Cryptologic

.

News and Updates

Bybit: when hackers target people, not systems

  • Written by Cryptologic


This past month, hackers stole a staggering $1.5 billion from the crypto exchange Bybit in what the market dubbed “The biggest digital heist ever”. Unsurprisingly, the sheer scale of the attack has led many to once again question the safety of crypto, with critics pointing fingers at the industry’s security vulnerabilities. But here’s the twist: the wallets did their job. The problem wasn’t a failure of the underlying technology - it was a failure of ‘human’ security.

Janine Grainger, Founder and CEO of Easy Crypto, explores what happened, what’s being done to recover the funds and what needs to be considered as the industry works to prevent similar attacks in the future.

What exactly went wrong?

The bottom line is that the Bybit hack wasn’t a failure of blockchain security - the attackers didn’t crack an impenetrable system; they manipulated people…

In very simple terms, the attack occurred when the company was making a routine transfer of Ethereum from an offline ‘cold’ wallet (a highly secure, offline storage solution designed to protect assets from cyber threats by keeping private keys completely disconnected from the internet) to a ‘warm’ wallet (a semi-online wallet used for operational liquidity, allowing faster access to funds while maintaining some security measures) for daily trading activities.

The hackers gained access to the software account that helps Bybit control these transfers by compromising a developer’s machine. They remotely modified the user interface, injecting malicious code that manipulated the wallet’s transaction approval process. Employees who usually sign off these transfers saw what looked like legitimate transactions, but behind the scenes, the attackers rewrote the rules, diverting funds straight into hacker controlled accounts.

To make matters worse, the attack leveraged ‘blind signing’. When approving the transactions, employees were effectively signing off on something they couldn’t fully see on their screen. The attackers manipulated this process so effectively that employees believed they were approving routine transfers.

The combination of UI manipulation and blind signing created a near-perfect deception. Importantly, however, it wasn’t crypto’s technology that failed. It was a case of catastrophic human error.

Can the funds be recovered?

The hack has been attributed to North Korean state-sponsored hacking group the Lazarus Group who has a history of targeting crypto exchanges to fund North Korea's economy and sanctioned programs.

Working against this group is the traceability of blockchain. With all eyes on the stolen funds and every blockchain transaction publicly visible, being able to bank the money will be as difficult as stealing it in the first place (although some funds have also been converted into privacy-focused coins like Monero, which are much harder to track).

Importantly, Bybit acted swiftly to reassure customers and worked quickly to secure emergency funding to restore liquidity. They’ve also launched a comprehensive bounty program offering 5% rewards to individuals or firms that help identify and freeze these stolen funds. A real-time leaderboard has been set up to track progress, turning crypto sleuths into heroes!

Preventing future attacks

If there’s one takeaway from this attack, it’s that the industry needs stronger protections against cyber crime - including human-targeted cyber crime..

Exchanges need to go beyond traditional security - The danger of ‘blind signing’ has been made clear and needs to be phased out in favour of clear transaction signing so users can actually see what they’re approving.

In addition, multi-factor authentication for this type of signing could be enabled if exchanges opt to use multi-party computation (MPC) wallets which have started to gain favour in many circles over seed phrases, making key compromises far more difficult. MPC wallets distribute private key ‘fragments’ among multiple parties, reducing the risk of a single point of failure. Unlike traditional seed phrases, MPC eliminates the risk of a single exposed key leading to complete account compromise. (Easy Crypto’s wallet is an MPC wallet.)

Employees need better training - Cyberattack drills should be routine and phishing awareness training should be ongoing. Attackers are getting smarter and exchanges need to ensure their teams can recognise a red flag before it’s too late.

Real-time monitoring needs to be the standard - AI-driven security systems can flag unusual transaction patterns instantly, triggering immediate reviews and helping prevent unauthorised withdrawals.

The bigger picture

This hack didn’t expose flaws in blockchain itself - but it did expose the risks of human error and deception. That distinction, however, didn’t make much difference to the general public. The damage was done, and confidence in crypto security took yet another hit.

Hackers will keep coming…The real question is whether the crypto industry will learn from Bybit and act now to prevent the next attack? If they don’t, it’s only a matter of time before another billion-dollar breach shakes the market all over again.

