TRM Links North Korea to Record $1.5 Billion Record Hack
Today, Bybit, a major cryptocurrency exchange, was targeted in a large-scale cyberattack that resulted in the theft of approximately USD 1.5 billion in Ethereum tokens. The hack is the largest exploit on record.
The attackers compromised one of Bybit’s offline cold wallets in what was possibly a supply chain attack, insider threat, or a sophisticated private key compromise.
.pptx%20(7).jpg)
TRM quickly identified and tagged the compromised addresses as “Hacked” or “Stolen Funds," and created a tracking entity labeled "Bybit Exploiter Feb 2025" to monitor the movement of stolen assets in real time.
.pptx%20(9).jpg)
TRM has determined - with high confidence - that the Bybit hack was perpetrated by North Korean hackers. This assessment is based on substantial overlaps observed between addresses controlled by the Bybit hackers and those linked to prior North Korean thefts.
In a single day North Korea's hackers nearly doubled the amount they stole in 2024 (roughly $800 million).
Access our coverage of TRON, Solana and 23 other blockchains
Fill out the form to speak with our team about investigative professional services.