
Bybit Already Lost $1.5 Billion. The Next Attack Could Be Silent.
On February 21, 2025, three Bybit employees signed what looked like a routine transfer. It was a delegatecall that handed $1.5 billion to North Korea. This technical intelligence analysis examines five attack surfaces that still threaten every user holding crypto on Bybit — and why the next attack, driven by AI, could be silent.
Executive Takeaway — TL;DR
- Category:
- Cyber Intelligence
- Severity:
- Critical
- Confidence:
- High Confidence
- Read Time:
- 14 min
Bybit Already Lost $1.5 Billion. The Next Attack Could Be Silent.
On February 21, 2025, three Bybit employees sat down at their computers to perform a routine task they had done hundreds of times before. They logged into the Safe{Wallet} interface, reviewed what appeared to be a standard transfer of Ethereum from the exchange’s cold wallet to its hot wallet, connected their Ledger hardware wallets, and signed the transaction.
They saw 30,000 ETH moving to the correct address. The Safe URL was legitimate. The interface looked exactly like it always did. Everything was normal.
Everything was a lie.
The transaction they signed was not a transfer. It was a delegatecall — a different Ethereum operation that allowed the attacker to replace the wallet’s implementation contract with malicious code. One parameter was changed, from 0 to 1. That single flip, invisible on the user interface they were looking at, handed complete control of Bybit’s cold wallet to North Korea’s Lazarus Group.
Forty-one minutes later, 401,000 ETH worth $1.5 billion began moving to attacker-controlled addresses. It was the largest cryptocurrency theft in history. And the people who authorized it didn’t know it had happened until the funds were already gone.
If you hold crypto on Bybit, you should understand exactly how this happened — because the conditions that made it possible have not been fully eliminated. And the next attacker won’t be human. It will be an AI. And you won’t see it coming.
How One Compromised Laptop Stole $1.5 Billion
The attack didn’t start at Bybit. It started at Safe{Wallet} — the third-party platform Bybit trusted to manage its cold wallet infrastructure. The Lazarus Group compromised a Safe{Wallet} developer’s computer using LummaC2, an infostealer malware available on the dark web for a few hundred dollars. The malware harvested credentials from the developer’s browser, giving the attackers access to Safe’s AWS S3 infrastructure.
Once inside, the attackers injected a malicious JavaScript snippet into the Safe{Wallet} frontend. This snippet was designed to activate only when Bybit’s specific cold wallet address was loaded, and only during a transaction signing flow. For every other user, the interface worked normally. For Bybit’s signers, it showed a lie.
When the Bybit employees opened the Safe{Wallet} interface to approve a routine cold-to-hot wallet transfer, the injected JavaScript intercepted the transaction data in the browser. The signers saw a normal transfer: 30,000 ETH to the correct hot wallet address, operation type 0 (a standard call). But the actual transaction data sent to their Ledger devices for signing contained a modified payload: a delegatecall (operation type 1) to a malicious contract that overwrote the implementation address stored in the proxy contract’s slot 0.
The Ledger hardware wallets displayed the raw transaction data. But Ledger’s screen showed the destination address and the ETH amount — not the operation type or the data payload. The signers couldn’t distinguish between a call and a delegatecall on the device screen. This is the blind signing problem: hardware wallets verify some transaction parameters but not all, leaving a gap between what the user thinks they’re signing and what they’re actually authorizing.
Once the malicious implementation contract was installed, the attackers had full control of the cold wallet. They transferred 401,000 ETH across 900+ wallets, through cross-chain bridges and decentralized exchanges, in a deliberate strategy to fragment and launder the funds before blockchain analytics could trace them.
One compromised laptop. One injected JavaScript file. One parameter changed from 0 to 1. $1.5 billion gone.
The Bank Run: When Trust Evaporates in Hours
The hack itself was catastrophic. What followed was worse. Within hours of the news breaking, Bybit users began withdrawing their funds in a panic that escalated into the largest bank run in crypto history. Over $5.5 billion flowed out of the exchange — $1.5 billion stolen by the hackers, and $4 billion withdrawn by terrified users who didn’t know if the exchange could survive.
