Bybit Hack
What happened
On February 21, 2025, attackers used a compromised Safe{Wallet} web interface to obtain three valid signatures for a malicious transaction from Bybit's Ethereum cold-wallet Safe. The transaction replaced the Safe proxy implementation and drained 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH, valued by Bybit at $1.46 billion.
A compromised trusted signing interface enabled transaction-data substitution and blind approval of a Safe delegatecall. The delegated helper overwrote the proxy's masterCopy storage slot, replacing the multisig implementation with attacker-controlled sweep logic.
Case & protocol details
How it happened
Forensic findings attribute the initial compromise to a Safe developer environment. Malicious JavaScript served through the Safe{Wallet} frontend altered the transaction data for Bybit's targeted cold wallet while presenting signers with what appeared to be a routine transfer to a warm wallet. Three signers therefore authorized an execTransaction whose operation was delegatecall, not an ordinary transfer.
The delegatecall invoked an attacker-controlled helper contract whose transfer(address,uint256) function wrote the Safe proxy's first storage slot. That slot holds the masterCopy implementation address. Pointing it to a second malicious implementation exposed sweepETH() and sweepERC20() functions, which drained the wallet.
Funds Recovery
Recovered
$43.0M
Net Loss
$1,417,660,000
Post-Incident Timeline
-
2025-02-23
mETH Protocol recovered 15,000 cmETH ($43M) from the Bybit hack, thanks to its 8-hour withdrawal delay, which allowed the team to pause unauthorized withdrawals. The recovery was led by Mudit Gupta (Polygon’s CISO) and SEAL security team. Additionally, Tether froze $181,000 USDT, and Bybit confirmed bounties of $4.3M for the recovery team and $18,100 for Tether. Exchanges helped freeze $42.89M in stolen funds, making this one of the fastest large-scale recoveries.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Report x.com
- analysis Twitter/X Alert x.com
- analysis Website reference beincrypto.com
- analysis Website reference theblock.co
- analysis Website reference crypto.news
- analysis Bybit Security Incident: Timeline of Events and FAQs bybit.com
- analysis Bybit Incident Technical Analysis certik.com
- analysis In-Depth Technical Analysis of the Bybit Hack nccgroup.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.