Crypto exchange Bybit lost about $1.5 billion in Ethereum-linked assets after attackers compromised the platform in what has been described as the largest cryptocurrency theft on record. Blockchain investigators at TRM Labs and a subsequent FBI/IC3 public attribution linked the operation to North Korean threat actors, citing wallet overlaps and tradecraft consistent with earlier DPRK-backed campaigns. Reporting tied the theft to a broader pattern of financially motivated North Korean operations that have previously targeted major crypto platforms and financial institutions.
After the theft, the stolen funds were moved at high speed through intermediary wallets, decentralized exchanges, and cross-chain bridges, with a large share ultimately converted into Bitcoin. Analysts said the laundering operation showed an evolution in DPRK tactics away from reliance on traditional mixers and toward rapid, high-volume cross-chain obfuscation; later reporting said more than $1 billion had been laundered within months. The heist also triggered recovery efforts, including Bybit's 10% bounty program for frozen or recovered assets, and intensified debate over cryptocurrency oversight and the implications for future U.S. regulation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2025-07-22, reporting said North Korean hackers had laundered over $1 billion of the funds stolen from Bybit in under six months. This marked a major escalation in the post-heist movement of the stolen assets.
Within days of the theft, the attackers shifted hundreds of millions of dollars through intermediary wallets, decentralized exchanges, and cross-chain bridges, with much of the value ultimately converted into Bitcoin. Analysts noted this reflected a DPRK laundering shift away from traditional mixers toward faster, high-volume cross-chain obfuscation.
In the aftermath of the hack, Bybit announced a 10% bounty program to incentivize the freezing or recovery of stolen funds. The measure was part of broader efforts with investigators and law enforcement to trace and claw back assets.
On 2025-02-26, the FBI/IC3 publicly stated that North Korea was responsible for the $1.5 billion Bybit hack. This formalized the attribution already emerging from private-sector blockchain intelligence.
By 2025-02-23, reporting indicated North Korean hackers were suspected of being behind the Bybit theft. Blockchain investigators linked the stolen funds to wallets and patterns associated with prior DPRK-linked operations and began tracing rapid laundering activity.
On 2025-02-21, cryptocurrency exchange Bybit suffered a cyberattack that resulted in the theft of roughly $1.5 billion in Ethereum-based assets. The incident was described as the largest cryptocurrency exploit on record.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcewilsoncenter.org
Open sourcecsis.org
Open sourcetrmlabs.com
Open sourceic3.gov
Open sourcechannelnewsasia.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.