/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An analysis of the $1.46B Bybit hack, by far the largest crypto heist of all time, ahead of Poly Network's $611M in 2021, and possibly the biggest theft ever

On February 21st 2025, approximately $1.46 billion in cryptoassets were stolen from Bybit, a Dubai-based exchange.

Elliptic

Context & Ripple Effects

The analysis follows reports of suspicious outflows from Bybit and confirmation that control of a cold Ethereum wallet had been compromised. It places the loss above Poly Network’s 2021 theft, making scale—not merely the incident itself—the central development.

A subsequent attribution claim tied the breach to North Korea’s Lazarus Group, connecting the event to earlier coverage of major crypto thefts involving North Korea-linked actors. The incident therefore tests whether exchanges’ custody protections are keeping pace with the value concentrated in their wallets.

First-order effects

  • Bybit faces an immediate custody-security and credibility crisis after the loss of roughly $1.46 billion in cryptoassets from a cold wallet.
  • The breach resets the benchmark for a single crypto theft, overtaking Poly Network’s $611 million incident and concentrating attention on the safeguards around exchange-held assets.

Second-order effects

  • Other exchanges and custody providers face pressure to reassess cold-wallet controls, approval processes, and incident-response readiness as customers compare counterparty risk.
  • Security researchers, blockchain-tracing firms, and law-enforcement partners gain a more consequential role in identifying and following stolen assets after the reported Lazarus attribution.

Third-order effects

  • If record-scale exchange breaches persist, crypto platforms’ ability to win mainstream trust will depend increasingly on demonstrable custody resilience rather than trading features alone.
  • The episode reinforces the crypto legitimacy gap: a market built around transferable assets remains exposed when a small number of institutional wallets concentrate exceptionally large balances.

The trend: The Bybit breach is a major data point in the continuing escalation of crypto-security risk, where increasingly valuable centralized custody pools attract sophisticated attackers.

Discussion

  • @joetidy @joetidy on bluesky
    Elliptic is following the money on this ByBit hack - the biggest theft ot all time.  “Within 2 hours of the theft, the stolen funds were sent to 50 different wallets, each holding approximately 10,000 ETH.  These are now being systematically emptied”. www.elliptic.co/blog/bybit-h…
  • @tomrobin Tom Robinson on x
    10% of the stolen assets have now begun to be laundered. Crypto exchange eXch appears to have knowingly aided Lazarus in swapping several tens of millions of dollars of this - despite pleas from Bybit The stolen assets are mostly being converted to Bitcoin - mixers next?
  • @tomrobin Tom Robinson on x
    The fantastic @elliptic team have been working around the clock to trace the $1.46Bn Bybit theft proceeds. This combined with our automated cross-chain tracing capabilities, is helping to counter the laundering efforts of NK's Lazarus Group. https://www.elliptic.co/...