Bybit Hack: Hackers Launder $1.4B Stolen Crypto
North Korean state-sponsored hackers have successfully converted nearly all of the $1.4 billion in Ethereum stolen from cryptocurrency exchange Bybit on February 21 into Bitcoin, executing the first phase of an unprecedented money-laundering operation.
The Largest Cryptocurrency Heist in History
The massive security breach occurred on February 21, when a highly sophisticated attack targeted one of Bybit’s digital wallets. The intruders made off with 401,346 Ethereum (ETH)—valued at approximately $1.4 billion at the time—making it the largest cryptocurrency theft in history and potentially the largest heist of any kind. The FBI, along with several blockchain intelligence firms, has formally attributed the devastating cyber heist to the North Korean government.
Tracking the Flow of Stolen Ethereum
Since the digital robbery, the perpetrators have systematically emptied the dozens of intermediary crypto wallets where they initially distributed the loot. According to blockchain experts, the vast majority of these funds have now been converted into Bitcoin (BTC). Andrew Fierman, head of national security intelligence at Chainalysis, confirmed that investigators are actively tracking roughly 90% of the stolen assets, which are currently distributed across approximately 4,400 Bitcoin addresses.
The remaining 10% of the stolen funds have already been consumed by transaction fees, frozen by authorities, or successfully converted into fiat currency through off-ramps, which are services used to exchange crypto for traditional cash.
Unprecedented Velocity in Decentralized Swapping
During the initial phase of the laundering process, which ran from February 24 to March 2, the threat actors moved with extreme speed to mask the origin of the digital assets. Ari Redbord, a former federal prosecutor and current global head of policy at TRM Labs, revealed that the hackers primarily utilized THORSwap. This decentralized protocol allows users to swap tokens across different blockchains directly, bypassing traditional financial intermediaries.
Redbord noted that this phase demonstrated an unprecedented level of operational efficiency, indicating that North Korea has significantly scaled its money-laundering capabilities or is leveraging sophisticated underground financial networks, particularly in China, to process illicit capital at speeds that outpace traditional anti-money laundering (AML) frameworks.
The Hurdles of Phase Two: Bitcoin Mixers
Despite their rapid initial success, cybersecurity experts emphasize that the hackers still face significant obstacles before they can fully cash out. Tom Robinson, co-founder and chief scientist at Elliptic, stated that the attackers still have a long way to go to safely utilize these funds.
The second phase of the operation has already begun, with the hackers depositing an initial portion of the Bitcoin into crypto mixers. These privacy-enhancing services pool and scramble transactions from various users to break the blockchain trail. While Robinson acknowledged that mixers present a major roadblock for law enforcement, Redbord pointed out a critical bottleneck: typical mixing services only handle between $5 million and $10 million in daily volume, raising serious questions about whether they can absorb a multi-billion-dollar fortune.
Can Bybit Recover the Stolen Billions?
There is still a slim chance that Bybit might claw back some of its lost assets. Industry analysts suggest that if the stolen Bitcoin passes through centralized cryptocurrency exchanges, those platforms could freeze the accounts—provided they identify the tainted assets quickly enough.
In a bid to recover the funds, Bybit launched a massive $140 million bounty program, offering to pay 5% of recovered assets to any entity that successfully freezes the funds, and another 5% to the first person who reports them. However, according to the official bounty page, only $4.3 million has been awarded to 19 bounty hunters so far. Bybit has declined to comment on the ongoing recovery efforts.
