Trending

Who Are the Lazarus Group Hackers? Unveiling the Mystery Behind Bybit’s $1.4B Breach

Bybit's $1.4B crypto heist, attributed to North Korea's Lazarus Group, exposes critical vulnerabilities in exchange security protocols.
Published by
Who Are the Lazarus Group Hackers? Unveiling the Mystery Behind Bybit’s $1.4B Breach

Highlights

  • The $1.4 billion theft from Bybit stands as one of the largest in cryptocurrency history, surpassing previous high-profile breaches.
  • The notorious Lazarus Group, linked to North Korea, has been identified as the mastermind behind the Bybit hack, continuing their history of significant cybercrimes
  • This incident underscores the pressing need for enhanced security measures across cryptocurrency exchanges to protect against sophisticated cyber threats.

On February 21, 2025, a $1.4 billion breach struck Bybit, a major player in the cryptocurrency exchange sector, alarming the entire industry. Blockchain investigator ZachXBT quickly identified the Lazarus hacker Group, the infamous state-sponsored hacking team from North Korea, as the culprits behind the scheme. Regarded as the biggest cryptocurrency heist in history, this breach has brought the elusive Lazarus Group back into the spotlight. So, who are these cyber criminals, and how did they capture such a huge bounty? Let’s unravel the puzzle of Bybit’s hack and peek behind the curtain at this mysterious.

Advertisement

The Bybit ‘s Lazarus Group Hackers Incident: A Masterclass in Cybercrime

The Bybit’s hack occurred with unsettling accuracy. Bybit’s Ethereum (ETH) cold wallet—allegedly an extremely secure offline storage solution—was breached during a routine transfer to a warm wallet. Hackers deceived Bybit’s team by disguising a malicious transaction as legitimate, modifying the smart contract rules to gain control.

In an instant, 401,347 ETH (valued at over $1.4 billion) disappeared into a network of wallets. Ben Zhou, CEO of Bybit, quickly assured users that the exchange is solvent, with all customer funds supported 1:1, but the harm was done—both financially and to the sector’s credibility.

ZachXBT, a famous blockchain investigator, solved the case thoroughly. His proof—trial transactions, wallet associations, and forensic timestamps—connected the theft to the Lazarus Group, a name associated with crypto chaos.

Source: @zachxbt

Arkham Intelligence, which placed a $50,000 reward for information on the attackers, validated ZachXBT’s discoveries within hours, solidifying Lazarus group as responsible in this extraordinary hack.

Advertisement

Who Are the Lazarus Group?

The Lazarus Group is not just any other average band of hackers—it’s a powerhouse backed by North Korea’s Reconnaissance General Bureau. Since emerging around 2007, they’ve sharpened their skills over nearly 20 years, mixing spying, cash grabs, and global chaos. Nicknames like APT38 and TraderTraitor only hint at their operation.

Their resume reads thrillers—think the 2014 Sony Pictures takedown and the 2016 Bangladesh Bank attack, pocketing $81 million.

In crypto, they’re infamous heavyweights. They’ve raked in billions, including:

  • Ronin network heist (March 2022): Snagged $620 million from Axie Infinity’s blockchain backbone.
  • Horizon bridge raid (June 2022): Lifted $100 million from Harmony’s cross-chain bridge.
  • Phemex exchange breach (January 2025): Nabbed over $70 million from Singapore’s Phemex exchange, echoing their signature moves.

The Bybit deal, securing 500,000 ETH, elevates them beyond Ethereum’s Vitalik Buterin, making them the 14th largest Ether holder globally. These scores emphasize their smooth, constantly changing strategies and ability to target crypto’s vulnerabilities.

How Lazarus Group Operate

The Lazarus Group’s playbook is as sophisticated as it is ruthless. They utilize custom malware—think Manuscrypt, AppleJeus, and FALLCHILL—to infiltrate systems. Phishing is their specialty, often through fake LinkedIn profiles or spear-phishing emails that dupe employees into handing over credentials.

The Bybit hack showcased their latest trick: “blind signing,” where a legit-looking user interface hides a malicious payload. They’ve also mastered social engineering—like luring victims with fake job offers, as seen in the 2023 CoinsPaid breach.

Once inside, they move fast. Funds get split across dozens of wallets, laundered through DeFi platforms like Uniswap (no KYC required), and obscured with mixers. The Bybit loot, now tracked across 53 wallets, exemplifies their knack for disappearing into the blockchain’s shadows—though dumping 500,000 ETH in a bearish market could prove tricky even for them.

