Blockchain security firm SlowMist has uncovered details of the cyberattack that resulted in a significant Ethereum (ETH) breach at cryptocurrency exchange Bybit.
The Bybit hack, which compromised Bybit’s cold wallet, was executed by manipulating smart contract logic.
According to SlowMist’s findings, the breach was initiated on February 19, 2025, at 7:15 UTC when attackers deployed a malicious contract. By February 21, 2025, at 14:13 UTC, the perpetrators successfully replaced a legitimate Safe deployment contract with their own, using a multi-signature ownership method.
The attack led to the theft of substantial digital assets, including approximately 401,347 ETH (valued at $1.068 billion), 8,000 mETH ($26 million), 90,375 stETH ($260 million), and 15,000 cmETH ($43 million).
SlowMist’s MistTrack analysis linked the hacker’s address to previous breaches involving BingX and Phemex.
The stolen funds were reportedly laundered through the eXch platform, where they were converted into Bitcoin, Monero, and other cryptocurrencies to obscure their origins.
SlowMist’s founder has also warned that eXch has a track record of hostility toward security researchers, urging exchanges to enhance risk controls for transactions involving the platform.
In response to the breach, Bybit has reassured users that its other cold wallets remain unaffected and that withdrawals continue without disruption.
The exchange is actively cooperating with law enforcement and regulatory bodies to trace and recover the stolen assets. If recovery efforts prove unsuccessful, Bybit commits to using its treasury reserves to compensate affected users.