
Bybit
$1.5 Billion Stolen Through Compromised Automated Wallet Infrastructure
North Korea's Lazarus Group exploited compromised infrastructure at Safe{Wallet}, a third-party multi-signature wallet provider used by cryptocurrency exchange Bybit.
- 01TRIGGERNorth Korea's Lazarus Group exploited compromised infrastructure at Safe{Wallet}, a third-party multi-signature wallet…
- 02MACHINE ACTIONOperational automation
- 03MISSING GATERisk-based SME approval before execution
- 04IMPACTFinancial harm
The short version
North Korea's Lazarus Group exploited compromised infrastructure at Safe{Wallet}, a third-party multi-signature wallet provider used by cryptocurrency exchange Bybit.
Case telemetry
- INCIDENT
- SS-IR-057
- DATE
- February 21, 2025
- SYSTEM
- Bybit
- LOCATION / SCOPE
- Global
- EVIDENCE
- Reported
- AI ROLE
- Operational automation
- HARM
- Financial harm
- SOURCES
- 1 cited record
The event
North Korea's Lazarus Group exploited compromised infrastructure at Safe{Wallet}, a third-party multi-signature wallet provider used by cryptocurrency exchange Bybit. The attackers manipulated the automated signing process to steal approximately 400,000 Ethereum - worth $1.5 billion - in the largest cryptocurrency exchange hack in history. The multi-signature wallet system, designed to require multiple approvals before authorizing transfers, was subverted through its own automated infrastructure rather than through the signatures themselves.
What the machine did
The multi-sig wallet infrastructure operated as an automated trust layer - if the signing infrastructure said the transaction was valid, the system executed it. The attackers compromised the automated infrastructure that presented transactions for signing, meaning signers approved transactions that looked legitimate on their screens but executed differently on-chain. The automation translated valid human approvals into malicious blockchain transactions.
Where the failure landed
$1.5 billion stolen - the largest crypto exchange hack ever. The FBI confirmed attribution to North Korea's Lazarus Group (TraderTraitor). Bybit replenished reserves within 72 hours through emergency funding from Galaxy Digital, FalconX, and Wintermute, but the stolen funds were laundered through mixers and cross-chain bridges. The incident exposed critical vulnerabilities in automated multi-sig wallet infrastructure.
Reported
Documented in the cited public record. Follow the sources for the precise evidentiary posture.
SOURCE RECORD UPDATED 2026-07-09
1 cited record
- 01Primary / officialFBI Press Release: Lazarus Group / Bybit (2025)
Risk-based SME approval before execution
The failure pattern in this case: High-stakes output had no accountable checkpoint.
The moment the path could change
The appropriate subject-matter expert reviews the evidence, exceptions, and affected people before the output becomes action.
Autonomy is a design choice.
See the operating model that keeps AI useful while preserving human authority at consequential moments.
Compare AgenticAI and AugmentedAI →