Bybit ETH Cold Wallet Breach Sees $1.5B Moved to Unknown Address

medium发布于2025-02-22更新于2026-05-25

文章摘要

This week, a former payroll executive was sentenced to nearly 10 years in prison after embezzling $5.7 million from Bybit.

By Giuseppe Ciccomascolo

Key Takeaways

Bybit reported a breach involving one of its ETH cold wallets, triggered by a manipulated transfer.

In response to the breach, Bybit has assured its users that the rest of its cold wallets remain secure and that client funds are safe.

This week, a former payroll executive was sentenced to nearly 10 years in prison after embezzling $5.7 million from Bybit.

Bybit reported a security breach involving one of its ETH cold wallets, in which a sophisticated attack stole funds.

The exchange assured users that other cold wallets remain secure and funds are unaffected as they investigate the incident.

It already made headlines this week as a former executive received a 10-year sentence after embezzling money from the exchange.

Bybit Reports Unauthorized Activity on ETH Cold Wallet

Bybit has reported a breach involving one of their ETH cold wallets. The platform stated that the issue started when a “sophisticated attack” manipulated a routine transfer from their ETH multisig cold wallet to their warm wallet.

The exchange stated, “The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet.”

“Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing interface, displaying the correct address while altering the underlying smart contract logic,” it added.

This manipulation allowed the attacker to gain control of the wallet and ultimately transfer the funds to an unidentified address.

The attack exploited vulnerabilities in the smart contract logic despite the correct address appearing, highlighting the increasing complexity of blockchain-related cyber threats.

Bybit’s Response

In response to the breach, Bybit has taken immediate action. “Our security team, alongside leading blockchain forensic experts and partners, is actively investigating the incident,” the exchange assured its community.

The company also invited collaboration from other teams, stating, “Any teams with expertise in blockchain analytics and fund recovery who can assist in tracing these assets are welcome to collaborate with us.”

Importantly, Bybit has assured users that the attack did not impact the overall security of its platform.

“We want to assure our users and partners that all other Bybit cold wallets remain fully secure. All client funds are safe, and our operations continue as usual without any disruption.”

Bybit emphasized that transparency and security are central to its operations, adding, “Transparency and security remain our top priorities, and we will provide updates asap.”

The exchange remains and will provide ongoing updates as the investigation progresses.

Former Executive Sentenced 10 Years

Bybit made headlines this week when a former payroll executive, Ho Kai Xin, was sentenced to nearly 10 years in prison for embezzling nearly $5.7 million to fund a lavish lifestyle.

Ho, who managed payroll for the crypto exchange, pleaded guilty to multiple charges, including cheating and criminal conduct.

She began diverting funds in May 2022 by manipulating Excel files to authorize payments to herself. Then, she transferred hundreds of thousands each month.

Ho laundered over $4.3 million into luxury goods, cars, and real estate.

Despite the court ordering her to forfeit her assets in 2023, she continued spending until authorities arrested her in April 2023.

Bybit managed to recover $1.2 million in stolen funds.

Ho’s case is one of Singapore’s highest-profile crypto fraud convictions.

你可能也喜欢

DeFi 到了最危险的时候:真正的漏洞不在代码里

2026年4月,DeFi行业遭遇了历史上被黑最严重的一个月,累计损失超6.25亿美元。关键在于,这些重大攻击(如Drift Protocol损失2.85亿美元、KelpDAO损失2.92亿美元、Wasabi Protocol损失450万美元)均非利用智能合约代码漏洞,而是针对其“运营底座”——包括管理员私钥、跨链桥验证者、多签配置和社会工程。 文章指出,行业长期笃信“安全即代码问题”,但如今威胁已迁移至智能合约之外的信任环节。这些事件暴露了DeFi(实为“OpenFi”)的真相:系统虽开放可审计,却在关键节点依赖少数受信方(如安全理事会、单一验证者、特权管理员)。这种中心化的运营杠杆如同“关闭开关”,既能用于紧急响应(如Arbitrum冻结被盗资产),也可能被攻击者劫持造成灾难。 KelpDAO事件尤其凸显了“非对称蔓延”风险:一家小协议的跨链桥配置错误,竟引发Aave等大型协议超过130亿美元的资金外流,暴露了可组合性下的系统性脆弱。 文章结论认为,行业心智模型已然破裂。前路在于诚实披露信任假设、将运营安全提升至与代码审计同等地位,并建立可被机构定价和承保的风险模型。未来能存活并吸引机构资金的协议,将是那些能清晰定义并管理自身中心化权衡的协议。

链捕手24分钟前

DeFi 到了最危险的时候:真正的漏洞不在代码里

链捕手24分钟前

Vitalik 发文强调以太坊必须“令人惊叹”,但基金会不是中心

以太坊创始人Vitalik发文回应近期社区对以太坊基金会的批评,强调以太坊必须保持“令人惊叹”的愿景,并澄清基金会并非生态中心,而是有明确目标的节点。文章承认,由于ETH价格疲软(一年内最大跌幅超64%)及生态表现落后于Hyperliquid等竞争者,社区将矛头指向基金会,批评其战略模糊、高层动荡、持续抛售ETH且利益未与持币者对齐。 Vitalik以谷歌为例,警示以太坊应避免从理想主义滑向平庸与腐败,坚持“不作恶”初心。他明确基金会定位:不再作为“以太坊的中心”,而是聚焦于推动对以太坊抗审查、安全、隐私等核心属性至关重要的长远工作,并承诺将大幅减少ETH出售。 对于发展路线,Vitalik反对盲目追求高TPS,认为那将导致平庸。他提出以太坊应在“CROPS”维度做到极致:实现可证明无Bug的以太坊(借助AI形式化验证)、保持高可用的链共识、彻底消除交易中介(达到100%中介最小化)。这些技术坚持旨在通过建立极致确定性来获取高级资本溢价,回应了对其忽略通证经济学的批评。 最后,文章指出,在基金会缩减职能后,如何创建一个与以太坊经济利益真正对齐并负责的新组织,仍是生态需要解决的关键缺口,这也可能是ETH扭转颓势的重要一步。

