CSIDB logo
Incident

Bybit

Incident posture

Attack window
Feb 2025
Location
United Arab Emirates
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 16:27

Linked entities

Victim
Bybit
Threat actors
4 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In a massive cryptocurrency heist, North Korean threat actors stole approximately $1.5 billion in Ethereum from the cryptocurrency exchange Bybit through a sophisticated supply-chain compromise of a third-party developer. The attackers exploited this trusted relationship to gain access to the exchange's systems, then executed a masterfully complex series of native swaps and cross-chain transactions to hinder the digital trail and obscure the stolen funds. The theft was attributed to the Lazarus threat group and represented one of the largest cryptocurrency compromises on record, contributing to North Korean groups' record-breaking year of digital asset theft. Following the breach, the perpetrators employed advanced laundering techniques, breaking down the funds into smaller amounts and routing them through multiple liquidity services and money laundering networks rather than centralized exchanges, making tracking and disruption significantly more difficult.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early February 2025, North Korean state-sponsored cybercriminals executed one of the largest cryptocurrency thefts on record, stealing approximately $1.5 billion worth of Ethereum from the exchange Bybit. The attack signaled a strategic shift by North Korean hacking groups toward patient targeting of high-value platforms, leveraging sophisticated methods and precise timing. The theft marked the beginning of a record-breaking year for North Korean cryptocurrency theft, with the country's cybercriminal groups ultimately accounting for the majority of the $3.4 billion in stolen digital assets tracked by blockchain-analysis firm Chainalysis in 2025. North Korean groups stole at least $2.02 billion in cryptocurrency during the year, bringing their total take over the past four years to at least $6.75 billion. The Bybit operation was attributed to the North Korean threat group Lazarus, which has been linked to numerous significant cryptocurrency compromises, ongoing infiltrations of companies through fake tech-worker personas, and the use of AI tools and large language models to enhance social engineering campaigns. The top three cryptocurrency compromises of 2025 accounted for 69% of all losses tracked by Chainalysis, with North Korea-linked actors responsible for 76% of all service compromises.

The Bybit attack demonstrated a high degree of operational sophistication, beginning with the compromise of a third-party supply-chain developer used in the operation. According to Peter Kálnai, a senior malware researcher at cybersecurity firm ESET, the attackers then utilized a masterfully complex series of native swaps and cross-chain transactions to hinder the digital trail of the stolen funds. The laundering approach reflected an evolution in North Korean tactics, as the groups moved away from centralized exchanges—previously a primary avenue for money laundering—toward liquidity services based in Southeast Asia and broader Chinese money laundering network operators. Chainalysis's head of national security intelligence, Andrew Fierman, noted that the groups break down funds exceptionally quickly and launder smaller sums through many different avenues rather than moving large chunks of money through singular places, making it harder for law enforcement and the financial community to disrupt and trace the transactions. The persistence, frequent innovation, and significant success with large compromises identified by ESET as defining characteristics of North Korean cyber operations were clearly demonstrated in the Bybit operation.

Sources

Sources available to members: 1 source.

CSIDB