On February 21, 2025, attackers drained 401,347 ETH ($1.46 billion) from a Bybit cold wallet by injecting malicious JavaScript into the Safe{Wallet} UI through a compromised AWS S3 bucket. Bybit's 3-of-6 multisig signers approved a transaction that looked routine; the manipulated UI hid that the destination had been swapped and the contract logic modified. Per Arkham Intelligence, it is the single largest financial heist in history — bigger than the $1B Central Bank of Iraq theft of 2003.
Within hours, ZachXBT publicly attributed the attack to North Korea's Lazarus Group using on-chain similarities to the Phemex hack. Within 24 hours, Mantle's mETH Protocol froze 15,000 cmETH (~$43M) using their built-in 8-hour withdrawal delay; Tether froze 181K USDT; coordinated industry action recovered $42.89M total in the first day. As of April 2025, per CEO Ben Zhou: 68.57% of funds remain traceable, 27.95% have gone dark, 3.84% are frozen.
This article is the forensic walkthrough — the attack, the attribution, the laundering pipeline, the recovery operation, and what working investigators take away from the case.
In This Article
- Why this case is the new gold standard
- By the numbers
- The attack: a Safe UI supply-chain compromise
- The first hour: ZachXBT attributes Lazarus
- The laundering map: where the money went
- The recovery operation: $42M in 24 hours
- Where the funds are now
- What forensic investigators take from this case
- What this means for victims of similar hacks
- Frequently asked questions
Why This Case Is the New Gold Standard
If you only study one crypto hack as an investigator, make it this one. Not because it's the biggest (though it is), but because it's the cleanest example of the modern forensic playbook running in real time at maximum stakes.
Within hours of the theft, an independent investigator on Twitter (ZachXBT) had attributed the attack to a state-sponsored hacking group by spotting on-chain laundering patterns identical to a prior incident. Within 24 hours, a coordinated industry response had frozen $42.89 million across multiple platforms. Within 72 hours, Bybit had publicly mapped the multisig compromise down to the specific JavaScript injection. Within weeks, Chainalysis had reconstructed a 45-day, multi-wave laundering model that the entire industry now uses as a reference for DPRK operations.
Five years ago, none of that response speed existed. Bybit is the first $1B+ crypto theft where the forensic response actually kept pace with the attacker. That alone makes it the new high-water mark.
I work pig-butchering and exchange-fraud cases for clients. The Bybit response is the picture I hold in my head of what's possible when an exchange of $20B+ scale, the issuer of the underlying stablecoin, multiple security firms, and the broader industry all coordinate within hours. For a smaller exchange or an individual victim, that level of coordination isn't automatic. But the same playbook applies, just at smaller scale.
By the Numbers
- Date: February 21, 2025
- Total theft: 401,347 ETH ($1.46 billion at the time of the attack), plus 90,300 stETH, 15,000 cmETH, and 8,000 mETH
- Attack vector: Safe{Wallet} UI compromise via a hijacked AWS S3 bucket serving Safe's front-end JavaScript
- Multisig configuration bypassed: Bybit ran a 3-of-6 multisig; all three required signatures were obtained because the manipulated UI showed a legitimate-looking transaction
- Attribution: Lazarus Group (DPRK) — confirmed publicly within hours by ZachXBT
- Primary attacker wallet:
0x47666Fab8bd0Ac7003bce3f5C3585383F09486E2(tagged "Bybit Exploiter 1" on Etherscan) - Laundering window: ~45 days for the bulk of the funds (Chainalysis 4-wave model)
- Recovered or frozen in first 24 hours: $42.89 million across all coordinated actions
- mETH Protocol freeze: 15,000 cmETH (~$43M) via Mantle's 8-hour withdrawal delay
- Tether freeze: 181,000 USDT (Paolo Ardoino confirmed)
- Bybit's bounty pool: 10% of recovered funds (originally pitched at ~$140M total)
- Status as of April 2025 (Ben Zhou): 68.57% traceable, 27.95% gone dark, 3.84% frozen
The Attack: A Safe UI Supply-Chain Compromise
The thing that makes this hack technically interesting — and the thing every other exchange has had to internalize since — is that no smart contract was exploited. The Bybit cold-wallet contract behaved exactly as designed. The multisig logic was sound. The signers' hardware wallets weren't compromised. The keys weren't leaked.
The attack was on the interface the signers used to approve the transaction.
What actually happened
Per the postmortems by NCC Group, Sygnia, and BleepingComputer, here's the chain of events:
- Lazarus compromised a Safe{Wallet} developer's environment. Specifically, an AWS S3 bucket used to serve the Safe front-end JavaScript. The compromised developer machine gave the attackers write access to the production JS bundle.