链捕手35分钟前

Vitalik 发文强调以太坊必须“令人惊叹”,但基金会不是中心

链捕手35分钟前

BTC市场脉搏:第22周

比特币上周交易走低,价格从7.9万美元跌至7.4万美元附近的局部低点,随后反弹至约7.7万美元。价格动能下降21.7%,反映出行情疲软和抛压上升。然而,现货与永续合约的CVD指标分别大幅增长77.2%和35.5%,表明抛压正在缓解,市场情绪趋于平衡。整体活动有所降温,现货交易量下降10%,期货未平仓合约减少3.5%,指向投机兴趣减弱和市场背景更趋谨慎。 尽管如此,风险偏好重现的迹象正在浮现。多头资金费率飙升135.4%,突显了强烈的多头敞口需求和看涨情绪的改善。在期权市场,25-Delta偏度小幅上升,显示对下行保护的需求略有增加,而未平仓合约大体稳定,表明仓位保持完好。 在传统金融领域,美国现货ETF的MVRV上升0.69%,表明ETF持有者的未实现利润略有增加。同时,ETF资金净流入改善28.9%,指向资本外流缓解和情绪稳定,尽管ETF交易量下降了22.9%,暗示投机活动放缓。 从网络活动看,每日活跃地址数和实体调整后的转账量略有减少,暗示市场可能进入盘整阶段或投资者活动减弱。流动性指标显示市场流动性状况更趋稳定,市场特征表现为信念更强而投机活动更低,进一步支持盘整阶段的判断。 然而,盈利指标提示市场压力可能增加。净未实现盈亏比显著下降,而已实现盈亏比表明实现亏损相对于获利了结有所增加,反映出谨慎且可能偏空的市场情绪。 总而言之,市场显示出温和与盘整的迹象,其特点是活动减少、情绪谨慎以及风险偏好复杂交织。这一微妙局面凸显了持续密切关注市场动态和投资者行为的重要性。

insights.glassnode1小时前

BTC市场脉搏:第22周

insights.glassnode1小时前

市值低于0.05美元但获证实资金实力的五大加密货币资产 — Ozak AI以700万美元募资额位居榜首

当前高价值加密货币增长放缓,早期收益已见顶,投资者转向寻找低价但具备高增长潜力的加密资产。分析师认为,具备坚实资金和技术实力的低价加密货币有望长期生存并获得巨大回报。其中,Ozak AI、BitTorrent、Siacoin、VeChain和Kaspa是价格低于0.05美元且资金实力得到验证的五大加密货币。 Ozak AI (OZK) 以约0.01美元的价格处于第七轮预售阶段,已筹集超过730万美元,预售增长势头强劲。其核心是将AI与区块链结合,开发可分析实时链上数据的预测工具。其技术采用三层去中心化网络架构,具备抗审查、高负载下快速响应及更安全等特性。此外,其个性化预测代理功能允许用户定制AI代理。项目已与Zeni、Spheron等AI和区块链公司建立战略合作。 其余四个代币概况如下:BitTorrent (BTT) 价格约0.00000039美元,拥有庞大用户基础和生态资金支持;Siacoin (SC) 价格约0.00142美元,是历史悠久的去中心化存储项目;VeChain (VET) 价格约0.01美元,在企业供应链应用和机构合作方面实力突出;Kaspa (KAS) 价格约0.046美元,以其快速区块时间的PoW机制和活跃社区著称。 结论指出,这五种低价加密货币均拥有强劲资金支持,降低了执行风险,增强了抵御市场波动的能力。其中,Ozak AI凭借其先进的AI技术、强劲的预售势头、超过700万美元的融资以及战略合作伙伴关系,在列表中处于领先地位,被视为低于0.05美元资产的新标杆。

TheNewsCrypto1小时前

市值低于0.05美元但获证实资金实力的五大加密货币资产 — Ozak AI以700万美元募资额位居榜首

TheNewsCrypto1小时前

交易

现货
合约

热门文章

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

本周,加密市场迎来两股重磅催化——华盛顿“加密货币周”的立法攻势与以太坊机构布局的密集爆发,共同构成加密行业2025年下半年的“政策拐点”与“资金拐点”。这一轮加密周期的深层逻辑,正从比特币转向以太坊、稳定币及链上金融基础设施。我们认为:美国的政策明朗化+以太坊的机构化扩展,标志着加密行业正进入结构性转正阶段,市场配置的重心亦应逐步从“价格博弈”过渡至“规则+基础设施的制度红利捕捉”。

1.6k人学过发布于 2025.07.17更新于 2025.07.17

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对ETH(ETH)币价的意见。

活动图片