ZachXBT: crypto exchange Bybit has experienced $1.46B worth of “suspicious outflows”; Bybit CEO confirms hacker took control of a cold ETH wallet
Cryptocurrency exchange Bybit has experienced $1.46 billion worth of “suspicious outflows,” according to blockchain sleuth ZachXBT.
CoinDeskOliver Knight
Context & Ripple Effects
The initial alert established that the incident involved an exchange-controlled cold ETH wallet, not merely anomalous customer activity. Follow-on coverage confirmed the wallet compromise and put the token loss at roughly $1.5 billion in Bybit's account of the cold-wallet breach.
The episode quickly became a test of whether an exchange could retain user confidence after a custody failure: subsequent data described more than $4 billion in withdrawal activity following the hack. Later reporting tied the attack to compromised transaction-handling infrastructure at wallet provider Safe, sharpening the supply-chain dimension of the incident.
First-order effects
Bybit must contain the compromised wallet, reconcile affected assets, and demonstrate that remaining customer funds and withdrawal operations are secure.
Customers face an immediate custody-confidence decision; the reported outflows create pressure on Bybit to communicate reserves, security controls, and incident response clearly.
Second-order effects
A surge in withdrawals can turn a security breach into a liquidity-management problem, raising the operational burden on Bybit even apart from the stolen assets.
Other exchanges and wallet providers face pressure to review transaction-signing workflows and third-party dependencies after reporting on malicious code at a provider used by Bybit.
Third-order effects
If major exchange breaches repeatedly trigger rapid withdrawals, custody security and transparent operational controls become more central competitive differentiators for centralized crypto platforms.
The incident reinforces the crypto legitimacy gap: confidence in on-chain assets does not eliminate reliance on the security practices of exchanges and their infrastructure partners.
The trend: Crypto markets are increasingly treating exchange security incidents as ecosystem-wide custody and infrastructure-risk events rather than isolated platform failures.
Bybit ETH multisig cold wallet just made a transfer to our warm wallet about 1 hr ago. It appears that this specific transaction was musked, all the signers saw the musked UI which showed the correct address and the URL was from @safe . However the signing message was to change
Bybit detected unauthorized activity involving one of our ETH cold wallets. The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing
@safe Bybit Hot wallet, Warm wallet and all other cold wallets are fine. The only cold wallet that was hacked was ETH cold wallet. ALL withdraws are NORMAL.
Bybit immediately processing withdrawals by the way. Which is good to see. The really shitty thing about crypto is there is one open and permanent bug bounty on everything.
We are aware of the situation currently evolving with Bybit and are continuing to monitor developments. As a reminder: all spot assets backing USDe are held in off exchange custody solutions, including ByBit via Copper Clearloop for this precise reason. Not a single dollar of
There are two scenarios 1. You can't just wash 1.5 BILLION dollars - Funds are returned for a bounty fee 2. Bybit has to buy back 1.5 BILLION ETH [image]
No one can disappear with $1.5B With $1.5B, you're among top 2,000 richest people in the world They may be smart for hacking Bybit, but the amount they're holding is massive Don't worry. They'll likely take a bounty and return the rest
JUST IN: Bybit CEO confirms the crypto exchange has been hacked, $1.4 billion $ETH and $stETH stolen. This is now the largest crypto exchange hack in history. [image]
Bybit appears to be processing withdrawals just fine after their hack They have $20B+ in assets on platform and their cold wallets are untouched. Given the isolated nature of the signing hack, and how well capitalized Bybit is, I don't expect there to be contagion [image]
If you want my serious take 1. Bybit has way more than 1.4b of revenue per year. They are good for the money and will make all customers whole. 2. It doesn't matter for ETH because Bybit will honor customers's ETH liabilities and buy back the assets on open market.
some people concerned about Ethena's 21% of funds potentially exposed to bybit. but its worth noting that (at least according to ethena), they dont keep collateral on the exchange but rather with a third party custodian and do periodic settlements of pnl. [image]
Seems that @Bybit_Official hot wallet just got hacked. Though, it's a multi-sign $1.5B worth of $ETH was withdrawn to the new address and is currently being sold More info below ⬇️ [image]