Bybit
Incident posture
Timeline
Summary
In a massive cryptocurrency heist, North Korean threat actors stole approximately $1.5 billion in Ethereum from the cryptocurrency exchange Bybit through a sophisticated supply-chain compromise of a third-party developer. The attackers exploited this trusted relationship to gain access to the exchange's systems, then executed a masterfully complex series of native swaps and cross-chain transactions to hinder the digital trail and obscure the stolen funds. The theft was attributed to the Lazarus threat group and represented one of the largest cryptocurrency compromises on record, contributing to North Korean groups' record-breaking year of digital asset theft. Following the breach, the perpetrators employed advanced laundering techniques, breaking down the funds into smaller amounts and routing them through multiple liquidity services and money laundering networks rather than centralized exchanges, making tracking and disruption significantly more difficult.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In early February 2025, North Korean state-sponsored cybercriminals executed one of the largest cryptocurrency thefts on record, stealing approximately $1.5 billion worth of Ethereum from the exchange Bybit. The attack signaled a strategic shift by North Korean hacking groups toward patient targeting of high-value platforms, leveraging sophisticated methods and precise timing. The theft marked the beginning of a record-breaking year for North Korean cryptocurrency theft, with the country's cybercriminal groups ultimately accounting for the majority of the $3.4 billion in stolen digital assets tracked by blockchain-analysis firm Chainalysis in 2025. North Korean groups stole at least $2.02 billion in cryptocurrency during the year, bringing their total take over the past four years to at least $6.75 billion. The Bybit operation was attributed to the North Korean threat group Lazarus, which has been linked to numerous significant cryptocurrency compromises, ongoing infiltrations of companies through fake tech-worker personas, and the use of AI tools and large language models to enhance social engineering campaigns. The top three cryptocurrency compromises of 2025 accounted for 69% of all losses tracked by Chainalysis, with North Korea-linked actors responsible for 76% of all service compromises.
The Bybit attack demonstrated a high degree of operational sophistication, beginning with the compromise of a third-party supply-chain developer used in the operation. According to Peter Kálnai, a senior malware researcher at cybersecurity firm ESET, the attackers then utilized a masterfully complex series of native swaps and cross-chain transactions to hinder the digital trail of the stolen funds. The laundering approach reflected an evolution in North Korean tactics, as the groups moved away from centralized exchanges—previously a primary avenue for money laundering—toward liquidity services based in Southeast Asia and broader Chinese money laundering network operators. Chainalysis's head of national security intelligence, Andrew Fierman, noted that the groups break down funds exceptionally quickly and launder smaller sums through many different avenues rather than moving large chunks of money through singular places, making it harder for law enforcement and the financial community to disrupt and trace the transactions. The persistence, frequent innovation, and significant success with large compromises identified by ESET as defining characteristics of North Korean cyber operations were clearly demonstrated in the Bybit operation.
Sources
Sources available to members: 1 source.