• Home
  • Latest
  • Coins2Day 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Some Coins2Day Crypto pricing data is provided by Binance.
RegulatorsNorth Korea

How North Korea cracked Bybit’s crypto safe to steal $1.5 billion in a record heist

By
Ben Weiss
Ben Weiss
Crypto Reporter
Down Arrow Button Icon
By
Ben Weiss
Ben Weiss
Crypto Reporter
Down Arrow Button Icon
March 4, 2025, 11:39 AM ET
Kim Jong Un smiles at the camera as he walks outside.
Kim Jong-un, the supreme leader of North KoreaGetty Images

In late February, hackers breached the Dubai-based Bybit, one of the world’s largest cryptocurrency exchanges, and stole about $1.5 billion of Ethereum. It was the largest hack in crypto’s history, and if Bybit were classified as a bank, it’s the largest ever bank heist, according to Guinness World Records. It eclipses even the $1 billion Iraqi President Saddam Hussein pilfered from his own country’s central bank in 2003. 

Recommended Video

“It was such a huge amount,” Ben Zhou, the cofounder and CEO of Bybit, said in an interview following the robbery.

Less than one week after the hack, the Federal Bureau of Investigation declared that North Korea was responsible for the breach. It’s also since emerged that, even by the standards of cybercrime, this was no ordinary hack: It was a calculated, creative, and highly advanced exploit that targeted a fundamental layer of Bybit’s infrastructure.

“This is a level up from any attack I’ve previously seen,” Omer Goldberg, founder and CEO of Chaos Labs, a crypto risk management firm, told Coins2Day.

Here’s how North Korea tricked Bybit, according to preliminary findings from the crypto exchange and one of its tech providers, Safe.

Bybit and Safe

Safe is one of many companies that develops tech to help people manage their cryptocurrency, like Bitcoin. Specifically, the firm builds open-source software that companies like Bybit use to create online wallets to store their crypto. The wallets are akin to bank vaults that need multiple keys to be unlocked.

Bybit used Safe to safeguard at least $1.5 billion of Ethereum, the world’s second largest cryptocurrency by market capitalization. Any time an employee from Bybit wanted to move the exchange’s Ethereum to another location, he or she signed into Safe’s website. Because Safe’s software is open-source, the company and Bybit had no formal business relationship, Stefan George, one of the original developers behind Safe’s technology, told Coins2Day.

Malware download

Even as Bybit was placing stores of Ethereum in Safe’s digital vault, North Korea’s group of elite hackers lay in wait, watching their moves. “They prepared it over a very long period of time, like definitely more than a month … probably many months,” George said.

Then they pounced. The Safe team has about 30 engineers, and a handful of them are “sys admins,” or system administrators. Sys admins are senior developers who are able to update Safe’s live website and code.

North Korean hackers targeted one admin in what was likely a phishing attack, George said, probably by tricking them into downloading an application or divulging personal info. The FBI has called the tactic North Korean hackers use “TraderTraitor.” George wouldn’t disclose any more details about how a Safe employee was tricked, citing an ongoing investigation.

Site update

After hackers duped the Safe system admin, they used their access to the person’s controls to download malware to the developer’s machine, which gave North Korea control over the admin’s computer, George said. From there, hackers updated Safe’s website with a snippet of code designed exclusively for Bybit, like a virus that activates when in contact with the right host.

In late February, the dormant code detected that a Bybit employee had opened its Safe account and was about to authorize a transaction. At the last moment, hackers swapped in a new command to drain Bybit’s crypto holdings. The employee unknowingly authorized the command, and North Korea was suddenly flush with $1.5 billion in crypto. Two minutes after the heist, Safe’s website was updated to hide the hackers’ tracks and erase the code snippet, according to a security investigation Bybit commissioned.

The investigation into how North Korea compromised a Safe developer’s computer is still ongoing, George told Coins2Day.

Goldberg, the CEO of Chaos Labs, told Coins2Day that the hack of Bybit is indicative of a broader problem in software. The vast majority of programmers use code from other programmers, who reference apps built by yet another batch of developers. “We’re building on houses of cards, and you know what you build,” he said. “You don’t know what’s going on underneath.”

Join us at the Coins2Day Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By Ben WeissCrypto Reporter
LinkedIn iconTwitter icon

Ben Weiss is a crypto reporter at Coins2Day.

See full bioRight Arrow Button Icon

Latest in Regulators

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
Economy
An unusual Fed ‘rate check’ triggered a free fall in the U.S. dollar and investors are fleeing into gold
By Jim EdwardsJanuary 26, 2026
15 hours ago
placeholder alt text
Politics
Trump was surging after the Venezuela raid—then came Jerome Powell, Greenland, and Minnesota. Now it feels like a ‘historic hinge moment’
By Jason MaJanuary 25, 2026
1 day ago
placeholder alt text
Personal Finance
Sweden abolished its wealth tax 20 years ago. Then it became a 'paradise for the super-rich'
By Miranda Sheild Johansson and The ConversationJanuary 22, 2026
4 days ago
placeholder alt text
North America
Gates Foundation plans to give away $9 billion in 2026 to prepare for the 2045 closure while slashing hundreds of jobs
By Sydney LakeJanuary 23, 2026
3 days ago
placeholder alt text
Success
Despite running $75 billion automaker General Motors, CEO Mary Barra still responds to ‘every single letter’ she gets by hand
By Preston ForeJanuary 26, 2026
10 hours ago
placeholder alt text
Success
'The Bermuda Triangle of Talent': 27-year-old Oxford grad turned down McKinsey and Morgan Stanley to find out why Gen Z’s smartest keep selling out
By Eva RoytburgJanuary 25, 2026
1 day ago

© 2026 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in Regulators

Changpeng Zhao looks of camera in front of blank wall.
RegulatorsBinance
Trump pardons Binance founder Changpeng Zhao 2 years after the crypto billionaire’s guilty plea
By Ben WeissOctober 23, 2025
3 months ago
RegulatorsDonald Trump
Exclusive: Senate Democrats demand top Trump advisor Steve Witkoff provide details on crypto investments, lack of divestment
By Ben WeissOctober 22, 2025
3 months ago
RegulatorsBitcoin
‘Bitcoin Jesus’ reaches $50 million deal with DOJ to dismiss tax evasion charges
By Ben WeissOctober 14, 2025
3 months ago
The CoinsBitcoin
Bitcoin zooms over $123,000 as crypto fans hail an ‘Uptober’ for the ages
By Leo SchwartzOctober 3, 2025
4 months ago
RegulatorsNew York
Top crypto regulator Adrienne Harris steps down from the New York Department of Financial Services
By Leo SchwartzSeptember 29, 2025
4 months ago
A man in a suit whispering to another man in a suit.
RegulatorsSecurities and Exchange Commission
Crypto hoarding brings a stock pop for small firms—and in some cases shows patterns of possible insider trading
By Ben WeissAugust 28, 2025
5 months ago