← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] One Year After Bybit: Crypto's Security Crisis Deepens

Zephyra|February 22, 2026|BPF
EXECUTIVE SUMMARY

On February 21, 2025, North Korea's Lazarus Group executed the largest digital heist in history — $1.5 billion drained from Bybit through a compromised Safe{Wallet} developer machine. Today marks the one-year anniversary. The question the industry should be asking is not whether it has recovered,...

"88.87% of the stolen assets remain traceable… but 27.6% of the hacked funds are now untraceable." — Ben Zhou, CEO, Bybit

Executive Summary

On February 21, 2025, North Korea's Lazarus Group executed the largest digital heist in history — $1.5 billion drained from Bybit through a compromised Safe{Wallet} developer machine. Today marks the one-year anniversary. The question the industry should be asking is not whether it has recovered, but whether it has learned anything at all.

The answer, measured in dollars, is no. In January 2026 alone, $370 million was stolen through crypto hacks and phishing attacks — a 214% increase from December 2025. Physical attacks on crypto holders jumped 75% year-over-year. France has become the kidnapping capital of crypto, with eleven wrench attacks recorded in the first seven weeks of 2026 alone, including a failed home invasion targeting Binance France's CEO. Meanwhile, North Korea's cumulative crypto theft since 2017 now exceeds $6.75 billion, and United Nations monitors estimate that stolen cryptocurrency constitutes approximately 13% of the nation's GDP — directly funding its nuclear weapons and ballistic missile programs.

The Bybit hack was supposed to be a watershed moment. One year later, it looks more like a data point on an accelerating curve.

Table of Contents

  1. The Bybit Hack: Anatomy of a $1.5 Billion Failure
  2. The Recovery Scorecard: What Happened to the Money
  3. January 2026: The Numbers Get Worse
  4. North Korea Inc.: Crypto as State Revenue
  5. The Physical Threat Dimension
  6. What Changed (and What Didn't)
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Bybit Hack: Anatomy of a $1.5 Billion Failure

The Bybit breach was not a smart contract exploit. It was not a flash loan attack. It was not even a phishing email sent to an exchange executive. It was something far more unsettling: a supply-chain compromise of Safe{Wallet}, the multisignature wallet infrastructure that hundreds of DAOs, protocols, and institutions rely on to secure billions in digital assets.

The Lazarus Group compromised a Safe developer's machine, gaining access to Safe's AWS infrastructure and injecting malicious JavaScript into the frontend code. The attack was surgically precise — the malicious code was designed to activate only when Bybit's specific multisig address interacted with the UI. When Bybit's signers executed what appeared to be a routine Ethereum cold wallet transfer, they were actually approving a contract upgrade that transferred ownership of 401,347 ETH (approximately $1.5 billion) to the attacker.

The attack exposed fundamental assumptions the industry had taken for granted:

  • Multisig is only as secure as its weakest signer interface. Bybit's multisig required multiple signatures, but all signers used the same compromised Safe{Wallet} frontend. The cryptographic security of the multisig was irrelevant because the transaction being signed had already been altered.

  • No Subresource Integrity (SRI) checking was in place. Safe{Wallet} did not implement SRI hashing to detect modified frontend code. There was no real-time alerting mechanism to flag unauthorized edits.

  • Off-chain validation was absent. None of the signers independently verified the transaction payload against the actual on-chain contract call. The human layer trusted the UI completely.

These were not exotic vulnerabilities. They were basic operational security failures — the kind that a well-funded, state-level adversary is designed to exploit.

The Recovery Scorecard: What Happened to the Money

Bybit's crisis response was widely praised. CEO Ben Zhou went live on X within 90 minutes, hosted a two-hour livestream, and launched a $140 million bounty program within 24 hours. By February 24, 2025 — just 72 hours after the hack — Bybit had replenished its reserves by securing 447,000 ETH through emergency funding from Galaxy Digital, FalconX, and Wintermute.

But replenishing reserves is not the same as recovering stolen funds. One year later, the recovery picture is sobering:

| Metric | Status | |--------|--------| | Total stolen | ~$1.5 billion (401,347 ETH) | | Currently traceable | 72.4% | | Successfully frozen | 3.54% | | Gone dark / untraceable | 27.6% | | Bounty reports received | 5,000+ | | Valid bounty reports | 63 |

The stolen 500,000 ETH were rapidly converted into approximately 12,836 BTC spread across 9,117 wallets. The Lazarus Group employed a sophisticated laundering playbook: Bitcoin mixers, cross-chain bridges, peer-to-peer OTC trades, and privacy-focused protocols. Within 48 hours, $160 million had been funneled through illicit channels. By February 26, 2025, over $400 million had been moved.

