Incident Recap: The Largest Theft in Crypto History On February 21, 2025, at 02:16 UTC, Bybit’s Ethereum cold wallet was breached. Approximately 401,346 ETH, 15,000 cmETH, 8,000 mETH, and 90,375 stETH were transferred to unknown addresses, totaling roughly $1.46 billion.
The attack leveraged a sophisticated phishing scheme. Investigations by the FBI and multiple on-chain analytics firms pointed to the TraderTraitor cluster of the North Korean Lazarus Group. The attackers:
  • Compromised the Safe{Wallet} interface via supply chain manipulation.
  • Targeted Bybit’s multi-signature wallet approvers, replacing the original wallet contract with a malicious contract.
  • Obtained three critical signatures. When multi-sig members approved what appeared as “small, normal transfers,” the system actually authorized massive fund movements.
Within minutes, the stolen assets were dispersed across thousands of addresses. ETH’s spot price plummeted nearly 8%, while Bybit faced 350,000 urgent withdrawal requests.
This was not Lazarus Group’s first use of such a blueprint:
  • 2022 – Ronin Bridge: Social engineering tricked validators into leaking private keys, resulting in a $625 million theft.
  • 2023 – CoinsPaid, Alphapo, Atomic Wallet attacks: Malicious updates and fake recruitment lures.
  • 2024 – WazirX & DMM Bitcoin: Multi-sig interface spoofing + employee phishing; losses of $235M and $308M, respectively.
  • 2025 – Bybit: Same methodology, scaled to a staggering $1.5B.
FBI data indicates that since 2017, Lazarus has stolen over $6 billion from crypto. Their tactic is never brute force—it’s psychology and trust manipulation. Even offline cold wallets are vulnerable if human oversight and control are concentrated.

Systemic Risks of Self-Custody Exposed

Bybit’s breach shone a harsh spotlight on the three most critical weaknesses of self-custody:
  • Humans are the weakest link: Social engineering + supply chain attacks can bypass any offline signature.
  • Fake multi-sig interfaces: Approvers can be shown falsified transaction data while the chain executes something entirely different.
  • No external safety net: Any mistake leads to 100% loss, with no insurance, recourse, or rollback.
The breach exploited human and operational process vulnerabilities, not blockchain technology itself. If top exchanges can fall, how resilient is the average self-custody wallet against state-level adversaries?

From “Hope for No Mistakes” to “Survive Even if You Slip Up”

This incident forces the industry toward pragmatic security. Exchanges, institutional investors, and high-net-worth individuals are learning to:
  • Avoid relying solely on “full control of private keys”.
  • Split and distribute core assets to mitigate single-point-of-failure risks.
  • Conduct audits and operational verification, not just signature validation.

Practical Solutions: The Role of Qualified Custody (QC) and MPC

Cold wallets once considered the gold standard are now being questioned. With the rise of professional custody solutions, the most effective systemic approach today combines qualified custody with MPC wallets.

Qualified Custody (QC)

  • Separation of control – Assets are managed by independent custodians; exchanges cannot directly access funds. Internal breaches alone cannot move assets.
  • Immutable or controlled upgrade contracts – Custodial wallets cannot be arbitrarily upgraded; any upgrade requires multi-party independent approval, blocking malicious contract replacements.
  • Multi-layered approvals & monitoring – Strict approval hierarchies, anomaly detection, and transaction freeze mechanisms prevent large or suspicious transfers.
  • Legal & regulatory protection – Custodial assets are legally segregated, reducing counterparty risk and increasing investor confidence.

MPC Wallets

  • Eliminate single points of failure – Keys are stored as distributed fragments; no single party can transfer funds alone. Addresses the core weakness of multi-sig wallets.
  • Support policy engines – Whitelisting, withdrawal delays, and limit enforcement.
  • Proven adoption – Widely used by Fireblocks, Coinbase Custody, Binance Institutional Services, and other leading platforms.
This approach does not abandon self-custody entirely. Instead, it adds a layer of “fail-safe insurance” for assets that absolutely cannot afford to be lost.

Industry Warning

Bybit’s $1.5B loss serves as a stark lesson: true security isn’t about clenching your keys tightly—it’s about distributing risk and building redundancy.
When state-level attackers automate social engineering + supply chain attacks, our defense cannot rely on being “smarter”—we must be harder targets with resilient systems.
In crypto, security is the most crucial element .

Leave a Reply

Copyright © 2026 GDC – Global Digital Custody. All Rights Reserved

WhatsApp Telegram

Discover more from GDC - Global Digital Custody

Subscribe now to keep reading and get access to the full archive.

Continue reading