Bybit Hack

REPORTED LOSS $1.5B
Critical Safe{Wallet} frontend injection, transaction masking, and delegatecall proxy implementation replacement Ethereum

What happened

On February 21, 2025, attackers used a compromised Safe{Wallet} web interface to obtain three valid signatures for a malicious transaction from Bybit's Ethereum cold-wallet Safe. The transaction replaced the Safe proxy implementation and drained 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH, valued by Bybit at $1.46 billion.

Technical Root Cause

A compromised trusted signing interface enabled transaction-data substitution and blind approval of a Safe delegatecall. The delegated helper overwrote the proxy's masterCopy storage slot, replacing the multisig implementation with attacker-controlled sweep logic.

Case & protocol details

Classification Multisig UI Compromise / Supply-Chain Phishing
Protocol Type CEX
Implementation language Solidity
Official Website www.bybit.com/
Protocol Twitter/X @Bybit_Official

How it happened

Forensic findings attribute the initial compromise to a Safe developer environment. Malicious JavaScript served through the Safe{Wallet} frontend altered the transaction data for Bybit's targeted cold wallet while presenting signers with what appeared to be a routine transfer to a warm wallet. Three signers therefore authorized an execTransaction whose operation was delegatecall, not an ordinary transfer.

The delegatecall invoked an attacker-controlled helper contract whose transfer(address,uint256) function wrote the Safe proxy's first storage slot. That slot holds the masterCopy implementation address. Pointing it to a second malicious implementation exposed sweepETH() and sweepERC20() functions, which drained the wallet.

Funds Recovery

2.9%

Recovered

$43.0M

Net Loss

$1,417,660,000

Post-Incident Timeline

  • 2025-02-23

    mETH Protocol recovered 15,000 cmETH ($43M) from the Bybit hack, thanks to its 8-hour withdrawal delay, which allowed the team to pause unauthorized withdrawals. The recovery was led by Mudit Gupta (Polygon’s CISO) and SEAL security team. Additionally, Tether froze $181,000 USDT, and Bybit confirmed bounties of $4.3M for the recovery team and $18,100 for Tether. Exchanges helped freeze $42.89M in stolen funds, making this one of the fastest large-scale recoveries.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.