The $1.46 Billion Bybit Hack Explained

The cryptocurrency industry has once again been shaken by a massive cyberattack, with Bybit, a Dubai-based exchange, falling victim to one of the largest hacks in history. On February 21, 2025, hackers stole approximately $1.46 billion in digital assets, sparking controversy and concerns over security in the crypto space. Reports suggest that the North Korean state-sponsored hacking group Lazarus was behind the attack. However, in the wake of these allegations, another controversy has emerged, involving the crypto exchange eXch, which has been accused of laundering the stolen funds.
The Bybit Hack: What Happened?
According to Bybit, the hackers managed to exploit vulnerabilities in the exchange’s multisig Ethereum cold wallet, enabling them to transfer funds to unknown external wallets. This type of attack showcases the increasing sophistication of cybercriminals targeting the crypto industry.
Despite the massive breach, Bybit’s CEO, Ben Zhou, assured users that the exchange has sufficient reserves to cover losses and that user funds remain secure. The company has also engaged with law enforcement agencies and cybersecurity experts to track and potentially recover the stolen assets.
eXch Denies Involvement in Money Laundering Allegations
Shortly after the hack, blockchain analyst ZachXBT alleged that eXch had processed approximately $35 million of the stolen funds, implicating the platform in a potential laundering operation for Lazarus Group. eXch, however, has strongly denied these claims, calling them “deliberate misinformation” aimed at damaging their reputation.
The exchange clarified that only a small portion of the hacked funds had moved through their platform and that they had taken immediate action to freeze any suspicious transactions. eXch also criticized ZachXBT for spreading unverified information, urging the crypto community to fact-check such accusations before accepting them as truth.
Industry Reactions and Security Measures
The Bybit hack has reignited discussions on the security of centralized exchanges. In response to the breach, Binance’s former CEO, Changpeng Zhao (CZ), suggested that exchanges should consider temporarily pausing withdrawals in the aftermath of such incidents to prevent further losses. While this approach could mitigate the risk of hackers liquidating stolen assets, it also raises concerns over user trust and access to funds.
The incident highlights the need for robust security measures, including improved wallet security protocols, frequent audits, and the use of decentralized solutions to minimize risks. As crypto heists become more sophisticated, exchanges must continuously upgrade their security frameworks to stay ahead of cybercriminals.
The Bigger Picture: North Korea and Crypto Crimes
The Lazarus Group has been linked to several high-profile crypto heists, with funds often used to finance North Korea’s nuclear and military programs. The group has employed various tactics, including phishing attacks, social engineering, and exploiting vulnerabilities in blockchain protocols.
The scale of the Bybit hack suggests that crypto exchanges remain prime targets for state-sponsored hackers. Regulatory bodies and cybersecurity firms are increasing their efforts to combat illicit financial flows, but the decentralized nature of cryptocurrencies presents unique challenges in tracking and recovering stolen assets.
The Bybit hack serves as a stark reminder of the ongoing threats facing the crypto industry. While the exchange has reassured users of its financial stability, the breach underscores the urgency of enhancing security measures across the sector. Meanwhile, the accusations against eXch highlight the risks exchanges face in handling suspicious transactions and the potential reputational damage caused by misinformation.
As investigations continue, the crypto community must push for stronger security standards and collaborative efforts to prevent future incidents. With hackers becoming more sophisticated, the industry must evolve accordingly to ensure the safety and integrity of digital assets.