Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

← Back to Safety Scores

Case file

Bybit

HackFebruary 2025
Hack2025

What happened

On 21 February 2025 attackers moved roughly $1.46 billion of ether and staked ether out of a Bybit cold wallet by manipulating what signers saw in a Safe multisig interface, so legitimate keyholders approved a transfer that was not what it appeared to be. The FBI attributed the attack to North Korea's Lazarus Group.

What to take from it

No key was stolen — the approval screen lied. Cold storage and multisig only help when every signer can verify, independently of that screen, what they are actually authorising.

Where it sits on the record

The documented exchange failures we track, in the order they happened.

  1. 2014

    Mt. Gox

    February 2014

    Once the exchange handling the large majority of the world's Bitcoin trades, Mt. Gox abruptly halted withdrawals and filed for bankruptcy in Japan after disclosing that hundreds of thousands of customer and company bitcoins were gone — later attributed to theft that went undetected for years.

  2. 2015

    Bitstamp

    January 2015

    In January 2015 roughly 19,000 BTC was taken from Bitstamp's hot wallets following a targeted attack on exchange staff. Bitstamp suspended trading, rebuilt its infrastructure, and afterwards moved to third-party institutional custody with the large majority of customer assets held offline.

  3. 2016

    Bitfinex

    August 2016

    A security breach in Bitfinex's multi-signature wallet setup let attackers drain a large share of customer bitcoin in a single incident. The exchange spread the loss across all users' balances and later repaid affected customers over several years.

  4. 2016

    The DAO

    June 2016

    The DAO was an investor-directed fund written entirely as Ethereum smart contracts: token holders would vote on which proposals received funding, with no manager in between. Its 2016 token sale gathered a large fraction of all circulating ether. In June 2016 an attacker exploited a reentrancy flaw in the code that let a participant withdraw their share: the contract sent ether out before it updated the sender's balance, so a malicious contract could call back into the withdrawal repeatedly and be paid again each time on a balance that had not yet been reduced. Roughly 3.6 million ETH was moved into a child contract subject to a holding period written into The DAO's own rules, which is what gave the community weeks to argue about a response. Ethereum's participants ultimately adopted a hard fork that moved the funds to a recovery contract. A minority rejected the fork on the grounds that the ledger should not be rewritten, and continued the original chain as Ethereum Classic.

  5. 2017

    Parity's multi-signature wallets did not each carry their own logic. To save deployment cost, every wallet was a thin contract that delegated its behaviour to one shared library contract on the network. That library had been deployed without being initialised, so its ownership was still unclaimed. In November 2017 a user claimed it and then invoked its self-destruct function, which removed the library's code from the chain. Every wallet that depended on it was left pointing at nothing: the balances still exist in the ledger, but the code that could authorise a transfer no longer does. Public estimates put the amount stranded at roughly 513,000 ETH. Nobody took the funds, and no exploit moved them; they simply stopped being reachable. Proposals to recover them by protocol change were debated and not adopted. Months earlier, a separate flaw in the same wallet software had allowed an actual theft of around 150,000 ETH by public estimates.

  6. 2018

    BitConnect

    January 2018

    BitConnect invited users to exchange bitcoin for its own token and lock it in a lending programme that promised steady returns, said to be generated by a proprietary trading bot nobody outside the company could inspect. A multi-level referral structure paid existing participants to recruit new ones. After state securities regulators in the United States issued cease-and-desist orders, the lending platform was shut down in January 2018 and the token's value collapsed. US authorities later charged the operation as a fraud: a promoter pleaded guilty, and the founder was indicted and reported as a fugitive.

  7. 2018

    Coincheck

    January 2018

    The Japanese exchange kept a large pool of a single token in an internet-connected hot wallet without a multi-signature setup. Attackers stole hundreds of millions of dollars' worth in one of the largest exchange hacks by value at the time.

  8. 2019

    Binance

    May 2019

    On 7 May 2019 attackers withdrew roughly 7,000 BTC — about $40 million at the time — from a Binance hot wallet in a single transaction, using stolen API keys and phished credentials. Binance covered the entire loss from its Secure Asset Fund for Users, and customer balances were left untouched.

  9. 2019

    Across 2018 and 2019 Bitfinex had roughly $850 million of commingled customer and corporate money sitting with its payment processor, Crypto Capital Corp, whose accounts were seized by authorities in several countries. Affiliated stablecoin issuer Tether's reserves covered the gap; both firms settled with the New York Attorney General for $18.5 million in February 2021 without admitting wrongdoing.

  10. 2019

    QuadrigaCX

    Early 2019

    Canada's largest exchange at the time told customers it could no longer access roughly CA$190M in funds after its founder died while allegedly holding sole control of the cold-wallet keys. A later court-appointed investigation found many of the wallets had been empty long before his death, pointing to mismanagement and likely fraud rather than a pure accident.

