Sitemap

The Bybit Hack 2025: Lessons Learned

6 min readJul 26, 2025

--

The DeFI Space continues to grow from the final quarter of 2024 as Bitcoin continues to break records while adoption peaking towards an expected 500 million users as the New Year comes along. Just when all signs are on the up, this romantic story has to be shaken by another unprecedented security breach with Bybit suffering a major hack. The incident dubbed “The Billion — Dollar heist” not only was on major headlines but also highlighted security issues within the DeFI Space. Let’s look at the Bybit Hack 2025 and lessons learned from it!

How does the Breach Unfold?

With every Bitcoin Boom that happens in the DeFI Space, new innovations always come around as plenty of enthusiasts always look to seize on the opportunity. Founded in 2018 by Ben Zhou, Bybit emerged as a cryptocurrency derivatives exchange that aims to provide a professional trading platform with an emphasis on speed, reliability, and user experience. Initially focusing on perpetual contracts, Bybit quickly gained traction among traders seeking alternatives to existing platforms.

Sharing its origins with another leading exchange Binance in 2018, Bybit’s ascent was marked by strategic expansions and feature enhancements. Its commitment to innovation and user-friendly platform facilitated the rapid growth, positioning it as a notable player in the DeFI Space. Bybit’s user base grew quickly by the bull run of 2020 and 2021, due to its community-building strategies, hosting global trading competitions and educational webinars that cultivated loyalty and trust among its users.

By 2025, Bybit had established itself as the world’s second-largest cryptocurrency exchange by trading volume, serving a global community of over 60 million users and listing over 400 digital assets . Its user base spanned various regions, with significant adoption in emerging markets like Nigeria and South Africa. The platform boasts a daily trading volume often exceeding $10 billion at peak times.

Its global footprint now spans multiple jurisdictions, including a presence in Dubai, where it established a regional headquarters in 2023, signaling its commitment to regulatory compliance and international expansion. The Exchange also successfully diversified its platform offering services for more than 650 digital assets across various markets while its commitment to excellence has been recognized by Global Finance Magazine “Best Crypto Exchange UAE 2025”.

Security has also been a cornerstone in Bybit’s operations such as two — factor authentication and cold wallet storage system while institutional investors receive dedicated security teams providing 24/7 alert and support. The platform also introduced an AI — driven risk engine that helps authenticate deposit and withdrawal requests from suspicious activities or users which has been successful in preventing more than $79 Million in losses.

Press enter or click to view image in full size
Source: https://www.aa.com.tr/en/economy/hack-attack-steals-14b-from-crypto-exchange-bybit/3489513

Despite this growth and robust security protocols, Bybit had to face a significant challenge in its progression when a security breach occurred on 21st February 2025. Dubbed the “Billion-Dollar Heist”, the theft resulted in more than $1.5 Billion worth of Ethereum and related assets being lost from user funds. This incident definitely caught attention as the biggest hack in DeFI history beating the previous Ronin Network Hack in March 2022.

The breach was then first detected by on — chain investigator ZachXBT, who observed significant outflows from Bybit’s platform that may be considered suspicious on February 21st. Shortly thereafter, blockchain security firms SlowMist and PeckShield confirmed the breach, noting that Bybit was experiencing unprecedented fund withdrawals.The attacker allegedly compromised the Safe Wallet AWS infrastructure.through the use of malicious code and social engineering.

Investigations revealed that on the day of the incident, the digital wallet address where 401,000 Ethereum was supposed sent to is altered and ByBit thought it was then transferring the funds to its own digital wallet, but instead sent it all to the attackers.Two minutes following the malicious transaction, the attackers removed the malicious code from Safe{Wallet}’s web interface, presumably to cover their track.

This hack was in general different from previous incidents such as the Ronin Network in 2022 or MT. Gox in 2014 which targets vulnerabilities in its own internal systems instead it targets the 3rd party Safewallet AWS Infrastructure. Two previous high-profile incidents that may show some resemblance to the Bybit heist are the WazirX heist (July 2024, $230M loss) and the Radiant Capital heist (October 2024, $50M loss). This sophisticated approach ultimately allowed them to bypass traditional security measures and execute the heist without immediate detection.

In the aftermath, Bybit took swift action to address the breach. The company conducted multiple security audits and implemented over 50 new security measures such as biometric verification, multi-channel verifications, and a One-Click Account Freeze feature to prevent future incidents. The company partnered with Zodia Custody to enhance asset security for institutional clients.

Additionally, Bybit collaborated with industry experts to trace the stolen assets and launched a recovery bounty program, offering up to 10% of the recovered amount to individuals who assist in retrieving the stolen funds. Ultimately this incident served as the telling to the DeFI Space that despite the progress and growth that have been made throughout the years, there are still vulnerabilities and room for improvement in the years to come!

Looking Ahead…..

This unprecedented and unexpected breach has provided several critical lessons for the DeFI Space to evolve in the future, emphasizing the need for enhanced security measures and proactive risk management. One of the most highlighted is the traditional belief that cold wallets are impenetrable and far more secure than hot wallets. This incident proves that even cold wallets are not immune to sophisticated attacks, particularly those involving social engineering and UI manipulation as deceiving signers can be tricked into authorizing malicious transactions.

Though Cold Wallets are still the most secure storage within the DeFI Space, it also highlights the critical need for rigorous security assessments and continuous monitoring of third-party services and dependencies, as vulnerabilities in external components can have cascading effects on overall platform security which in this case Bybit. The sophistication of the incident highlights the evolving nature of cyber threats and platforms must implement continuous monitoring systems, conduct regular security audits, and foster a culture of security awareness.

Bybit’s swift acknowledgment of the breach and immediate communication with stakeholders also needs to be applauded during the whole crisis. This approach was pivotal in helping control public outburst while promptly collaborating with cybersecurity firms and law enforcement agencies to investigate the incident and initiated efforts to recover the stolen assets. It’s crucial to demonstrate the importance of transparent and timely responses in maintaining user trust and mitigating the impact of security breaches.

Finally, incidents and exploits from the past always result in the growth of security within the DeFI Space, this proves that additional verification mechanisms and independent validation steps within multi signature frameworks. The key is to always stay proactive and utilize whatever the security measures available within the DeFI Space because after all they are designed to protect your precious digital assets. For all of you Nagayanss out there, you can activate the newest addition on your Nagaya (S) Wallet which is “NGY Lock!”, a revolutionary security measure that will help protect your HODLing Journey!

Press enter or click to view image in full size
Source: https://www.nagaya.tech/post/stay-proactive-in-cybersecurity-with-ngy-lock

‘NGY Lock!’ acts as a shield to protect your NGY (BEP20) tokens from unauthorized outgoing transfers. Once activated, the NGY (BEP20) balance in your Nagaya (S) Wallet will be locked for the next 30 days to safeguard your HODLing experience. To further secure your Nagaya (BEP20) within your Nagaya (S) Wallet, cannot be deactivated anytime before the 30-day period is up. This feature is optional and available within your Nagaya (S) Wallet, for more information you can visit us at www.nagaya.co

Or you can download the Nagaya (S) Wallet app available on Google Play Store through the link below

https://play.google.com/store/apps/details?id=com.antpixel.NAGAYA

Let’s stay Proactive and Secure DeFI from Cyber Threats!

--

--

Nagaya Technologies
Nagaya Technologies

Written by Nagaya Technologies

NAGAYA (NGY) is a Gold-Backed Cryptocurrency with Subsidiary Projects. We aim to build Trust and Value through LEGALITY and TRANSPARENCY. https://nagaya.co/