|

Bybit's $1.4 billion hack traced to Lazarus Group: ZachXBT

  • Blockchain investigator ZachXBT traced the attack on Bybit to the North Korean Lazarus Group.
  • The hack is allegedly connected to the attack on crypto exchange Phemex in January. 
  • Bybit CEO Ben Zhou claims the exchange has secured 80% of customers' stolen funds by leveraging bridge loans.

Crypto investigator ZachXBT linked the $1.44 billion hack of crypto exchange Bybit on Friday to the infamous Lazarus Group, which has been allegedly responsible for some of the top attacks on digital asset platforms.

Additionally, Bybit CEO Ben Zhou claimed the exchange had raised nearly 80% of the stolen funds from bridge loans, encouraging users to stay calm.

Lazarus group strikes crypto again, Bybit aims for quick recovery

Crypto investigator ZachXBT claims that the Bybit attack was performed by the North Korean Lazarus Group.

According to a post by Arkham on X, ZachXBT submitted "definitive proof" that linked this recent exploitation to the Lazarus Group.

"His submission included a detailed analysis of test transactions and connected wallets used ahead of the exploit, as well as multiple forensics graphs and timing analysis," Arkham shared in a post on X.

This marks yet another successful attack on top crypto companies by the anonymous group.

ZachXBT also shared in response to Arkham that he connected the attack to that of the Phemex exchange in January, where hackers stole $30 million.

Arkham offered a bounty of 50,000 ARKM, worth $32,000, to anyone who could identify the perpetrators behind the attack.

This came after Bybit confirmed a major security breach resulting in the loss of $1.44 billion in ETH-related assets, marking one of the largest theft in crypto market history.

In response, co-founder and CEO Ben Zhao assured users that the exchage will honour all withdrawal requests, include those under review.

He claimed the company is leveraging bridge loans from partners to settle the increased withdrawal requests as a repurchase of the stolen tokens from the open market is unlikely.

Bybit also released a statement to users on X, claiming that it has reported the incident to the proper authorities.

They also claim to have reached out to on-chain providers to track the activities of wallets involved in the heist to prevent the hackers from spending the tokens.

The latest hack adds to a growing list of cyberattacks attributed to the Lazarus Group, which has orchestrated some of the most largest cryptocurrency thefts in history. 

Other major incidents from the group include the $625 million Ronin Network (Axie Infinity) heist, the Atomic Wallet breach with a $100 million exodus, the $54 million CoinEx hack and the Alphapo exploit of $60 million.

Author

Michael Ebiekutan

With a deep passion for web3 technology, he's collaborated with industry-leading brands like Mara, ITAK, and FXStreet in delivering groundbreaking reports on web3's transformative potential across diverse sectors. In addi

More from Michael Ebiekutan
Share:

Markets move fast. We move first.

Orange Juice Newsletter brings you expert driven insights - not headlines. Every day on your inbox.

By subscribing you agree to our Terms and conditions.

Editor's Picks

Crypto Today: Bitcoin, Ethereum, XRP slide further as risk-off sentiment deepens

Bitcoin faces extended pressure as institutional investors reduce their risk exposure. Ethereum’s upside capped at $3,000, weighed down by ETF outflows and bearish signals. XRP slides toward November’s support at $1.82 despite mild ETF inflows.

Ripple eyes record high breakout in 2026 as Ripple scales infrastructure

XRP has traded under pressure, but short-term support keeps hopes of a sustainable recovery in 2026 alive. The launch of XRP ETFs and regulatory clarity in the US pave the way for institutional adoption.

Bitcoin risks deeper correction as ETF outflows mount, derivative traders stay on the sidelines

Bitcoin (BTC) remains under pressure, trading below $87,000 on Wednesday, nearing a key support level. A decisive daily close below this zone could open the door to a deeper correction.

Monero builds momentum amid bullish bets and looming resistance

Monero (XMR) trades close to $430 at press time on Wednesday, after a 5% jump on the previous day. The privacy coin regains retail interest, evidenced by heightened Open Interest and long positions.

Orange Juice Newsletter – Smart insights by real people. Every day.

A free newsletter highlighting key market trends to help traders stay a step ahead. Daily insights on the most relevant trading topics, compiled by our experts in an easy-to-read format so you never miss an important move.

Bitcoin: Fed delivers, yet fails to impress BTC traders

Bitcoin (BTC) continues de trade within the recent consolidation phase, hovering around $92,000 at the time of writing on Friday, as investors digest the Federal Reserve’s (Fed) cautious December rate cut and its implications for risk assets.