COINOTAG recommends • Exchange signup |
💹 Trade with pro tools |
Fast execution, robust charts, clean risk controls. |
👉 Open account → |
COINOTAG recommends • Exchange signup |
🚀 Smooth orders, clear control |
Advanced order types and market depth in one view. |
👉 Create account → |
COINOTAG recommends • Exchange signup |
📈 Clarity in volatile markets |
Plan entries & exits, manage positions with discipline. |
👉 Sign up → |
COINOTAG recommends • Exchange signup |
⚡ Speed, depth, reliability |
Execute confidently when timing matters. |
👉 Open account → |
COINOTAG recommends • Exchange signup |
🧭 A focused workflow for traders |
Alerts, watchlists, and a repeatable process. |
👉 Get started → |
COINOTAG recommends • Exchange signup |
✅ Data‑driven decisions |
Focus on process—not noise. |
👉 Sign up → |
-
In February 2025, the crypto world was rocked by the Bybit hack, one of the largest security breaches in history, resulting in the loss of $1.5 billion in Ethereum.
-
This incident has raised serious questions about the adequacy of existing security measures in cryptocurrency exchanges and third-party providers.
-
According to the forensic investigation, “Bybit’s core systems were not breached; instead, attackers exploited a vulnerability in Safe{Wallet}, the third-party wallet service used for transaction processing.”
The Bybit hack has revealed critical vulnerabilities in crypto exchanges, leading to a $1.5B loss and prompting urgent calls for improved security measures.
What was the Bybit hack 2025?
The Bybit hack was a highly coordinated attack that resulted in $1.5 billion in Ethereum (ETH) being drained from the platform. Investigations suggest that hackers exploited a single-signing transaction vulnerability, allowing them to bypass wallet security and execute unauthorized withdrawals.
THE BYBIT HACK WAS THE LARGEST FINANCIAL HEIST IN HISTORY
Bybit sustained losses of $1.4 billion at the time of the hack, 21st February 2025. The closest competitor is the theft from the Central Bank of Iraq, which lost $1 billion on 18th March 2003. pic.twitter.com/OzAcWFUXPL
COINOTAG recommends • Professional traders group |
💎 Join a professional trading community |
Work with senior traders, research‑backed setups, and risk‑first frameworks. |
👉 Join the group → |
COINOTAG recommends • Professional traders group |
📊 Transparent performance, real process |
Spot strategies with documented months of triple‑digit runs during strong trends; futures plans use defined R:R and sizing. |
👉 Get access → |
COINOTAG recommends • Professional traders group |
🧭 Research → Plan → Execute |
Daily levels, watchlists, and post‑trade reviews to build consistency. |
👉 Join now → |
COINOTAG recommends • Professional traders group |
🛡️ Risk comes first |
Sizing methods, invalidation rules, and R‑multiples baked into every plan. |
👉 Start today → |
COINOTAG recommends • Professional traders group |
🧠 Learn the “why” behind each trade |
Live breakdowns, playbooks, and framework‑first education. |
👉 Join the group → |
COINOTAG recommends • Professional traders group |
🚀 Insider • APEX • INNER CIRCLE |
Choose the depth you need—tools, coaching, and member rooms. |
👉 Explore tiers → |
— Arkham (@arkham) February 24, 2025
How did the Bybit hack happen?
Blockchain security firms analyzing the Bybit hack have pointed to a flaw in the wallet signing process, which may have been the key entry point for attackers. Here’s how it might have played out:
COINOTAG recommends • Exchange signup |
📈 Clear interface, precise orders |
Sharp entries & exits with actionable alerts. |
👉 Create free account → |
COINOTAG recommends • Exchange signup |
🧠 Smarter tools. Better decisions. |
Depth analytics and risk features in one view. |
👉 Sign up → |
COINOTAG recommends • Exchange signup |
🎯 Take control of entries & exits |
Set alerts, define stops, execute consistently. |
👉 Open account → |
COINOTAG recommends • Exchange signup |
🛠️ From idea to execution |
Turn setups into plans with practical order types. |
👉 Join now → |
COINOTAG recommends • Exchange signup |
📋 Trade your plan |
Watchlists and routing that support focus. |
👉 Get started → |
COINOTAG recommends • Exchange signup |
📊 Precision without the noise |
Data‑first workflows for active traders. |
👉 Sign up → |
- A transaction signing exploit began when attackers took advantage of a single-signing transaction vulnerability. This allowed them to authorize multiple withdrawals using one “single” approval.
- Cold wallet compromise followed, raising concerns about deeper security loopholes.
- Additionally, phishing and social engineering attacks may have helped gain internal credentials.
E110: Bybit’s Hack EMERGENCY EPISODE: How @Bybit_Official survived the biggest Crypto Theft of all time!
