ZachXBT: $1.46B flowed out of Bybit Ethereum (ETH) cold wallet

Source Cryptopolitan

Bybit, one of the most active centralized exchanges, has undergone a security incident after its wallet interface was exploited. Over $1.46B has flowed out to four Ethereum addresses, and some of the funds are being swapped on DEX. 

On-chain investigator ZachXBT and other services registered suspicious outflows from Bybit’s wallets. Previously, the exchange was also attacked by address poisoning, with spoof token transactions entering the cold wallet among legitimate inflows. Minutes after the attack, Bybit confirmed the incident, stating it was an exploit during the routine movement of funds from cold to hot wallets.

The Bybit attack is the biggest hack so far in 2025 and the first one targeting a major market operator. At the time of the attack, Bybit lost up to 8.64% of its assets out of its total reserves of $16.2B. Bybit was also just funded with additional assets to reimburse the first group of FTX creditors for claims under $50,000. 

Bybit noted its only affected wallet was the ETH cold wallet, which fell under the full control of the hacker. Bybit was affected by what was also known as an upgrade transaction attack, in which a smart contract’s address looks legitimate to the wallet, but sends a malicious instruction to the sender, redirecting funds to a different wallet.

The exchange used the Safe layer on Ethereum to verify the destination wallet. It is possible that Safe displayed the transaction data correctly, but an element of human error led to the signing of a malicious contract. Incident analysis suggests Bybit may have omitted to run either an automated or manual check on the actual destination address and the contents of the transaction. 

No other cold or hot wallets of Bybit were affected, and deposits and withdrawals are still open. The exchange, which gets most of its traffic from the Russian Federation, continues its operations after a series of new listings. 

The Bybit incident was completed in the same way as the hacks of WazirX and Radiant Capital, some of the biggest exploits of 2024. The attack against Bybit happened at a time when overall attacks have slowed down or shifted to other types of exploits. 

Hacking incident leads to $1.46B in losses

The exchange saw outflows of $1.46B for mETH and stETH, which is being swapped back into ETH through DEX. The ETH can then be mixed and remain untraceable, causing one of the first big security incidents against an exchange for 2025. 

ZachXBT tracked the outflow of funds to five addresses on the Ethereum chain. Soon after the attack, some of the funds were split in batches of 10K ETH to 39 addresses. The exploiter is scrambling to hide the tokens while most of the addresses are blacklisted. 

In the first hour after the attack, the assets continued to split into smaller holdings, though most were linked to the flagged and blacklisted wallets. The attacker is trying to swap some of the funds through DEX, which may be extremely inefficient for a haul valued at close to $1.5B.

Bybit ranks third based on its reputation and trading volumes, lining up after Binance and Coinbase. The exchange recently boosted its transparency with new tools for full reporting of liquidations. The exchange was working on transparency technologies in a trial to produce proof-of-reserves similar to Binance. 

Ben Zhou, the founder and CEO of Bybit, stated that the exchange is solvent and will not cease operations. 

The Bybit hack affected the wider market, breaking the ETH rally. In the past hour, ETH is down by 2.9%, back to $2,752.42. Bitcoin (BTC) sank under $99,000, stalling in its most recent rally.

Cryptopolitan Academy: FREE Web3 Resume Cheat Sheet - Download Now

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold sinks as risk appetite improves on Trump-Powell calm, China tariff relief hopesGold prices plunged more than 2.50% on Wednesday as risk appetite improved due to a possible de-escalation of US-China tensions and US President Donald Trump's statement that he doesn’t plan to fire Federal Reserve (Fed) Chair Jerome Powell.
Author  FXStreet
Yesterday 01: 32
Gold prices plunged more than 2.50% on Wednesday as risk appetite improved due to a possible de-escalation of US-China tensions and US President Donald Trump's statement that he doesn’t plan to fire Federal Reserve (Fed) Chair Jerome Powell.
placeholder
Bitcoin Price Stabilizes After Surge — Is It Gearing Up for Another Leg Up?Bitcoin price is moving higher above the $93,200 zone. BTC is consolidating gains and might continue higher above the $94,000 zone in the near term.
Author  NewsBTC
Yesterday 03: 22
Bitcoin price is moving higher above the $93,200 zone. BTC is consolidating gains and might continue higher above the $94,000 zone in the near term.
placeholder
Gold price bulls could regain control amid fading US-China trade deal optimismGold price (XAU/USD) attracts fresh buyers during the Asian session on Thursday, reversing the previous day's heavy losses and snapping a two-day losing streak to the $3,260 area or the weekly low.
Author  FXStreet
22 hours ago
Gold price (XAU/USD) attracts fresh buyers during the Asian session on Thursday, reversing the previous day's heavy losses and snapping a two-day losing streak to the $3,260 area or the weekly low.
placeholder
Forex Today: Easing geopolitical tensions support USD ahead of mid-tier dataThe US Dollar (USD) stays resilient against its peers early Thursday after posting gains for two consecutive days.
Author  FXStreet
20 hours ago
The US Dollar (USD) stays resilient against its peers early Thursday after posting gains for two consecutive days.
placeholder
Gold price snaps selling off after fresh Trump comments on tariffsGold price (XAU/USD) is turning positive, recovering above the $$3,300 level at the time of writing on Thursday after two days of firm selling pressure since it topped at $3,500 on Tuesday.
Author  FXStreet
18 hours ago
Gold price (XAU/USD) is turning positive, recovering above the $$3,300 level at the time of writing on Thursday after two days of firm selling pressure since it topped at $3,500 on Tuesday.
goTop
quote