- They injected malicious JavaScript that targeted only Bybit. The injected code checked which wallet was being used. For every Safe user in the world except Bybit's specific cold-wallet address, the UI behaved identically to before. For Bybit, it didn't.
- Bybit's signers initiated a routine cold-wallet movement. Three of the six required signers reviewed and approved what the UI showed them: a transfer to a known, trusted destination.
- The actual transaction was different. The injected JavaScript replaced the destination with an attacker-controlled address and modified the contract-call data to overwrite the Gnosis Safe proxy's storage slot 0x00 (which holds the
masterCopyaddress). - The proxy now pointed to the attacker's contract. Once the transaction was signed and broadcast, every future call through the Safe proxy executed code from the attacker's backdoor contract instead of the legitimate Safe implementation.
- The drain. The attacker's contract immediately transferred all ETH and staked-ETH variants to
0x47666Fab...86E2. The cold wallet was empty within a single block.
Why this attack class is so dangerous
Multisig cold-wallet security is built around the assumption that each signer independently verifies what they're signing. The model breaks if all signers see the same lying interface. Hardware wallets help — they show a destination on the device's own screen — but most institutional signing flows still have humans glancing at the hardware screen rather than rigorously cross-checking the destination address character-by-character against an independently-derived source.
The Bybit attack didn't break cryptography. It broke the human in the loop, and it did so by attacking infrastructure two companies upstream from Bybit. That's a supply-chain attack hitting a different company's UI, propagated through a third company's hosting service, to drain a fourth company's cold wallet. Defending against that requires changes to how the entire stack works, not just Bybit's procedures.
Safe has since hardened its build pipeline, removed direct AWS S3 dependencies for production JS, and added monitoring for transaction-data divergence between UI and on-chain state. Most major exchanges have added separate hardware-wallet verification for cold-wallet movements that doesn't rely on the multisig UI. The fix is real, but the attack class — supply-chain compromise of front-end JavaScript — remains live for any platform that signs transactions through a web UI without independent verification.
The First Hour: ZachXBT Attributes Lazarus
The remarkable thing about the Bybit response isn't that the funds were eventually traced. It's that the attribution to Lazarus happened within hours of the theft, on a public timeline, by a single independent investigator working from Twitter.
ZachXBT spent the day after the hack mapping the laundering movements and flagging theft addresses on his own. By the end of February 22, he had publicly published a list of 920+ addresses connected to the hack:
I spent the entire day graphing out the laundering movements and flagged theft addresses.
— ZachXBT (@zachxbt) February 22, 2025
I am making 920+ addresses connected to the Bybit hack publicly available here:
The attribution itself rested on a specific on-chain pattern: the Bybit attacker's wallets exhibited the same laundering signatures — same DEXs in the same sequence, same bridge usage, same denomination patterns — as the wallets behind the prior Phemex hack, which had before been attributed to Lazarus. That kind of behavioral attribution is exactly what somaxbt and other forensic writers refer to as a "digital signature": the operator may rotate addresses, but the operational habits don't change.
ALERT: BYBIT HACKER TRANSFERRING ETH
— Arkham (@arkham) February 22, 2025
The Bybit Hacker has begun to move portions of the hacked funds from Bybit again, moving $7M ETH in the past hour alone.
These on-chain movements appear to clearly link the Bybit Hacker to the Phemex Hack, which was conducted by the Lazarus...
Arkham Intelligence had a public bounty out for definitive Lazarus attribution. ZachXBT submitted the proof. Arkham awarded the bounty. The U.S. FBI later confirmed Lazarus attribution in their own statement, citing the same pattern.
Three things to note about how this happened:
- The investigator was independent. No badge, no firm, no contractual obligation. ZachXBT works publicly on Twitter and has built a reputation for accurate attribution over years. That an independent investigator could call Lazarus before the FBI did says something real about the maturation of public on-chain forensics.
- The attribution was based on operational patterns, not identity disclosure. Nothing in the on-chain data revealed any DPRK operator's name, location, or device. It revealed that the laundering pattern matched a prior incident already attributed to Lazarus — transitive trust in the previous attribution chain. That's actually how most blockchain attribution works: you don't identify who, you identify that this is the same who as before.
- Speed mattered enormously. Public attribution within hours meant that exchanges, stablecoin issuers, and security firms could orient their freeze and KYC alerts within the first 24-hour window when the funds were still consolidating. Late attribution is dramatically less useful.
