Bybit theft: Hacker launders over 50% of stolen $1.4B in Ethereum

February 28, 2025 05:23 PM AEDT | By Invezz
 Bybit theft: Hacker launders over 50% of stolen $1.4B in Ethereum
Image source: Invezz

A hacker responsible for the $1.4 billion Bybit heist has laundered over 50% of the stolen Ethereum in just five days, pushing THORChain’s transaction volumes to record highs.

According to blockchain analytics firm Spot On Chain, the attacker moved 266,309 Ethereum (ETH), worth approximately $614 million, at an average rate of 48,420 ETH per day.

If this pace continues, the remaining 233,086 ETH could be fully laundered within the next five days.

The surge in illicit transactions has exposed vulnerabilities in decentralized finance (DeFi) protocols, as THORChain recorded an unprecedented $2.91 billion in transaction volume between Feb. 22 and Feb. 27.

The spike highlights how DeFi platforms can be exploited for large-scale money laundering, raising concerns over regulatory gaps in the crypto industry.

THORChain transaction volumes hit record

THORChain, a decentralised liquidity protocol, has become the primary channel for laundering the stolen Ethereum. Before the attack, THORChain’s average daily transaction volume stood at $80 million.

Since the hacker began moving funds, daily volumes have jumped to $580 million.

The most dramatic spike occurred on Feb. 26, when THORChain processed a record-breaking $859.61 million in swaps, followed by an additional $210 million on Feb. 27, bringing the two-day total past $1 billion.

This unprecedented increase has also generated significant profits for THORChain. The network earned $3 million in fees from the sudden surge in activity, underscoring the financial impact of illicit transactions on DeFi platforms.

The situation raises concerns about the ability of decentralised exchanges to detect and prevent large-scale laundering schemes.

FBI links hack to North Korea

The US Federal Bureau of Investigation (FBI) has officially linked the Bybit hack to North Korean state-sponsored cybercriminals.

In a statement released on Feb. 26, the FBI identified the attack as part of a broader cyber campaign known as “TraderTraitor,” which has been used to target cryptocurrency firms and financial institutions worldwide.

North Korean hacking groups, particularly Lazarus Group, have been linked to multiple high-profile crypto heists in recent years.

The funds stolen in such attacks are often used to finance the country’s weapons programme, making the Bybit hack not just a financial crime but a geopolitical concern.

The rapid laundering of stolen assets through DeFi platforms further complicates efforts to track and recover illicit funds, as decentralized protocols lack the oversight of traditional financial systems.

Attackers exploited the infrastructure provider

Forensic investigations by Sygnia Labs and Verichain have revealed that Bybit’s security infrastructure remained intact despite the breach.

Instead, the vulnerability was traced back to a Safe Wallet developer machine that had been compromised. Attackers exploited this weak link to inject malicious JavaScript code into the Gnosis Safe UI, targeting Bybit’s cold wallet.

This incident highlights a shift in hacker tactics. Rather than directly breaching exchanges, cybercriminals are increasingly targeting infrastructure providers that support major crypto platforms.

While Safe has affirmed that its smart contracts remain secure, the attack underscores the need for enhanced security across the entire crypto ecosystem, including wallet providers and third-party developers.

To mitigate the damage, Bybit has launched a website to track the movement of stolen funds. The exchange is also offering a bounty to any platform or individual who assists in recovering the assets.

With over half of the stolen Ethereum already laundered, the likelihood of full recovery is rapidly diminishing.

The post Bybit theft: Hacker launders over 50% of stolen $1.4B in Ethereum appeared first on Invezz


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Pty Ltd (“Kalkine Media, we or us”), ACN 629 651 672 and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide investment advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content.
Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media. Some of the images/music that may be used on this website are copyrighted to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have made reasonable efforts to accredit the source wherever it was indicated as or found to be necessary.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.


AU_advertise

Advertise your brand on Kalkine Media

Sponsored Articles


Investing Ideas

Previous Next
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.