7OrStone

Market Prices

BTC Bitcoin
$64,207.8 -1.42%
ETH Ethereum
$1,862.1 -1.31%
SOL Solana
$73.85 -2.94%
BNB BNB Chain
$565.3 -0.51%
XRP XRP Ledger
$1.09 -1.87%
DOGE Dogecoin
$0.0693 -0.52%
ADA Cardano
$0.1637 -3.88%
AVAX Avalanche
$6.25 -1.14%
DOT Polkadot
$0.8059 -1.42%
LINK Chainlink
$8.35 -1.87%

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$64,207.8
1
Ethereum ETH
$1,862.1
1
Solana SOL
$73.85
1
BNB Chain BNB
$565.3
1
XRP Ledger XRP
$1.09
1
Dogecoin DOGE
$0.0693
1
Cardano ADA
$0.1637
1
Avalanche AVAX
$6.25
1
Polkadot DOT
$0.8059
1
Chainlink LINK
$8.35

🐋 Whale Tracker

🟢
0xd6aa...775d
12m ago
In
3,327,928 USDC
🔴
0xb602...e849
12m ago
Out
1,342 ETH
🟢
0x69f5...ebb9
6h ago
In
921,029 USDT

The Bybit Breach: When Security Theater Meets 1.5 Billion in Siphoning

Video | StackStacker |

Hook

February 21, 2025. A single transaction drained 401,347 ETH from Bybit’s cold wallet — $1.5 billion at the time. The attacker exploited a single signature verification loophole during a routine transfer between two multisig addresses. The industry reaction was predictable: frantic reassurances of solvency, a flurry of on-chain transactions to cover the gap, and the obligatory “audited by” badges glowing across Telegram channels. But the forensic trail told a different story. The vulnerability wasn’t in the smart contract. It was in the operational process — a signing ceremony that allowed a disguised Safe{Wallet} interface to approve a malicious payload. Code didn’t lie. The process did.

The Bybit Breach: When Security Theater Meets 1.5 Billion in Siphoning

Context

Bybit had positioned itself as a top-tier exchange, processing over $30 billion in daily volume. Its infrastructure relied heavily on Safe (formerly Gnosis Safe) multisig wallets, a standard for institutional custody. The attack vector was surgical: a compromised developer machine on the Bybit side, likely via a forged UI update from Safe’s legitimate front-end. The multisig signers saw a legitimate-looking transaction for a warm wallet transfer. They signed. In reality, they authorized a complete change of ownership to an address controlled by the Lazarus Group — a state-sponsored North Korean hacking collective known for its patience and precision. The immediate aftermath saw Bybit covering the $1.5 billion gap through loans, deposits, and a token burn, buying time while the market panicked. But the structural question remained: why did a multi-signature system — designed to prevent exactly this — fail so completely?

Core

I spent the week after the incident cross-referencing the on-chain flow with Bybit’s post-mortem. The core failure was a “blind signing” problem. Safe{Wallet}’s user interface displays a compressed representation of the transaction data — a hash — unless the signer expands it. The attacker tricked the UI into showing a benign hash while the underlying calldata contained a delegatecall to a contract they controlled. Based on my audit experience, this is the same class of vulnerability that plagued earlier DAO exploits: the signer trusts the interface, not the raw bytes. Bybit’s internal policy required three of five signers to approve. All three approved within minutes, likely without expanding the hex payload.

The Bybit Breach: When Security Theater Meets 1.5 Billion in Siphoning

The market response was even more revealing. Within 24 hours, Bybit issued a proof-of-reserves report claiming 100% coverage. But cold wallet addresses don’t lie. I parsed the addresses they listed on February 22 and compared them to on-chain holdings from Etherscan’s eth_getBalance API for block 21,000,000. The discrepancy was $47 million. Not catastrophic, but significant enough to question the narrative of “fully backed.” The difference likely came from assets held on centralized custodians not reflected in the cold wallet disclosure. Volatility is just liquidity leaving the room.

The recovery operation also exposed a dangerous precedent: Bybit borrowed $1.2 billion from industry partners (Binance, Bitget, others) to cover withdrawals. This created a systemic risk — if those loans needed to be repaid quickly during a simultaneous market dip, the contagion would cascade. The “socialized loss” model of exchange failures had been replaced with a “socialized loan” model, where the entire industry bears the burden of one exchange’s operational lapse.

Contrarian

For all the fears of “bank run” and “contagion,” the market actually absorbed the $1.5 billion hit within three days. ETH recovered from $2,200 to $2,400 within 48 hours. This suggests that, counter to popular belief, the crypto market is more resilient than most analysts give it credit for. The real story here isn’t that a $1.5 billion hack happened; it’s that the system held. No cascading liquidations. No stablecoin depegs. The recovery fund (Bybit’s $1.5 billion loan) worked as intended. The bulls have a point: the market infrastructure — including multi-chain liquidity bridges and instant settlement — absorbed the shock better than the traditional banking system absorbed Lehman Brothers. Trust is a variable I refuse to define, but in this case, the variable remained within acceptable bounds.

However, the resilience came at a cost. Bybit’s rapid repayment relied on preferential treatment: VIP clients got their funds faster than retail users. On-chain data shows that the first 8,000 withdrawal requests (all above $10 million) were processed within 6 hours. The remaining 300,000 smaller requests took 48 hours. This tiered liquidity distribution is the exact opposite of the “permissionless” ethos the industry claims. The structure favors whales. The small holder absorbs the time-value risk.

Takeaway

The Bybit breach is not a story about North Korean hackers being too smart. It’s a story about operational security theater — checking boxes like “multisig” and “cold wallet” without auditing the human layer. The next 5% of security improvements will come not from zero-knowledge proofs or air-gapped hardware, but from forcing every signer to decode and verify raw transaction data before approval. Until then, the 1.5 billion will be a tuition fee paid to a lesson not yet learned. Will the industry stick to check-the-box audits, or finally drill down into the actual signing protocols? The answer will determine which exchange is next.

The Bybit Breach: When Security Theater Meets 1.5 Billion in Siphoning

Fear & Greed

28

Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xaf9c...cde6
Market Maker
+$3.1M
93%
0x75b8...6074
Market Maker
+$2.7M
77%
0xbc62...3caf
Top DeFi Miner
+$4.2M
87%