Arkham's later confirmation (Feb 24) framed the scale of what had happened:
THE BYBIT HACK WAS THE LARGEST FINANCIAL HEIST IN HISTORY
— Arkham (@arkham) February 24, 2025
Bybit sustained losses of $1.4 Billion at the time of the hack, 21st Feb 2025. The closest competitor is the theft from the Central Bank of Iraq, which lost $1 Billion on 18th March 2003.
The Laundering Map: Where the Money Went
Per Chainalysis, the post-theft laundering followed a four-wave structure spanning roughly 45 days. This is now the canonical model for DPRK-attributed laundering and is worth understanding in detail because the same pattern shows up in later Lazarus operations.
Wave 1: Immediate layering (days 0-5)
Within hours of the drain, the attacker fragmented the 401,347 ETH from the primary wallet into 40 separate transactions of ~10,000 ETH each, distributed across dozens of secondary wallets. The fragmentation served two purposes: it broke the visual coherence of the original theft amount, and it spread the funds across enough addresses that no single freeze action could capture the whole haul.
During this same window, staked-ETH variants (stETH, cmETH, mETH) were swapped to liquid ETH through DEXs that don't require KYC: ParaSwap and BreederDodo were the two named DEX aggregators in the Chainalysis analysis. This step illustrates a core Lazarus pattern: swap illiquid assets for liquid ones early, before scrutiny crystallizes around specific addresses.
Wave 2: Cross-chain bridging (days 5-15)
Once the funds were consolidated into liquid ETH at multiple addresses, the next step was to break the chain-level trace by bridging to Bitcoin. The two named services were:
- Thorchain — a cross-chain decentralized exchange that allows direct ETH-to-BTC swaps without wrapping or KYC
- eXch — an instant-exchange service known for minimal KYC and willingness to accept high-value swaps
Bridging breaks the chain-of-custody at a chain boundary unless the investigator manually correlates the outgoing ETH transaction with the incoming BTC transaction by matching amounts, timing, and bridge-transaction identifiers. Done well, the trace continues smoothly. Done poorly, the chain boundary is where investigators stop.
Wave 3: Bitcoin mixing (days 15-30)
Once the funds reached Bitcoin, Lazarus deployed mixing services to break the post-bridge trace. The two named Bitcoin-side mixers were:
- Cryptomixer — a centralized BTC mixer
- Wasabi Wallet — a CoinJoin-based privacy wallet
This is the wave where genuine forensic uncertainty enters the picture. Mixing services pool inputs from multiple users into combined transactions; demixing post-Wasabi withdrawals is probabilistic, not deterministic. Even high-quality demixing analysis produces a most-likely attribution rather than a certainty.
Wave 4: Off-ramp via P2P and OTC (days 30-45+)
The final wave was the conversion of mixed BTC into fiat or stablecoins through:
- Peer-to-peer trading platforms with weak KYC
- OTC desks in jurisdictions without strong AML cooperation
- Non-cooperative or sanctioned exchanges
This is the wave where most of the "untraceable" 27.95% Ben Zhou cited eventually disappears. Once funds reach a non-cooperative endpoint, the trace ends not because the on-chain record stops, but because there's no legal mechanism to compel disclosure of the off-chain identity behind the receiving wallet.
The bigger pattern
Lazarus's strategy has matured into a deliberate four-phase model: fragment, swap, bridge, mix, off-ramp. They let some funds sit dormant for weeks to let scrutiny die down. They never use a single laundering technique in isolation. And they specifically target services with the weakest KYC posture and the lowest cooperation history.
Every working forensic investigator should be able to recognize this pattern on sight. It shows up in the Phemex hack, the Ronin Bridge hack, the WazirX hack, and now Bybit. When the same operator runs the same playbook, attribution becomes radically faster — which is exactly how ZachXBT made the call within hours.
The Recovery Operation: $42M in 24 Hours
What happened in the first 24 hours after the hack is the single best demonstration of what coordinated industry response can accomplish.
mETH Protocol's $43M cmETH save
Mantle's mETH Protocol — the team behind cmETH (a yield-bearing ETH derivative) — recovered 15,000 cmETH worth approximately $43 million using a structural feature most users had never noticed: an 8-hour withdrawal delay built into the protocol. Once the team detected that an attacker-controlled address was attempting to redeem cmETH for the underlying ETH, they had eight hours to act before the withdrawal would settle.
