Case File 002: Bybit / Safe{Wallet} theft
Status: PUBLISHED with stated gaps. Claims are labelled by source quality. No accusation against any named person.
Documented (secondary sources, consistent)
- Theft date 2025-02-21, about $1.5B in ETH and staked-ETH tokens (BlockSec and others).
- Mechanism: compromised Safe{Wallet} front end. BlockSec says malicious JavaScript was possibly planted around 2025-02-19. NCC and Huntress describe a compromised developer machine.
- Lazarus attribution is repeated by secondary writeups. Not verified by me from a primary source. External claim.
What I opened myself
- Etherscan labels
0x47666Fab8bd0Ac7003bce3f5C3585383F09486E2"Bybit Exploiter 1", and says the label was reported by ZachXBT. A label is not proof. I did not independently trace its flows. - A hash I searched showed sender "ByBit Exploiter" and target "Bybit: Cold Wallet 1", 2025-02-21. The page showed the hash truncated, so I do not reprint it.
Named by CertiK / NCC (unverified by me)
- Victim:
0x1db92e2eebc8e0c075a02bea49a2935bcd2dfcf4 - Malicious implementation:
0xbdd077f651ebe7f7b3ce16fe5f2b025be2969516 - Attack contract:
0x96221423681a6d52e184d440a8eFCEbB105C7242
Open questions
- A full untruncated exploit tx hash from a primary explorer page.
- Independent laundering trace past the first hops.
- Primary-source attribution.
