Bybit’s $1.5 Billion Hack: How North Korea’s Lazarus Group Stole the Spotlight

By ETHNews
about 23 hours ago
ONE BEN ZACH AXS BILL
  • ZachXBT identified Lazarus through blockchain analysis, revealing their signature in Bybit’s Ethereum wallet breach.
  • Lazarus has a history of crypto attacks, including Axie Infinity ($617M) and Harmony Horizon ($100M), using advanced techniques.

On February 21, 2025, the cryptocurrency industry was rocked by shocking news: the crypto exchange Bybit suffered what has been labeled the largest hack in the sector’s history, with an estimated loss of nearly $1.5 billion in tokens.

Arkham Intelligence, announced via its X account that the mystery behind this massive attack had been solved thanks to the work of renowned on-chain investigator ZachXBT.

In a post published at 20:21 UTC, Arkham detailed that ZachXBT provided definitive evidence identifying the Lazarus Group, linked to the North Korean government, as the perpetrator behind the hack on Bybit’s Ethereum wallet.

The hack, described by Bybit CEO Ben Zhou, involved unauthorized access to an offline wallet, allowing the attackers to transfer assets worth approximately $1.46 billion in a series of suspicious transactions.

Arkham, which had previously offered a bounty of 50,000 ARKM (equivalent to over $30,000) to identify those responsible, shared ZachXBT’s findings with the Bybit team to support their investigation.

The evidence presented by ZachXBT included a detailed analysis of test transactions, connected wallets, and forensic graphs that revealed the distinctive “fingerprint” of the Lazarus Group on the blockchain—a signature previously associated with attacks on other crypto platforms.

The Lazarus Group, known for its ties to North Korea’s military intelligence, has a history of high-profile cyberattacks in the crypto space, including the theft of $617 million in the Axie Infinity hack of 2022 and the $100 million attack on Harmony Horizon.

According to reports from ETHNews analysts and outlets like BleepingComputer and Bloomberg, the group has exploited the anonymous nature of crypto transactions to move large sums without leaving a trace, using techniques such as private key theft and cryptocurrency mixing services. This pattern was repeated in the Bybit case, where the attackers exploited vulnerabilities to access funds and disperse them quickly.

The resolution of the case by ZachXBT, described by the X community as a “legendary” figure in his field, sparked a wave of reactions on social media. Users like JulbyJuli.eth, David Owens, and others celebrated his work, while some speculated about the geopolitical implications, even joking about potential extreme responses against North Korea.

However, ZachXBT and other experts, such as Coinbase’s Conor Grogan, emphasized that the involvement of a state actor like Lazarus complicates recovery efforts, as nations can operate outside the reach of traditional international laws.

The post Bybit’s $1.5 Billion Hack: How North Korea’s Lazarus Group Stole the Spotlight appeared first on ETHNews.

Related News