Trending

Ripple Labs - A Paradigm Shift in the Crypto Landscape

In recent developments that have sent shockwaves through the cryptocurrency market, Ripple Labs has achieved a significant victory in court. The ruling states that XRP, the digital asset associated ...

Koinly: The Leading Crypto Tax and Portfolio Tracking Solution

Koinly has swiftly established itself as one of the most reliable and innovative platforms in the cryptocurrency industry, especially in the realm of tax reporting and portfolio management. Founded in...

BingX Among the First Exchanges to List Monad (MON), Enabling Early Access for Users

PANAMA CITY, November 27, 2025 – BingX, a leading cryptocurrency exchange and Web3 AI company, today announced that it is among the first exchanges worldwide to list Monad (MON), a highly anticipated ...

Major changes to crypto tax from 1 April will make tax avoidance impossible

By: Paul Quickenden, Swyftx NZ Country Manager In some people's minds Crypto has always lived in a strange ‘grey zone’ and they hold steadfast to a lingering belief that crypto somehow sits outside t...

Unmasking the Underworld: The Rising Tide of Money Laundering, Darknet Marketplaces, and Wash Trades in the Cryptocurrency World

Laundering of funds Criminals laundered $8.6 billion in cryptocurrencies in 2021, up 30% from the previous year, according to blockchain data company Chainanalysis. According to the data, rather t...

The Trump Effect: How Politics Fuelled Bitcoin’s Rally

A New Political Ally for Crypto Donald Trump’s transformation from a crypto sceptic to a vocal supporter has been one of the most significant shifts in the digital asset landscape. After his 2024 re-...

Decoding Whale Literacy in the Crypto Market

In the cryptocurrency world, the term “whale” refers to individuals or entities holding large amounts of a digital asset. Their trades can move markets, impact investor sentiment, and trigger large...

Victoria Police Seizes Crypto Assets Amid New Legal Powers: Unpacking Australia’s Evolving Crypto Regulation

The first successful crypto asset seizure by Victoria Police in Australia marks a significant moment in the country’s approach to cryptocurrency regulations. This recent move underlines a new legal ...

Unveiling the Depths of the Mirror Trading International Scandal: Australians Brace for Fallout

In the underbelly of the cryptocurrency boom, a tale of deception and financial ruin unfolds as South African alleged conman Johann Steynberg, the brawny mastermind behind Mirror Trading Internati...

Michael Saylor and the Bitcoin ETF Milestone of Holding Over One Million BTC

Bitcoin exchange-traded funds (ETFs) have reached a monumental milestone, now holding over one million BTC. This milestone underscores the burgeoning adoption of Bitcoin by both institutional and re...

BingX Strengthens Leadership in Web3 AI with 3 Million Early Users and $80 Billion in Copy Trading Volume in Q3

Q3 2025 Key Highlights • According to CoinGecko's Q3 Crypto Industry Report, the total quarterly perpetual trading volume across all centralised exchanges (CEX) hit an all-time high, with BingX ranked...

BingX Launches AI Master, the World-First AI Crypto Trading Strategist

PANAMA CITY, September 10, 2025 – BingX, a leading cryptocurrency exchange and Web3 AI company, today announced the launch of BingX AI Master, the world's first AI-powered crypto trading strategist an...

Australian Police Confiscate $4.1M in Bitcoin as Darknet Crypto Crackdown Expands

Australian Authorities Intensify Enforcement Against Crypto-Enabled Crime Australian law enforcement agencies have confiscated approximately $4.1 million worth of Bitcoin as part of a coordinated inv...

Think carefully before buying Bitcoin – and don't buy the 'safe haven' claims

The sharp rise and subsequent fall in Bitcoin’s value places it among the greatest market bubbles in history. It has outpaced the 17th-century tulip mania, the South Sea bubble of 1720, and the more...

Australia’s 2025 Cryptocurrency Regulatory Overhaul: A Deep Dive into the Nation's Strategic Pivot Toward Innovation and Compliance

Introduction Australia's cryptocurrency landscape is undergoing a seismic shift. As we move through 2025, the nation is rolling out a sweeping regulatory overhaul that promises to reshape how digital...