The save was initiated by Mudit Gupta, Polygon's CISO, who flagged the redemption attempt and pulled in SEAL (Security Alliance), the rapid-response security collective. The mETH/Mantle team executed the freeze, with Veda — cmETH's infrastructure partner — standing by 24/7 to push the protocol-level changes. The whole save was completed in under 24 hours.
This is one of the cleanest examples of protocol-level defense as a structural advantage. The 8-hour delay wasn't designed for hack response; it was designed as a withdrawal-throttling mechanism for normal operations. But it gave the response team enough runway to identify, coordinate, and act. Every protocol design team should be looking at this case and asking what equivalent structural defenses they have.
Tether's USDT freeze
Tether CEO Paolo Ardoino confirmed the issuer had frozen 181,000 USDT linked to addresses in the laundering network within the first 24-48 hours. By Tether's standards this is small — they routinely freeze tens of millions in single seizure actions — but the speed mattered. The freeze blocked further movement of those specific tokens and created a recoverable pool of funds for eventual victim restitution.
Tether has, in the years since, dramatically expanded its freeze cooperation with U.S. and international law enforcement. This particular freeze was small relative to the $1.46B haul, but it set a precedent: stablecoin issuers will act in real time on attribution from public investigators, not just on formal law-enforcement requests.
Coordinated industry freeze: $42.89M
Bybit ran a coordinated outreach to every major exchange, security firm, and stablecoin issuer in the immediate aftermath. The cumulative result, according to Bybit's own published numbers, was approximately $42.89 million in frozen funds within the first 24 hours. The freezes spanned multiple chains, multiple exchanges, and multiple asset types.
This is the kind of coordination only possible at $20B-of-customer-funds scale. A smaller exchange hit by a similar attack wouldn't have the same response use; their reputation, their legal team, and their connections all matter to how seriously other platforms treat the freeze request.
The deficit close
Three days after the hack, Bybit had recovered approximately $1.23 billion in ETH — not from the attacker, but through a combination of borrowing, buying, and partner contributions. The exchange covered the deficit and restored 1:1 customer-asset backing. This is what allowed Ben Zhou to make his early statement that all customer assets remained 1:1 backed and the exchange was solvent. The hack was real and the loss was real, but the customer-facing experience was a temporary system pause rather than a multi-year clawback.
Bybit also launched a 10% bounty program — ~$140 million pool — for any entity that successfully recovered or helped freeze of stolen funds. The bounty has since paid out to multiple parties.
Where the Funds Are Now
Per Ben Zhou's April 2025 update, two months after the hack:
| Status | Approximate share | Where it went |
|---|---|---|
| Traceable | 68.57% | Mapped on-chain, pending further freeze or recovery action |
| Untraceable | 27.95% | Mixed through Cryptomixer / Wasabi, off-ramped via P2P / OTC / non-cooperative exchanges |
| Frozen | 3.84% | mETH cmETH freeze, Tether USDT freeze, exchange-side freezes, OFAC-sanctioned addresses |
The honest read on those numbers: roughly $400 million is gone, in the sense that it has reached endpoints from which legal recovery isn't practical. The $1 billion that remains traceable is still on-chain — it can be watched, flagged, and frozen if it ever moves to a cooperative venue — but moving from "traceable" to "recovered" requires either the operator making a mistake or a jurisdictional cooperation breakthrough.
This breakdown is itself useful for setting client expectations on smaller exchange hacks and pig butchering cases. "Most of the funds went dark" is rarely accurate. "A meaningful minority went dark; most remains visible but not recoverable" is closer to the modal outcome.
The Greece seizure
In mid-2025, Greek authorities executed the country's first-ever criminal crypto seizure — funds traceable to the Bybit hack — using Chainalysis's tracing data and cooperation with U.S. counterparts. The amount was modest by hack-scale standards but established a meaningful precedent: jurisdictions before without active crypto enforcement infrastructure are now executing seizures based on public-private forensic cooperation. That trend is what eventually moves "traceable" into "recovered" over multi-year timelines.
What Forensic Investigators Take From This Case
If I had to compress the working lessons for a forensic investigator into five points, these would be them.
1. The trace can outpace the operator
For years the assumption was that sophisticated operators would always be a step ahead of investigators — bridges, mixers, and cross-chain hops broke the trail faster than humans could rebuild it. Bybit shows that's no longer true. ZachXBT's team mapped 920+ addresses within a day. The Chainalysis 4-wave model was published within weeks. The trace not only kept up; it documented the entire 45-day laundering operation in real time.
2. Attribution is now behavioral, not just transactional
The Lazarus attribution didn't come from any specific transaction. It came from recognizing that the laundering pattern was the same as the Phemex pattern. Operational habits leak. When the same operator runs the same playbook across multiple incidents, attribution gets faster every time. This is why every working investigator should be cataloging operator patterns, not just specific addresses.
