the-north-korean-bybit-hack:-a-$1.4-billion-lesson-in-crypto-security

On February 21, 2025, Bybit, one of the largest crypto exchanges, lost roughly $1.4 billion in a hack that blockchain investigators, including Arkham Intelligence and the pseudonymous researcher ZachXBT, attributed to North Korea’s Lazarus Group. This wasn’t a brute force attack on Bybit’s code. It was a patient exploitation of human vulnerabilities, and it’s a reminder that even the largest platforms in crypto aren’t immune.

How Lazarus pulled it off

The attack didn’t crack blockchain encryption or exploit a smart contract flaw. Lazarus relied on social engineering: manipulating people rather than systems. Reports suggest the group spent months laying groundwork, likely through phishing schemes, fake job offers, or other tailored scenarios designed to trick employees or users into granting access to critical systems. Once inside, they moved over $1.4 billion in Ethereum and related tokens.

This wasn’t Lazarus’s first large heist. The group has been linked to the $600 million Ronin Network hack in 2022 and a $308 million theft from Japan’s DMM Bitcoin exchange in 2024. The pattern is consistent: exploit human error, then launder proceeds through mixers and unregulated exchanges. The Bybit attack stands out mainly for its scale.

Why centralized exchanges are a concentrated target

Bybit, like most exchanges, holds user funds in its own wallets. That concentration is exactly what makes it a target: an attacker needs one point of entry to reach billions in assets. Firewalls and multi-signature wallets help, but none of it stops an employee from clicking a malicious link or a user from handing over credentials under a convincing pretext.

Unlike a bank account, crypto held on an exchange doesn’t come with government backed deposit insurance the way FDIC-insured accounts do. When a hack like this happens, users are often left waiting to see whether the exchange can make them whole, and history suggests full recovery is the exception, not the rule.

Institutional custody and insurance as a different model

Institutional custody works differently. A regulated third party holds the assets using offline cold storage, multi-signature protocols, and access controls, and the assets are typically distributed across multiple secure locations rather than sitting in one online wallet. Withdrawals often require multiple parties to approve, which adds friction for anyone who compromises a single employee’s credentials. That structure doesn’t make custody unhackable, but it removes the single point of failure that made the Bybit hack so damaging.

Insurance is the other half of the equation. Institutional custodians often back their services with policies, underwritten by established insurers, that cover theft or operational failure. Compare that to the discretionary “insurance funds” many exchanges maintain out of trading fee revenue: those funds are rarely sized for a mega-hack. After a 2018 hack of the Youbit exchange in South Korea, also linked to North Korea, the exchange’s insurer denied a multi-million dollar claim over inadequate disclosure, a gap that left users with nothing. Institutional-grade coverage tied to custody, with clearly defined terms and audited reserves, is a materially different proposition than an exchange’s self-funded reserve.

None of this guarantees an institutional custodian can’t be breached. But separating custody from the exchange that facilitates trading, and backing that custody with real insurance, removes the concentrated single point of failure that made the Bybit hack a $1.4 billion problem instead of a contained incident.

Educational only, not tax, legal, or investment advice. Check primary sources and speak with a qualified professional before making financial decisions.

STOP! BEFORE YOU GO

Get The Wyoming Crypto LLC Briefing Free

The structure to hold digital assets with the legal protection and tax advantages of a Wyoming LLC.
DOWNLOAD NOW
close-link