I sat down with @benbybit, the CoFounder & CEO of Bybit, just 72 hours after the largest heist ever in history affected his company.
COINOTAG recommends • Traders club |
⚡ Futures with discipline |
Defined R:R, pre‑set invalidation, execution checklists. |
👉 Join the club → |
COINOTAG recommends • Traders club |
🎯 Spot strategies that compound |
Momentum & accumulation frameworks managed with clear risk. |
👉 Get access → |
COINOTAG recommends • Traders club |
🏛️ APEX tier for serious traders |
Deep dives, analyst Q&A, and accountability sprints. |
👉 Explore APEX → |
COINOTAG recommends • Traders club |
📈 Real‑time market structure |
Key levels, liquidity zones, and actionable context. |
👉 Join now → |
COINOTAG recommends • Traders club |
🔔 Smart alerts, not noise |
Context‑rich notifications tied to plans and risk—never hype. |
👉 Get access → |
COINOTAG recommends • Traders club |
🤝 Peer review & coaching |
Hands‑on feedback that sharpens execution and risk control. |
👉 Join the club → |
Ben opens up on what exactly happened… pic.twitter.com/FvuCZb3I6f
— MR SHIFT 🦁 (@KevinWSHPod) February 26, 2025
What is a single-signing transaction vulnerability?
This vulnerability allows a single transaction approval to be reused or manipulated, leading to unauthorized withdrawals. Here’s how it breaks down:
- Smart contract signing flaw – When funds are moved from a cold wallet to a hot wallet, the system generates an approval signature to verify the transaction.
- Attackers intercepted this signature and triggered multiple unauthorized transactions.
- Since the system treated these as approved transactions, the funds could be drained without immediate alerts.
Think of it as signing a blank check; the hackers did exactly that by intercepting a valid signature and draining Bybit’s funds.
COINOTAG recommends • Exchange signup |
📈 Clear control for futures |
Sizing, stops, and scenario planning tools. |
👉 Open futures account → |
COINOTAG recommends • Exchange signup |
🧩 Structure your futures trades |
Define entries & exits with advanced orders. |
👉 Sign up → |
COINOTAG recommends • Exchange signup |
🛡️ Control volatility |
Automate alerts and manage positions with discipline. |
👉 Get started → |
COINOTAG recommends • Exchange signup |
⚙️ Execution you can rely on |
Fast routing and meaningful depth insights. |
👉 Create account → |
COINOTAG recommends • Exchange signup |
📒 Plan. Execute. Review. |
Frameworks for consistent decision‑making. |
👉 Join now → |
COINOTAG recommends • Exchange signup |
🧩 Choose clarity over complexity |
Actionable, pro‑grade tools—no fluff. |
👉 Open account → |
Were there other security loopholes?
While the single-signing transaction flaw appears to be the main exploit, phishing attacks and delayed detection contributed to the vulnerability. The breach was first spotted by ZachXBT, who noticed excessive fund outflows on February 21.
What caused the Bybit hack of 2025?
Finally, it was determined that a breach in Safe{Wallet}, a third-party service used for transaction verification, enabled the hack.
COINOTAG recommends • Members‑only research |
📌 Curated setups, clearly explained |
Entry, invalidation, targets, and R:R defined before execution. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🧠 Data‑led decision making |
Technical + flow + context synthesized into actionable plans. |
👉 Join now → |
COINOTAG recommends • Members‑only research |
🧱 Consistency over hype |
Repeatable rules, realistic expectations, and a calmer mindset. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🕒 Patience is an edge |
Wait for confirmation and manage risk with checklists. |
👉 Join now → |
COINOTAG recommends • Members‑only research |
💼 Professional mentorship |
Guidance from seasoned traders and structured feedback loops. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🧮 Track • Review • Improve |
Documented PnL tracking and post‑mortems to accelerate learning. |
👉 Join now → |
Bybit Hack Forensics Report
Here are preliminary reports from @sygnia_labs and @Verichains
Check out the full report: here
— Ben Zhou (@benbybit) February 26, 2025
COINOTAG recommends • Exchange signup |
🎯 Focus on process over noise |
Plan trades, size positions, execute consistently. |
👉 Sign up → |
COINOTAG recommends • Exchange signup |
🛠️ Simplify execution |
Keep decisions clear with practical controls. |
👉 Get started → |
COINOTAG recommends • Exchange signup |
📊 Make data your edge |
Use depth and alerts to avoid guesswork. |
👉 Open account → |
COINOTAG recommends • Exchange signup |
🧭 Be prepared, not reactive |
Turn setups into rules before you trade. |
👉 Create account → |
COINOTAG recommends • Exchange signup |
✍️ Plan first, then act |
Entries, exits, and reviews that fit your routine. |
👉 Join now → |
COINOTAG recommends • Exchange signup |
🧩 Consistency beats intensity |
Small, repeatable steps win the long run. |
👉 Sign up → |
What is Safe{Wallet}?