3. Coordinated industry response is the real recovery vehicle
The $42.89M frozen in 24 hours wasn't the product of any single legal mechanism. It was the product of ZachXBT publishing addresses publicly, exchanges flagging those addresses against deposit screening, Tether acting on attribution from a non-government source, and Mantle deploying a structural defense that hadn't been designed for this exact scenario. Modern recovery is a network effect, not a courtroom outcome. The forensic report you produce as an investigator is the input that activates the network.
4. Structural defenses beat reactive ones
Mantle's 8-hour withdrawal delay saved $43M because it existed before anyone knew it was needed. Tether's freeze capability saved another chunk because the infrastructure was already in place. Bybit's $20B war chest let them cover the deficit before customers panicked. The defenses that mattered most were ones built well before the hack. When advising exchange clients or protocol teams, push for structural defenses (delays, multi-layer verification, freeze capability, reserves) rather than detection-only tooling.
5. Supply chain compromises are now in scope
The Bybit attack didn't compromise Bybit's infrastructure. It compromised Safe{Wallet}'s build pipeline two companies upstream. As an investigator working a similar incident, you can no longer assume the attack vector lives at the victim. The trace and attack-vector analysis must include every system the victim trusted, not just the victim's own systems.
What This Means for Victims of Similar Hacks
Most exchange-hack victims aren't Bybit. The case where the entire industry mobilizes within hours is a $1.46B Lazarus theft, not a $50K phishing drain. But the same forensic playbook applies, just at a different scale.
The trace work is identical
Whether the theft is $50K or $1.5B, the first-72-hour forensic actions are the same: identify the destination wallet, build the forward graph, identify the cash-out exchange (if reachable), and produce a forensic report suitable for filing with that exchange and with law enforcement. The breadth of the response varies; the methodology doesn't. We cover the full process in how blockchain forensic investigators trace stolen crypto and the foundational crypto forensic investigation guide.
USDT freezes are the strongest recovery lever
Tether's freeze cooperation has dramatically expanded since the Bybit response. If your case involves USDT — and most pig butchering and exchange-laundering cases do at some point — the strongest single lever you have is a forensic trace identifying scammer-controlled USDT addresses, packaged for either a Tether freeze request or a U.S. law enforcement freeze request that Tether will act on. We discuss this lever in detail in can you get crypto back after being scammed.
Speed matters more than scale
The Bybit case moved fast because the attribution was fast. For your case, the equivalent speed advantage comes from filing the forensic trace within the first 7 days. After that, funds usually reach off-ramp endpoints from which freeze becomes substantially harder. We cover the time-sensitive action checklist in what to do in the first 72 hours after a crypto scam.
Most cases settle without recovery
Even the Bybit response only froze 3.84% of the original haul. For smaller cases without coordinated industry response, the recovery share is often lower. The honest framing for clients is: forensic work produces a documented trace, an identified destination, and the legal basis for asset freeze and civil action. It doesn't produce a guaranteed recovery. Anyone who guarantees recovery is running a recovery scam.
Free Forensic Case Assessment
Hit by an exchange hack, wallet drainer, or pig butchering scam? Tell us what happened. We'll trace the funds, identify where they ended up, and tell you honestly what recovery looks like in your specific case. Initial assessments are free and usually returned within 24 hours.
Start a Free Case ReviewFrequently Asked Questions
0x47666Fab8bd0Ac7003bce3f5C3585383F09486E2. It was funded directly from Bybit Cold Wallet 1 with 401,346.77 ETH. ZachXBT later published a list of 920+ addresses connected to the laundering network.Final Thoughts
The Bybit hack will be in forensic textbooks for the next decade. Not because of the dollar amount, though that's historic. Because of the speed of the response. Because of the cleanness of the attribution. Because of the structural defenses that worked and the ones that didn't. And because of what it taught the industry about supply-chain attacks against multisig UIs.
For a working investigator, the case is a complete worked example of every part of modern forensic practice running at maximum stakes. For an exchange or protocol team, it's a list of structural defenses that should already exist before they're needed. For a victim of a smaller exchange hack, it's a reminder that the same playbook scales down — the response is smaller, the coordination is harder, but the methodology that made $42M in 24 hours possible is the same methodology that recovers funds in a $50K case.
If you've been hit by a similar incident, get in touch. We'll trace the funds, identify where they ended up, and tell you honestly what recovery looks like in your specific case.