Here’s the part that should keep you up at night: as far as anyone can tell, nobody at Bybit did anything careless. No one clicked a dodgy link or reused a password. They followed their own security rules to the letter — and lost $1.5 billion anyway. That’s the story worth understanding, because it’s the one that could happen to careful people, which is most of us.
Let me admit where this hits home for me. I’m the sort who sends a tiny test transaction before a big one and double-checks an address so many times my family teases me for it. That habit was born of a small fright years ago — a near-miss that cost me nothing but a cold sweat and taught me to trust nothing on a screen at face value. The Bybit hack is that lesson written in nine figures.
How do you rob a vault without touching the lock?
On 21 February 2025, Bybit — a Dubai-based exchange and the world’s second-largest by trading volume moved some Ethereum from cold storage. Routine stuff. Except the transfer was anything but.
The thieves never broke into Bybit directly. Instead, days earlier, they’d quietly compromised Safe{Wallet} — the third-party multi-signature software Bybit leaned on – by getting into a developer’s machine and swapping a harmless piece of the code for a malicious one on 19 February, two days ahead of time, aimed squarely at Bybit’s cold wallet. So when Bybit’s team looked at their screens and approved what appeared to be an ordinary transfer, the tampered code was quietly redirecting the money to the attackers. They walked out with roughly $1.5 billion — the largest crypto theft in history by a distance.
Trust the screen, lose the money
This is where it gets genuinely instructive, so stay with me. Bybit used a multi-signature wallet — several people must approve a transfer, precisely so one compromised person can’t drain it. Sensible. But here’s the flaw the hackers exploited, and it has a name: blind signing. If the interface everyone is looking at has been tampered with, every signer sees the same lie. Adding more approvers doesn’t help when they’re all reading the same doctored screen. You can hold the keys perfectly and still authorise your own robbery, simply because you trusted what the display told you.
Zoom out, and this isn’t really a crypto problem at all — it’s a supply-chain problem. The attackers didn’t beat Bybit’s defences; they slipped in through a supplier Bybit trusted. It’s the same shape as the SolarWinds attack that rattled governments and blue-chip firms back in 2020: get into one trusted vendor, and you inherit the trust of everyone who relies on them. Your own front door can be bolted shut while the intruder strolls in through your plumber’s van. In a connected system, your security is only ever as strong as the weakest link you’ve quietly decided to trust.
Where the money went
The FBI formally attributed the theft to North Korea, naming a state-backed crew it tracks as TraderTraitor — part of the notorious Lazarus Group. And these people are frighteningly good at the getaway. Within days, the bulk of the loot had been converted from Ethereum into Bitcoin, run through mixers designed to scramble the trail, and scattered across thousands of wallets. Bybit stood up a $140 million recovery bounty and rallied half the industry to help chase it. It barely dented the outcome: only around $42 million — roughly 3.5% — was ever frozen. Most of it went dark.
Two things sit under this that are bigger than one exchange. First, the sting is softened by a detail I’ll happily give Bybit credit for: it stayed solvent, covered its customers out of its own pocket, and actually kept growing. The users were made whole; the company took the hit. Second, the part that isn’t reassuring at all — this wasn’t ordinary crime. Across 2025, North Korea-linked hackers stole more than $2 billion in crypto, with Bybit alone making up roughly three-quarters of it, and those proceeds reportedly helped fund the regime’s weapons programmes. This is geopolitics wearing a hoodie.
How I read it
I read this as the strongest possible argument for a boring discipline: assume the screen can lie, and verify anyway. The uncomfortable truth is that in any system built on layers of trust, you can be careful and still be exposed by someone else’s slip three doors down the supply chain. That’s not a reason to panic — panic is how people make the next mistake — it’s a reason to understand where your trust actually sits, and to keep the sensible habits that feel excessive right up until the day they save you. I still sent the tiny test transaction. I still triple-check the address. Call it paranoia; I call it cheap insurance.
This is me thinking out loud in your company, not security or financial advice. If you’re holding anything that matters, learn how it’s actually secured — properly, from a trustworthy source.
The Jacqueline Brand — knowledge builds confidence, confidence builds wealth. This is editorial commentary for inspiration, not financial or professional advice. Always do your own research. The Collection
© 2026 TheJacquelineBrand. All rights reserved. Please do not reproduce or republish without written permission.


