Crypto Exchange Wallet Security and the Bybit Multisig Heist
Summary
The article describes a reported theft of a large amount of ETH from Bybit in February 2025. It says attackers manipulated a third-party wallet provider’s multisignature process so that transaction details shown in the interface appeared legitimate while the underlying smart contract logic had been altered. It attributes the attack to the Lazarus Group and outlines alleged laundering through decentralized exchanges, cross-chain bridges, and peer-to-peer platforms. Bybit’s stated response was to cover any unrecovered assets from its treasury.
The security lessons focus on validating the transaction itself rather than trusting a display, simulating transactions before signing, and adding off-chain checks. The incident illustrates that offline storage does not eliminate risks in connected approval systems. The article provides a narrative account and recommendations, but no technical forensic evidence, independent verification, or detailed implementation guidance. Its claims about attribution, fund recovery, and the exchange’s response should therefore be treated as reported statements rather than a complete security analysis.
Key ideas
- Multisignature approval can be undermined if the signed transaction differs from what the interface displays.
- Cold storage does not protect assets from flaws in transaction preparation and approval workflows.
- Pre-signing simulation and validation of raw transaction data can help reveal suspicious changes.
- The article reports laundering through decentralized exchanges, bridges, and peer-to-peer transactions, but does not provide forensic detail.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.