather than a simple wallet drain. Cyfrin’s analysis says the attackers used a malicious DELEGATECALL in a Safe multisig transaction to rewrite proxy logic, while signers approved the transfer after relying on what they saw on their computers instead of verifying the calldata on hardware wallets. The broader incident involved a 3-of-6 multisig setup, meaning three separate approvals were enough to authorize the malicious transaction once the signers were deceived. The key context is that later reporting changed the attribution of the initial compromise: Safe said a developer machine at Safe was breached and malicious JavaScript was injected into the Safe UI, altering what Bybit signers saw during approval. That matters because it reframes the hack as a supply-chain and signer-verification failure affecting a third-party wallet infrastructure layer, not just an exchange operational mistake. The theft also remains important because it was the largest crypto exchange hack on record, and investigators including ZachXBT linked it to North Korean state-sponsored actors; Bybit later said most of the stolen funds remained traceable, while a significant portion had already moved through mixers and bridges.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on update

Comments