As AI advances, so do criminals’ tactics. See what TRM is doing to counter AI-enabled crime.

TRM Links North Korea to Record $1.5 Billion Record Hack

TRM InsightsInsights
TRM Links North Korea to Record $1.5 Billion Record Hack

Today, Bybit, a major cryptocurrency exchange, was targeted in a large-scale cyberattack that resulted in the theft of approximately USD 1.5 billion in Ethereum tokens. The hack is the largest exploit on record.

The attackers compromised one of Bybit’s offline cold wallets in what was possibly a supply chain attack, insider threat, or a sophisticated private key compromise.

TRM quickly identified and tagged the compromised addresses as “Hacked” or “Stolen Funds," and created a tracking entity labeled "Bybit Exploiter Feb 2025" to monitor the movement of stolen assets in real time.

TRM has determined - with high confidence - that the Bybit hack was perpetrated by North Korean hackers. This assessment is based on substantial overlaps observed between addresses controlled by the Bybit hackers and those linked to prior North Korean thefts. 

In a single day North Korea's hackers nearly doubled the amount they stole in 2024 (roughly $800 million).

This is some text inside of a div block.
Subscribe and stay up to date with our insights

Access our coverage of TRON, Solana and 23 other blockchains

Fill out the form to speak with our team about investigative professional services.

Services of interest
Select
Transaction Monitoring/Wallet Screening
Training Services
Training Services
 
By clicking the button below, you agree to the TRM Labs Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.