Bybit’s CEO Ben Zhou went public immediately, confirming the hack, reassuring users that all losses would be covered, and that the exchange had sufficient reserves. Emergency loans and large deposits from institutional partners replenished the stolen ETH within days. A proof-of-reserves audit by Hacken confirmed that Bybit had restored its reserves to a 1:1 ratio.
The exchange survived. But survival is not the same as safety. The bank run revealed something that every Bybit user should internalize: when trust fails in a crypto exchange, the failure is instantaneous. There is no FDIC insurance. There is no weekend grace period. There is no central bank liquidity facility. The moment doubt enters the market, the exit door becomes a bottleneck, and the people who move slowest are the ones who are left holding the bag.
If your crypto is on Bybit right now, you are trusting that the exchange’s security architecture will prevent the next attack. After what happened in February 2025, you should ask yourself whether that trust is justified.
Surface One: The Supply Chain — Every Third Party Is a Backdoor
The Bybit hack was not a failure of Bybit’s own security. It was a failure of Safe{Wallet}’s security. Bybit did everything right by their own standards: multisig wallet, hardware wallets, multiple signers, cold storage. None of it mattered because the vulnerability was in the third-party platform they depended on to manage their cold wallet.
Every major exchange has this problem. The custody platform, the KYC vendor, the analytics provider, the API gateway, the cloud infrastructure — every third party in the stack is an attack surface. And the exchange has no direct control over the security of those third parties. Safe{Wallet} was considered a trusted, battle-tested platform. It was compromised through a single developer’s laptop.
An AI-driven supply chain attack would not target one vendor. It would map every third-party dependency in Bybit’s infrastructure simultaneously, identify the developer laptops with the weakest security posture across every vendor, and compromise them in parallel. The AI would inject malicious code not into one vendor’s frontend, but into every vendor’s frontend — each injection tailored to activate only when the target exchange’s specific wallet addresses or transaction patterns are detected. Bybit would see a single anomalous transaction. The AI would have already compromised five vendors.
Surface Two: The Blind Signing Problem — What You See Is Not What You Sign
The fundamental vulnerability that enabled the Bybit hack was blind signing — the gap between what the user interface displays and what the hardware wallet actually authorizes. The signers saw a transfer. They signed a delegatecall. The hardware wallet verified the destination address and the amount. It did not verify the operation type or the data payload.
This is not a Bybit-specific problem. It is an industry-wide problem with smart contract wallet interactions. Every exchange that uses Safe{Wallet}, every protocol that requires users to sign complex transactions, every platform that relies on hardware wallet approval for smart contract operations is vulnerable to the same class of attack.
An AI system would not need to compromise the entire Safe{Wallet} infrastructure to exploit this. It could target the signer’s browser directly — injecting a browser extension or a compromised script that intercepts the transaction data between the Safe UI and the Ledger. The AI could dynamically generate malicious payloads that match the exact parameters the Ledger displays while hiding the operation type change in the data field. And it could adapt the attack in real time based on which signers are online, what time of day it is, and what transactions are pending.
The AI wouldn’t need to trick three signers at once. It would need to trick three signers across three different sessions, each one seeing a slightly different lie, each one believing they’re approving a routine transfer.
Surface Three: API Keys and the AI Trading Surface
Bybit operates 253 API endpoints. In 2025, Bybit launched AI Trading Skill, allowing users to execute trades through ChatGPT, Claude, or Gemini using natural language. This integration creates a new attack surface: the API keys that connect AI agents to Bybit’s trading engine.
An API key is a door to your account. A compromised key can place trades, withdraw funds, and access account data. When that key is used by an AI agent, the attack surface expands: the AI agent’s infrastructure, the communication channel between the agent and the API, and the agent’s own prompt processing pipeline all become potential targets.
An AI-driven attack on Bybit’s API layer would not brute-force API keys. It would target the infrastructure around the keys: the AI trading agents that users have authorized, the OAuth flows that connect LLM platforms to Bybit, and the webhooks that trigger automated trading. An attacker who compromises a user’s AI trading agent can execute trades and withdrawals through a channel that looks completely legitimate — because it is legitimate. The API key is real. The agent is real. The instructions are fake.