The uncomfortable truth: despite the industry's best tracking tools — Chainalysis, TRM Labs, Elliptic — and the coordinated efforts of exchanges, law enforcement, and the FBI, the vast majority of the funds remain in North Korean hands. The 3.54% freeze rate represents a recovery of roughly $53 million out of $1.5 billion. That is a 96.5% success rate for the attacker.

January 2026: The Numbers Get Worse

If the Bybit hack was supposed to catalyze an industry-wide security reckoning, the January 2026 data suggests the opposite occurred. According to blockchain security firm CertiK, attackers stole approximately $370 million in cryptocurrency in January 2026 — the highest monthly loss in 11 months and a 214% increase from December 2025.

The breakdown reveals a structural shift in attack methodology:

| Category | January 2026 Losses | |----------|-------------------| | Protocol hacks (16 incidents) | $86.01 million | | Phishing attacks | $311.3 million | | Total | $370.3 million |

The headline number is driven by phishing, not code exploits. On January 10, 2026, a single individual lost $282 million in Bitcoin and Litecoin to a phishing attack — the largest individual phishing loss in cryptocurrency history. This is not a protocol failure. It is a human failure, enabled by an ecosystem that has optimized for composability and speed at the expense of user protection.

The broader 2025 statistics provide context: total crypto theft reached $3.4 billion across the year, with North Korea responsible for $2.02 billion (59% of all stolen crypto globally). Contract exploits accounted for 64% of all hacks, with total protocol exploit damage reaching $861.54 million — a 36% increase in the second half of 2025.

Early 2026 data suggests the pace is accelerating, not decelerating.

North Korea Inc.: Crypto as State Revenue

The geopolitical dimension of crypto security is no longer theoretical. North Korea has transformed cryptocurrency theft into a primary state revenue stream, and the scale now constitutes a national security threat to multiple countries.

Key figures from 2025:

  • $2.02 billion stolen by DPRK-linked actors — a 51% increase from 2024's $1.3 billion
  • 76% of all exchange compromises attributed to North Korean threat actors
  • $6.75 billion cumulative crypto theft since 2017
  • ~13% of GDP now derived from stolen cryptocurrency, according to UN monitors

The Lazarus Group's operational sophistication continues to evolve. The majority of 2025's major hacks were perpetrated through social engineering rather than technical vulnerability exploitation. North Korean IT workers are increasingly embedded inside crypto services — exchanges, custodians, and Web3 firms — to gain privileged access and enable high-impact compromises from within.

This is no longer cybercrime in the traditional sense. It is state-sponsored economic warfare, with the cryptocurrency industry serving as both the target and the unwitting financier of a nuclear weapons program. The 38 North research institute described the transformation in January 2026 as North Korea evolving "from digital kleptocracy to rogue crypto-superpower."

The Physical Threat Dimension

While the industry debates smart contract audits and multisig configurations, a parallel security crisis is unfolding in the physical world. So-called "wrench attacks" — physical violence aimed at coercing crypto holders into surrendering private keys — jumped 75% year-over-year, with 72 confirmed incidents worldwide in 2025.

The violence has escalated dramatically in early 2026:

  • 11 wrench attacks recorded in the first seven weeks of 2026, according to Jameson Lopp's tracker
  • France has emerged as the global epicenter, with 19 reported attacks — more than double the United States
  • Physical assaults increased 250%, including home invasions, kidnappings, and three murders
  • Organized crime is increasingly targeting known crypto holders, with criminals targeting family members to compel cooperation

On February 12, 2026, three masked assailants targeted Binance France CEO David Prinçay in a failed home invasion in the Paris suburbs. The attack was linked to a broader pattern: a French tax agency employee was caught providing crypto investors' identities to criminal networks, and Waltio, a crypto tax reporting service, was hacked in January 2026, exposing user data.

Europe now accounts for over 40% of all physical crypto attacks globally, up from 22% in 2024. The convergence of on-chain transparency (making wealth visible), inadequate privacy infrastructure, and data breaches at tax and compliance services has created a target-rich environment for violent criminals.

