Open app

HostDeFi › Is Bybit safe

Is Bybit safe? The venue that took crypto's largest-ever hit and stayed open

Bybit holds this family's most extreme datapoint: on February 21, 2025, Lazarus stole ~$1.5 billion from its ETH cold wallet — the largest heist in crypto history — via a compromised Safe{Wallet} developer machine that poisoned the signing UI itself. Bybit kept withdrawals open through the panic wave and covered the hole from reserves. The stress test every other CEX page can only speculate about actually happened here.

Updated September 28, 2026 · By the HostDeFi editorial desk · Sources linked throughout; vendor claims labeled.

What Bybit is

Bybit is a top-tier global derivatives and spot exchange — custodial in the standard CEX shape: account balances are claims, assets live in cold/hot multisig wallets, and the safety question is really two questions: can the venue be breached, and what happens to users when it is. After February 2025, Bybit is the one venue with a definitive answer to the second.

February 21, 2025: the largest heist in crypto history

At ~12:30 UTC on February 21, 2025, Bybit detected unauthorized activity during a routine transfer from its ETH multisig cold wallet to a hot wallet. Losses: 401,347 ETH plus ~113K stETH/mETH/cmETH — over $1.5 billion. The FBI confirmed North Korea's Lazarus Group as the actor.

The vector, per Sygnia and Verichains forensics (confirmed by Safe Ecosystem Foundation): attackers compromised a Safe{Wallet} developer machine, injected malicious JavaScript into app.safe.global's AWS-served signing interface — specifically targeting Bybit's cold wallet — and presented Bybit's three signers (CEO Ben Zhou among them) with a transaction that looked routine but silently upgraded the Safe to a malicious implementation containing sweepETH/sweepERC20 backdoors. The signers signed what they saw; the contract did something else. No evidence of compromise was found in Bybit's own infrastructure.

Why the mechanism matters more than the number

The multisig model promises that no single key holder can drain a wallet — three independent signers must each approve. This attack broke the model without touching a single key: it poisoned the shared display layer all three signers read. Every signer's hardware, every key, every quorum rule performed perfectly — the interface simply lied to all of them at once. It is the same lesson the frontend-hijack pages in this family teach, raised to nine figures: what the UI shows is what gets signed, and a compromised UI can defeat perfect key architecture.

What happened to users: nothing — and that's the point

The stolen funds were Bybit's own cold-wallet reserves, not segregated user balances. In the following days:

Compare the corpus's other CEX incident: OKX froze withdrawals five weeks over a single unreachable key holder with zero dollars missing. Bybit kept the exits open through a $1.5B hole. That is the difference between a promise and a stress test.

The honest residual risks

LayerStatusRead
Custodial reservesBreached once — covered in full, exits stayed openProven at scale, but custody remains concentrated risk
Third-party signing UI (Safe)The failure point — hardened post-incidentVendor trust is part of the CEX attack surface
User-side phishingEndemic on a top-3 brandCloned domains/apps — unchanged
Regulatory reachVaries by jurisdictionStandard offshore-CEX variance

What the response revealed about reserves

The part of the incident worth keeping for a user evaluating any CEX: the proof was behavioral, not attested. Bybit could have frozen — every precedent (OKX 2020, Binance 2019's week-long pause) said freeze first. Instead it kept withdrawals open while a run was visibly underway, bridged the ETH gap through institutional OTC channels within days, and published follow-on attestations. A venue that stays liquid and open through a $1.5B hole has demonstrated something a snapshot PoR structurally cannot: access under stress. That is the property this family's risk tables keep circling — solvency is static, access is dynamic — and it is why the incident, perversely, makes the venue's record stronger than a clean one that has never been tested.

Where Bybit stands

No other venue in this family has a datapoint this extreme. The dated read: Bybit was attacked by a state actor through a third-party supply chain, lost more than most exchanges are worth, and processed every withdrawal anyway — custodial risk made concrete, and resilience made concrete in the same event. The lesson travels: the signing interface is part of the trust stack.

The verdict in one line: Bybit got hit for $1.5B through a poisoned signing UI its multisig couldn't see — and stayed solvent and open through the run; it is now the best-documented case that a custodian's real safety metric is what it does on the worst day, not what it claims on a normal one.

Frequently asked questions

Is Bybit a legitimate exchange?

Yes — Bybit is one of the largest derivatives/spot exchanges globally, and after February 2025 it holds a unique credential: it absorbed the largest theft in crypto history (~$1.5B), kept withdrawals open through a 580,000-request wave, and re-bridged reserves. Being hit proves nothing about safety; how a venue behaves while being hit proves a great deal — and Bybit's answer is on the record.

What exactly happened in the February 2025 Bybit hack?

On February 21, 2025, North Korea's Lazarus Group (FBI-confirmed) stole ~401,347 ETH plus stETH/mETH/cmETH — ~$1.5 billion — from Bybit's Ethereum multisig cold wallet. The vector was not Bybit's own systems: attackers compromised a Safe{Wallet} developer machine, injected malicious JavaScript into app.safe.global's signing UI, and served Bybit's three signers (including CEO Ben Zhou) a disguised transaction that silently upgraded the cold wallet to a malicious implementation with sweepETH/sweepERC20 backdoors. Forensics by Sygnia and Verichains — confirmed by Safe itself — found no compromise in Bybit's infrastructure.

Did Bybit users lose money?

No — and this is the remarkable part. The $1.5B was stolen from Bybit's cold wallet (its own reserves), not user balances. Bybit covered the gap (bridging reserves via OTC partners), processed a 580,000-request withdrawal wave without closing the exits, and CEO Ben Zhou stated the exchange remained solvent even with zero recovery. The incident ran the playbook every other 'is X safe' page treats as hypothetical: a nine-figure loss, absorbed in public, with users made whole by solvent reserves.

Who holds your crypto on Bybit?

Bybit does — it is a custodial CEX: account balances are claims on the company, custodied across cold/hot multisig wallets. The hack demonstrated both sides of that: custody concentrates risk into the venue's key-management stack (which failed at the Safe signing-UI layer, not Bybit's infrastructure) — and it concentrates responsibility, which is why a solvent venue could backstop a $1.5B hole without touching user balances.

What does the Bybit hack prove about CEX safety?

Two things at once. (1) Multisig is only as strong as its signing interface — three independent signers all approved a malicious transaction because the Safe UI itself was compromised; the attack bypassed the entire signer-independence model at the display layer. (2) Solvency + behavior beat promises — the exchange that can lose $1.5B and process every withdrawal is quantitatively more resilient than one that merely says funds are safe. Both halves belong in an honest risk read.

Is Bybit safer now than before the hack?

Materially, yes on the specific vector: signing flows were hardened, Safe upgraded its infrastructure (rotated credentials, tightened release controls), and Bybit instituted additional transaction-verification and independent security reviews. Categorically, the residual risks are the standing CEX set — custodial counterparty exposure, phishing clones, jurisdiction variance — plus the new lesson that a trusted third-party signing UI is itself a single point of failure. The dated read: battle-tested at a scale no other venue has faced.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product