Surface Four: The Delegatecall Trap — A Class of Vulnerability, Not a Single Bug
The specific vulnerability that Bybit fell victim to — a delegatecall replacing an implementation contract — is not a one-time flaw. It is a class of vulnerability inherent to Ethereum’s smart contract upgradeability pattern. Proxy contracts that use delegatecall for implementation upgrades are standard practice. The pattern is sound when used correctly. But the pattern depends on the signers understanding what they’re authorizing.
Every smart contract wallet that uses the proxy-upgrade pattern has this exposure. The protection is not in the code — it’s in the human verification step. And as the Bybit hack proved, the human verification step can be deceived by a compromised UI.
An AI system could automate the discovery of this vulnerability class across every smart contract wallet on every blockchain. It could scan for wallets using proxy patterns, identify the specific implementation addresses, and generate delegatecall payloads that replace implementations with attacker-controlled contracts. The AI wouldn’t need to find a new vulnerability. It would need to find the same vulnerability in new places — and there are thousands of proxy contracts across the ecosystem.
Surface Five: The Trust Architecture — The Problem You Can’t Patch
Bybit survived the $1.5 billion hack because it had the reserves and the institutional relationships to backstop the loss. Not every exchange does. The hack revealed that the entire crypto exchange model depends on a fragile trust architecture: users trust the exchange, the exchange trusts its custody provider, the custody provider trusts its developers, and the developers trust their laptops.
The chain is only as strong as its weakest link. In Bybit’s case, the weakest link was a developer’s laptop at a third-party vendor. $1.5 billion was stolen because one person’s computer was infected with commodity malware.
An AI-driven attack would not target the strongest link. It would systematically probe the entire chain, from the exchange’s internal security to every vendor’s developer workforce, and attack the weakest point. The AI could compromise dozens of developer machines across multiple vendors simultaneously, maintaining persistence across all of them, and activating the attack only when the optimal conditions align — the right transaction, the right signers, the right time.
The trust architecture that secures crypto exchanges is a chain. The AI is learning where every link is.
What This Means for Your Crypto on Bybit
Bybit survived the largest hack in crypto history. That fact has been used to build confidence. But survival is not proof of security. It is proof of reserves. The difference matters.
Bybit had enough money to cover the $1.5 billion loss. That means your funds were safe this time. It does not mean they will be safe next time. The next attack could be larger. The next attacker could be faster. The next attack could target not the cold wallet, but the withdrawal system, the API infrastructure, or the trading engine itself — systems where a compromise doesn’t steal from the exchange’s reserves but from user accounts directly.
The February 2025 hack took months of preparation by one of the most sophisticated state-sponsored hacking groups in the world. An AI system could compress that preparation into hours. The LummaC2 infostealer that compromised the Safe{Wallet} developer’s laptop is commodity malware. The JavaScript injection technique is well-documented. The delegatecall attack pattern is understood. Every component of the Bybit hack is now public knowledge — and anything that is public knowledge is something an AI can learn, replicate, and deploy at machine speed.
The question is not whether Bybit has hardened its defenses since February 2025. They have. The question is whether those defenses can withstand an attack that adapts faster than they can patch.
The $1.5 billion hack was the work of humans. The next one won’t be. And when an AI-driven attack succeeds against an exchange, there will be no 48-hour news cycle, no CEO statement, no proof-of-reserves audit. The funds will move through cross-chain bridges and mixing services at machine speed, fragmented across thousands of addresses in seconds, and gone before anyone knows the attack happened.
Your crypto on Bybit is only as safe as the weakest link in a chain that extends from the exchange’s cold wallet to a developer’s laptop at a third-party vendor you’ve never heard of. That chain held once. It broke once. And the AI is already learning where the next break will be.
This is not FUD. This is forensic analysis. The vulnerabilities are documented. The incidents are real. The $1.5 billion is gone. The only question is whether the next billion leaves silently.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Surveillance: Pegasus Zero-Click Exploits Target Civil Society in Eastern Europe

Global Intelligence Alert: BlueMoon Exploit Kit Adopted by Multiple Nation-State Actors

