Skip to content

2025-02-21 (incident) · Location not reported · Bybit

Bybit loses about $1.5 billion to North Korea's TraderTraitor, 2025

Disclosed by the affected organisation.

On or about 21 February 2025, attackers took about $1.5 billion in virtual assets from the cryptocurrency exchange Bybit, and the FBI attributed the theft to North Korea, calling the activity TraderTraitor. Safe, whose multisignature wallet interface Bybit's signers used, said in a statement quoted by BleepingComputer that the attack came through a compromised Safe{Wallet} developer machine, and researchers found malicious JavaScript injected into app.safe.global that disguised the transaction the signers approved. Crypto.news, citing Safe's investigation with Mandiant, reported the developer's Mac was infected on 4 February by a Docker project posing as a stock investment simulator, after which the attackers used stolen AWS session tokens to get past MFA.

$1.5B (stolen; Approximate value of the virtual assets taken, as stated by the FBI.)

Timeline

  1. 2025-02-04 A Safe{Wallet} developer's Mac is compromised by a Docker project posing as a stock investment simulator, according to Safe's investigation as reported by crypto.news.
  2. 2025-02-21 About $1.5 billion in ETH and staked ETH is moved from Bybit to an attacker-controlled address during a routine cold wallet transfer.
  3. 2025-02-26 The FBI attributes the theft to North Korea's TraderTraitor activity and asks exchanges, bridges and other services to block the Ethereum addresses it listed.

Lessons

Scam types: Developer-targeted lures (fake job tests and malicious packages)

Sources

  1. FBI IC3 PSA: North Korea responsible for $1.5 billion Bybit hack (Law enforcement, primary, accessed 2026-09-24)
  2. BleepingComputer: Lazarus hacked Bybit via breached Safe{Wallet} developer machine (News report, secondary, accessed 2026-09-24)
  3. crypto.news: Bybit's $1.4b breach started with stock invest malware, investigation reveals (News report, secondary, accessed 2026-09-24)