TL;DR:
- Bybit reported the neutralization of incidents and potential losses estimated at $700 million through the restructuring of its internal defense systems.
- The platform implemented modifications to its signing processes following the February 2025 attack, in which 401,000 ETH (equivalent to $1.5 billion) were stolen.
- The official technical investigation confirmed that the original exploit stemmed from a breach in the user interface of a third-party multisig wallet provider, rather than the exchange’s core infrastructure.
This Tuesday, Bybit reported that its recent infrastructure upgrades prevented over $700 million in potential losses. The measure comes in response to mitigation protocols implemented after the $1.5 billion cyberattack recorded in early 2025.
The company completed a comprehensive audit of its institutional custody systems. According to the entity’s technical report, the new real-time transaction validation tools enabled the interception of multiple operational anomalies before they could compromise the corporate balance sheet.
The direct precedent for this reinforcement took place on February 21, 2025, the date when malicious actors diverted 401,000 Ethereum (ETH) units. Forensic analyses attributed by security agencies to the Lazarus Group determined that the intrusion was executed via malicious code injection into the frontend of Safe{Wallet}, an external multisignature storage provider.
During that event, authorized signers processed routine transfers without noticing alterations in the application’s visual layer. The manipulation of the delegatecall function in the Ethereum Virtual Machine facilitated the diversion of funds to unauthorized wallets.
As a result of this attack vector, the firm overhauled all of its interaction parameters with third-party services.
Custody Restructuring and Cryptographic Verification
The platform integrated isolated air-gapped signing environments and mandatory smart contract verification independent of web interfaces. Data shared by Bybit’s technical leadership reveals that this framework blocked successive exploit attempts that would have totaled $700 million in unscheduled capital outflows.
Current protocols now require data decoding at the mempool level prior to broadcasting blocks to the network. This additional step eliminates blind reliance on the visual interface during the multi-party signing procedure.
The exchange covered the entirety of the balance stolen in 2025 using corporate reserves and bridge liquidity instruments without suspending user withdrawals. In line with this stance, management maintains that operational solvency remains intact under the new contingency standard.
For industry analysts, these changes in centralized platforms represent a necessary adjustment against attack vectors increasingly focused on the software supply chain.
The implementation of these defenses coincides with the sector’s technical adaptation to international regulatory frameworks, including the cybersecurity standards required by MiCA in the European Union. Bybit will subject its settlement modules to a new round of periodic external audits scheduled for the close of the current quarter.Â