Safe{Wallet} is a smart contract-based wallet service that ensures secure transactions using multi-signature approvals. However, a security flaw led to JavaScript exploits that compromised its integrity.
Hackers embedded malicious code into the Safe{Wallet} service running on AWS, allowing them to modify transaction details unnoticed.
COINOTAG recommends • Premium trading community |
🏛️ WAGMI CAPITAL — Premium Trading Community |
Strategic insights, exclusive opportunities, professional support. |
👉 Join WAGMI CAPITAL → |
COINOTAG recommends • Premium trading community |
💬 Inner Circle access |
See members share real‑time PnL and execution notes in chat. |
👉 Apply for Inner Circle → |
COINOTAG recommends • Premium trading community |
🧩 Turn theses into trades |
Reusable templates for entries, risk, and review—end to end. |
👉 Join the club → |
COINOTAG recommends • Premium trading community |
💡 Long‑term mindset |
Patience and discipline over noise; a process that compounds. |
👉 Get started → |
COINOTAG recommends • Premium trading community |
📚 Education + execution |
Courses, playbooks, and live market walkthroughs—learn by doing. |
👉 Get access → |
COINOTAG recommends • Premium trading community |
🔒 Members‑only research drops |
Curated analyses and private briefings—quality over quantity. |
👉 Join WAGMI CAPITAL → |
How did the attack happen?
During a typical ETH cold wallet transfer, the compromised Safe{Wallet} script altered transaction details just as they were being authorized.
Bybit’s authorized wallets approved what they thought was a secure transfer while the malicious script redirected funds to the hacker’s destination.
COINOTAG recommends • Exchange signup |
🧱 Execute with discipline |
Watchlists, alerts, and flexible order control. |
👉 Sign up → |
COINOTAG recommends • Exchange signup |
🧩 Keep your strategy simple |
Clear rules and repeatable steps. |
👉 Open account → |
COINOTAG recommends • Exchange signup |
🧠 Stay objective |
Let data—not emotion—drive actions. |
👉 Get started → |
COINOTAG recommends • Exchange signup |
⏱️ Trade when it makes sense |
Your plan sets the timing—not the feed. |
👉 Join now → |
COINOTAG recommends • Exchange signup |
🌿 A calm plan for busy markets |
Set size and stops first, then execute. |
👉 Create account → |
COINOTAG recommends • Exchange signup |
🧱 Your framework. Your rules. |
Design entries/exits that fit your routine. |
👉 Sign up → |

Why this matters for crypto security
This hack emphasizes that vulnerabilities can arise not from direct attacks but from third-party integrations. Transactions must undergo continuous audits, ensuring that dependencies do not weaken exchange security.
How much has been recovered?
As of late February 2025, approximately $42.8 million of the stolen assets have been secured or frozen. The recovery is facilitated through coordinated efforts across different exchanges and blockchain forensics.
- Ethereum (ETH): 34 ETH (≈$97,000) was intercepted.
- Bitcoin (BTC): $37,000 was blocked after being bridged cross-chain.
- Stablecoins (USDT/USDC): Tether froze 181,000 USDT linked to the stolen funds.
What does the Bybit hack change for crypto?
The Bybit hack demonstrates a pressing need for enhanced security across all cryptocurrency exchanges. Stronger protocols and collaborative efforts are essential to mitigate the risks posed by increasingly sophisticated cyber threats.
Frequently asked questions
Was Bybit itself hacked, or was it a third-party vulnerability?
Bybit wasn’t directly hacked; instead, the attackers exploited vulnerabilities in the third-party service, Safe{Wallet}.
How much of the stolen crypto has been recovered so far?
As of late February 2024, about $42.8 million has been frozen or recovered.
What’s Bybit doing to prevent future attacks like this?
Bybit has implemented tighter security measures and launched initiatives like LazarusBounty.com, which aims to track stolen funds.
COINOTAG recommends • Members‑only research |
📌 Curated setups, clearly explained |
Entry, invalidation, targets, and R:R defined before execution. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🧠 Data‑led decision making |
Technical + flow + context synthesized into actionable plans. |
👉 Join now → |
COINOTAG recommends • Members‑only research |
🧱 Consistency over hype |
Repeatable rules, realistic expectations, and a calmer mindset. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🕒 Patience is an edge |
Wait for confirmation and manage risk with checklists. |
👉 Join now → |
COINOTAG recommends • Members‑only research |
💼 Professional mentorship |
Guidance from seasoned traders and structured feedback loops. |
👉 Get access → |
COINOTAG recommends • Members‑only research |
🧮 Track • Review • Improve |
Documented PnL tracking and post‑mortems to accelerate learning. |
👉 Join now → |