  11. 2020

    KuCoin

    September 2020

    On 25 September 2020 attackers drained roughly $281 million from KuCoin's hot wallets. About 84% was recovered over the following weeks through on-chain tracing, token issuers freezing and reissuing supply, and blacklisting by other exchanges. KuCoin's insurance fund covered the remainder, and users were made whole.

  12. 2022

    The crypto lending platform froze all customer withdrawals during a market downturn and filed for bankruptcy weeks later. Its founder was subsequently charged with, and later pleaded guilty to, fraud for misrepresenting the platform's risk to depositors.

  13. 2022

    Crypto.com

    January 2022

    On 20 January 2022 roughly $34 million in bitcoin, ether and other assets was withdrawn from 483 Crypto.com customer accounts. The withdrawals were approved without two-factor authentication being properly enforced. The company paused withdrawals, rebuilt the authentication flow, and reimbursed every affected user.

  14. 2022

    FTX

    November 2022

    One of the largest exchanges globally collapsed within days after reporting revealed customer deposits had been comingled with, and lent to, a sister trading firm. Its founder was later convicted on multiple counts of fraud.

  15. 2022

    Ronin Bridge

    March 2022

    The Ronin bridge, which connected the Axie Infinity game's sidechain to Ethereum, was drained in March 2022 after attackers gained control of a majority of the small validator set whose signatures authorised withdrawals. Nothing was broken in the contract: the withdrawals were validly signed by the keys the system trusted. The loss was only discovered days later, when a user reported being unable to withdraw. US authorities subsequently attributed the theft to the North Korea-linked Lazarus Group.

  16. 2022

    Terra / LUNA

    May 2022

    TerraUSD was an algorithmic stablecoin that held its dollar peg not with reserves but with a mint-and-burn link to LUNA, the network's own volatile token: a UST below a dollar could always be exchanged for a dollar of newly created LUNA. In May 2022 the peg slipped and that mechanism worked in reverse — restoring it required minting ever more LUNA, which crushed LUNA's price and destroyed the very value the peg depended on. Both assets collapsed within days, and Terraform Labs and its founder later faced criminal and civil proceedings in the United States and South Korea.

  17. 2022

    Three Arrows Capital was a Singapore-based hedge fund that had become one of the largest borrowers in crypto, funding leveraged positions with loans from centralised lending desks. It held a substantial position in Terra's ecosystem, which lost effectively all of its value in May 2022, and it was exposed to other trades that moved against it as prices fell. When lenders issued margin calls in June 2022 the fund could not meet them. A court in the British Virgin Islands ordered its liquidation at the end of that month, and the liquidators sought recognition in the United States shortly after. The default did not stop at the fund: several of the lending platforms that had extended it credit disclosed losses, and some of them subsequently entered bankruptcy themselves. Singapore's regulator later issued prohibition orders against its founders.

  18. 2022

    Wormhole

    February 2022

    Wormhole, a bridge issuing wrapped assets across several chains, lost roughly 120,000 wrapped ether in February 2022 when an attacker exploited a flaw in how its Solana-side contract verified the guardian signatures that authorise a mint. The attacker was able to produce a mint that the contract accepted without a matching deposit on Ethereum, leaving the wrapped tokens undercollateralised. Jump Crypto, which backed the project, replaced the missing ether so that holders of the wrapped asset were made whole.

  19. 2023

    HTX (formerly Huobi)

    September 2023

    On 24 September 2023 roughly 5,000 ETH — about $8 million — was taken from a single HTX hot wallet. The exchange identified the attacker, negotiated the return of 95% of the funds and paid the remaining 5% as a white-hat bounty. Customer balances were covered in full.

  20. 2024

    DMM Bitcoin

    May 2024

    On 31 May 2024 DMM Bitcoin, a Japanese exchange registered with the Financial Services Agency, reported an unauthorised outflow of 4,502.9 BTC — worth roughly $300m at the time and one of the largest thefts in the country's history. The company said it would procure the equivalent bitcoin with support from the wider DMM group so that customer holdings were fully covered, and Japan's FSA issued a business improvement order. In December 2024 US and Japanese agencies publicly attributed the theft to North Korea-linked actors, and DMM announced it would cease its crypto business and transfer customer accounts to SBI VC Trade.

  21. 2025

    Bybit

    You are hereFebruary 2025

    On 21 February 2025 attackers moved roughly $1.46 billion of ether and staked ether out of a Bybit cold wallet by manipulating what signers saw in a Safe multisig interface, so legitimate keyholders approved a transfer that was not what it appeared to be. The FBI attributed the attack to North Korea's Lazarus Group.

Next

The gradesThe grade ledgerThe five checks this record produced, applied to every exchange we grade.Open