What was the detailed timeline of the largest hacking incident in crypto history?

Crypto hacking incident

The Bybit hack, the largest single hacking attack in crypto history, took place on February 21, 2025 (UTC). Total losses reached approximately $1.46 billion, including 401,347 ETH, 90,375 stETH, plus small amounts of cmETH and mETH. The FBI attributed the attack to North Korea’s Lazarus Group under its TraderTraitor sub-group.

1. Pre-attack Preparation

Hacker preparation

Around February 18, hackers deployed a malicious smart contract in advance to prepare for tampering with the logic of the multi-sig wallet contract. Bybit stored massive ETH assets in Safe multi-sig cold wallets, widely regarded as high-security offline storage in the industry. The multi-sig wallet required signatures from multiple administrators before transactions could be executed.

The hackers used a combination of supply-chain attack, social engineering and front-end UI tampering. They compromised devices belonging to Safe developers and injected malicious JS code into the signature page. Administrators saw a normal fund transfer UI on their computers. However, when they signed to confirm, their signatures were bound to the hacker’s pre-set malicious contract instead of the intended transaction.

2. Attack Timeline

Attack timeline

13:30 UTC: Bybit performed routine fund scheduling, planning to move ETH from the multi-sig cold wallet to a warm wallet, a regular operation for exchanges.
14:13 UTC: Administrators logged into the multi-sig page, checked transaction details and completed signature authorization. Although the UI looked normal, the signature triggered the hacker’s pre-deployed malicious contract. The multi-sig wallet contract logic was upgraded and tampered. Hackers gained permission to transfer all funds out and split stolen assets into 39 separate wallet addresses to prepare for money laundering later.
15:44 UTC: The platform detected abnormal fund movement. CEO Ben Zhou released an emergency statement on social media, confirming unauthorized withdrawals from one ETH cold wallet and announcing the theft.

3. Aftermath of the Incident

Market panic

Market panic spread quickly. ETH dropped sharply, many users rushed to submit withdrawal requests. Over 170,000 traders were liquidated within 24 hours. The incident challenged the long-held belief that cold wallets plus multi-signature were absolutely secure.

The exchange promised full compensation for all user assets. Bybit stated customer funds would not be lost. It used internal capital and loans to fill the gap and kept withdrawal channels running to ease bank-run pressure.

4. Asset Laundering & Industry-wide Reforms

Crypto security upgrade

Hackers split stolen funds across numerous addresses. They used DEXs, cross-chain bridges and mixers to swap, transfer and obfuscate fund trails. Most stolen assets have not been recovered to this day.

Major exchanges and on-chain security firms shared blacklisted addresses to track hacker capital and cooperated with the FBI for investigations. Safe and other multi-sig wallet providers immediately audited front-end code. Top exchanges upgraded multi-sig signing workflows, added more validation checks and isolated signature pages.

Key takeaway: This attack did not crack private keys. Instead, front-end UI deception plus contract upgrade loopholes tricked administrators into signing malicious transactions unknowingly. This shocked the whole industry: even offline multi-sig cold wallets can be compromised during signature phase via supply-chain attacks.