What Changed (and What Didn't)

One year after Bybit, the industry's response can be categorized into three tiers:

What improved:

  • Multisig wallet providers have adopted cryptographic code signing and Subresource Integrity (SRI) checking
  • Cloud Security Posture Management (CSPM) tools are now standard for detecting unauthorized infrastructure access
  • The multisig wallet market has grown to $1.27 billion and is projected to reach $4.37 billion by 2033 (15% CAGR)
  • Institutional custody solutions increasingly require multiple independent custody providers to eliminate single points of failure

What stayed the same:

  • Social engineering remains the dominant attack vector — the Lazarus Group's primary weapon
  • No major exchange has implemented mandatory off-chain transaction verification for large transfers
  • The industry still relies on post-hack forensics (Chainalysis, TRM Labs) rather than pre-hack prevention
  • Recovery rates remain negligible — the 3.54% freeze rate on Bybit funds is representative

What got worse:

  • Total theft volumes are accelerating ($370M in January 2026 alone)
  • Phishing losses now dwarf protocol exploits ($311M vs. $86M in January 2026)
  • Physical attacks are escalating at an alarming rate (75% YoY increase)
  • State-sponsored actors are embedding operatives inside crypto companies
  • Data breaches at tax and compliance services are creating physical security risks

The economic value framework reveals a stark imbalance: the industry spends billions annually on protocol audits, bug bounties, and smart contract security, while the actual attack surface has shifted to human psychology, supply-chain infrastructure, and physical coercion. The security investment thesis is misallocated.

Key Takeaways

  • The Bybit hack's one-year anniversary is not a milestone of recovery — it is a benchmark of continued failure. Only 3.54% of the $1.5 billion has been frozen. North Korea retains the vast majority of the funds.

  • Crypto security is getting worse by every measurable metric. January 2026 saw $370 million stolen (214% increase from December 2025), physical attacks are up 75%, and state-sponsored theft now exceeds $2 billion annually.

  • The attack surface has fundamentally shifted. Phishing and social engineering now account for more losses than protocol exploits. The industry's security investment — concentrated on smart contract audits — is aimed at yesterday's threat model.

  • North Korea has industrialized crypto theft. At $6.75 billion cumulative and ~13% of GDP, cryptocurrency theft is now a core component of the DPRK's economic model and weapons program financing.

  • Physical security is the industry's blind spot. The convergence of on-chain wealth transparency, compliance data breaches, and inadequate privacy infrastructure has created an accelerating physical threat to crypto holders and executives.

Conclusion

The Bybit hack was supposed to be the industry's wake-up call. One year later, the alarm is still ringing and nobody is getting out of bed.

The cryptocurrency industry has spent the past twelve months debating fee switches, Layer 2 economics, and stablecoin regulation — all legitimate topics. But the foundational question remains unanswered: how does an industry that aspires to manage trillions in value secure itself against adversaries that range from nation-states to street criminals?

The current trajectory is unsustainable. When a single state actor can steal $2 billion in a year with a 96.5% success rate, when phishing attacks drain $311 million in a single month, and when crypto executives are being kidnapped in their homes, the industry is not facing a security challenge. It is facing an existential credibility problem.

The security investment thesis needs to be inverted. Less money on auditing immutable code. More money on securing the mutable humans who interact with it. Until the industry makes that shift, the Bybit hack anniversary will not be a turning point — it will be a recurring reminder of what $1.5 billion in lessons failed to teach.

Sources & References

  1. Chainalysis — 2025 Crypto Theft Reaches $3.4 Billion — Comprehensive analysis of 2025 crypto theft statistics and DPRK attribution
  2. TRM Labs — The Bybit Hack: Following North Korea's Largest Exploit — Detailed blockchain forensics on Bybit fund movements
  3. NCC Group — Bybit Hack: In-Depth Technical Analysis — Technical breakdown of the Safe{Wallet} supply-chain attack
  4. 38 North — From Digital Kleptocracy to Rogue Crypto-Superpower — Analysis of North Korea's evolution as a state-level crypto threat actor
  5. CoinDesk — Crypto Crime Is Getting Violent: Wrench Attacks Jumped 75% — Data on physical attacks targeting crypto holders
  6. CryptoImpactHub — January 2026's Crypto Hack Epidemic: $370 Million Stolen — January 2026 theft statistics and phishing dominance
  7. Cryptopolitan — France Earns Crypto Kidnapping Capital Title — Physical security crisis in France and Europe
  8. CryptoNinjas — Bybit CEO Confirms 27.6% of Hacked Funds Still Untraceable — Ben Zhou's recovery update and traceability statistics
  9. CSIS — The Bybit Heist and the Future of U.S. Crypto Regulation — Geopolitical and regulatory analysis of the Bybit breach
  10. Cyfrin — Bybit's $1.4B Heist: The Safe Wallet Hack That Changed Everything — Security analysis of Safe{Wallet} vulnerabilities and post-hack improvements
  11. DL News — Why Wrench Attacks Continue to Rock Crypto Industry — Analysis of early 2026 physical attack trends
  12. NBC News — North Korea Stole Billions in Crypto in 2025 — DPRK theft figures and weapons program financing