Why It Matters

The Bybit breach isn’t just a headline—it’s a wake-up call. The Lazarus Group’s relentless attacks expose gaping vulnerabilities in even the most fortified crypto platforms. For Singapore-based Bybit users (and beyond), it’s a stark reminder: not your keys, not your coins.

Yet, CEO Zhou’s pledge to cover losses offers some relief, backed by the exchange’s $20 billion in assets. Still, Ethereum price was impacted, crashing 8% after the Bybit hack

This isn’t random crime—it’s statecraft. The U.S. estimates North Korea’s crypto thefts bankroll 30% of its missile program, turning digital wallets into geopolitical weapons. ZachXBT’s swift unmasking, paired with efforts from firms like Elliptic and Chainalysis, shows the industry’s fighting back—but recovery remains a long shot against a nation-state foe.

What’s Next?

The Lazarus Group isn’t slowing down. Discussions in the crypto space assert that, they have been behind January’s $30 million Phemex hack too, hinting at a spree targeting exchanges.

For Bybit, it’s about rebuilding trust with beefed-up security. For the crypto world, it’s a race to outpace hackers who evolve as fast as the tech they exploit. Self-custody, multisig wallets, and sharper vigilance are trending as users rethink centralized platforms.

Advertisement

Conclusion

The Lazarus Group’s $1.4 billion Bybit heist is more than a record-breaking theft—it’s a glimpse into a shadowy war where code meets geopolitics. Revealed through ZachXBT’s investigation, these North Korean hackers continue to be a significant threat, combining technological skill with state-backed boldness. As crypto grows, so does their shadow. The question isn’t just “Who are they?”—it’s “Who’s next?”

You can also read: Changpeng Zhao Denies Binance’s Involvement In ETH Moves Post Bybit Hack

Advertisement

Frequently Asked Questions

What happened in the Bybit $1.4 billion hack?

On February 21, 2025, Bybit experienced a security breach where hackers stole approximately $1.4 billion in Ethereum from the exchange's cold wallet.

Who is responsible for the Bybit hack?

Investigations have identified the Lazarus Group, a North Korean state-sponsored hacking organization, as the perpetrators behind the Bybit breach.

How did the hackers execute the Bybit breach?

The attackers compromised Bybit's cold wallet during a routine transfer, manipulating the process to redirect funds to unauthorized addresses.
Share
Jane Lubale

Jane Lubale is a crypto journalist and content writer at CoinGape, with a strong focus on blockchain, cryptocurrency, FinTech, and Web3 narratives. Jane holds a Master’s in Business Administration, and a degree in Marketing, and blends this background with her passion for market research and digital marketing to deliver engaging price analysis, thought leadership, and educational content. Her work has also been published in leading crypto media such as Insidebitcoin, where she has contributed to the growing conversation around decentralized technologies. With 5+ years of experience in Decentralized Finance (DeFi), Jane's writing is driven by a mission to educate and empower readers with insights that cut through hype and deliver true value. She achieves this in the form of trading strategies, regulatory updates, or blockchain adoption trends. Away from the keyboard, Jane is a proud mother of three boys and is often found mentoring young people on career paths, personal development, and life choices, as well supporting needy teens complete school. She holds modest investments in cryptocurrency, reflecting her belief in the future of digital finance.

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • Crypto News

Aster Stage 5 Airdrop Will Go Live Dec 22. What to Expect From Token Price?

The Aster Stage 5 Airdrop will officially start on December 22. This phase, called “Crystal,”…

December 18, 2025
  • Crypto News

Why is Crypto Market Down Today? (18 Dec)

The crypto market declined by 0.74% in the past 24 hours, adding to a 7%…

December 18, 2025
  • Crypto News

$200M Worth of Token Unlocks Hit Market This Week- Buy The Dip Or Wait? Aster, ZRO, MERL

As the week of December 15 to 21 unfolds, the cryptocurrency market continues to show…

December 15, 2025
  • Crypto News

Top 3 Crypto Events to Watch at Year-End, Bullish Ahead?

As 2025 Ends, Crypto Market Prepares for Major Economic Triggers This Week. Bitcoin price trades…

December 15, 2025
  • Price Analysis

Why is Cryptocurrency Market Down Today (DEC 11)?

The cryptocurrency market has dropped over the past 24 hours, extending its monthly loss to…

December 11, 2025
  • Price Analysis

Why ZEC, CC, FLOKI, and LUNC Prices Are Pumping Today?

ZEC, CC, FLOKI, and LUNC have become top gainers in the crypto market over the…

December 9, 2025