Bybit Hack Leaves 90% of $1.5B Stolen Funds Untraceable
The case highlights the gap between legal authority and asset recovery: court backing can support tracing, but it cannot guarantee stolen funds become recoverable.
Crypto security covers the failures, attacks and deceptive practices that can put digital assets at risk: compromised exchange wallets, smart-contract exploits, governance attacks, flash-loan manipulation, phishing, scams and privacy breaches. The consequences often extend beyond the protocol first affected. Stolen USDC may be swapped for ETH, an exchange may suspend withdrawals after hot-wallet outflows, or a governance proposal may redirect a DAO treasury. For holders of BTC, ETH, SOL and stablecoins such as USDT and USDC, understanding the attack path is essential to judging whether an incident threatens one platform, connected protocols or the wider market.
Zipp tracks incidents from the first on-chain alert through confirmation, containment and recovery. Coverage examines transaction trails, attacker methods, disputed loss estimates, withdrawal status, token approvals, bridge and oracle dependencies, validator or admin-key controls, and any reimbursement or recovery plan. Recent reporting has followed the Ostium and Summer Finance exploits, the BONK DAO treasury attack, suspicious AscendEX hot-wallet movements and KelpDAO activity involving Chainlink CCIP. The desk also covers audits, disclosure practices and longer-term risks such as quantum computing, as well as sanctions enforcement, exchange exposure and blockchain tracing around Iran-linked CoinEx flows. We distinguish verified losses from funds merely moved or placed at risk, identify the evidence behind researchers’ claims, and monitor whether stolen assets are bridged, mixed, frozen or converted into assets including ETH. Privacy belongs to the same beat: readers need to know what transaction data is public, how analytics firms connect wallets, and where surveillance, compliance and user protection intersect.
The case highlights the gap between legal authority and asset recovery: court backing can support tracing, but it cannot guarantee stolen funds become recoverable.
Chainalysis shows DPRK-linked groups launder stolen crypto within ~45 days, meaning most of the $1.46B likely cleared the pipeline before this 17-month-old lawsuit arrived.
Standard BTCPay on-chain wallets are safe, but LND operators on v2.4.1 or earlier face remote node takeover via unauthenticated .macaroon file access.
BIP-110's trigger fires this weekend; its replay protection waits until September. The dangerous case is a minority chain that refuses to die, because miner signalling sits at just 2.6%.
Polymarket's fix mirrors Kalshi's: time-weighted averages via Chainlink make last-second Binance pushes costly. Stanford-SMU paper found 93% of losses in manipulated windows fell on retail.
The action reaches beyond two exchanges to Shelbit’s operator and his cross-border corporate network, raising the compliance stakes for firms handling Iran-linked crypto flows.
Coldcard's migration guidance adds an immediate wallet-security issue to the fund movement, with specific device versions and seed setups requiring action.
The warning shifts the custody debate from storage location to the controls protecting and using private keys.
Active exploitation makes this an infrastructure-security emergency for Bitcoin payment operators, not a routine maintenance notice.
The raid follows Russia's January ban on WhiteBit and treats unlicensed crypto desks as a sanctions-evasion vector funding Kyiv.
Bitcoin trades 50% below its all-time high while long-term holders redistribute, a setup that points to custody reshuffling after the Coldcard breach rather than the profit-taking that has…
Range-bound action with Fear at 29 leaves the market coiled for a volatility catalyst, while small caps diverge sharply from majors.
Dormant supply from when bitcoin traded near $10 is resurfacing as Coinkite's $114M Coldcard exploit sends long-term holders back to audit old storage setups, with the receiving address already wired…
Starknet's strkBTC launch puts the tradeoff in focus: shielding BTC can mean accepting new trust assumptions in wrappers, sidechains or e-cash systems.
The no-migration path lets users gain quantum resistance without generating new phrases or moving to another address.
The decision keeps executive accountability at the center of crypto's post-FTX compliance debate.
Coldcard losses alone climbed past $100M as investigators widened the scope, proving a vendor-level flaw can drain thousands of cold wallets at once.
MiCA turns authorization status into a frontline trust signal as EU users distinguish firms allowed to serve them from impersonators.
Tarsha allegedly drained SAFT proceeds into gambling, crypto speculation, and a Miami condo while staging a fake marketplace to keep investors in the dark.
The market backdrop remains cautious, with BTC dominance at 56.8%, an Altcoin Index score of 45/100 and Fear & Greed at 25, or Extreme Fear.
A hack is a broad term for unauthorized access or theft, including compromised keys, accounts and infrastructure. A smart-contract exploit specifically abuses faulty code, economic design or permissions in an on-chain application, sometimes without breaching its servers.
Check whether the figure is supported by identifiable on-chain transactions, a statement from the affected project and independent analysis. Large wallet movements are not automatically losses; funds may be relocated, quarantined or counted more than once.
Stablecoin issuers may be able to freeze tokens at specific addresses, while native assets such as ETH generally do not have an issuer-controlled freeze function. Swapping does not make funds untraceable, and exchanges, bridges or other services may still block them.
No. An audit reviews a defined codebase and scope at a particular stage, but it cannot guarantee that every bug, governance weakness, key-management failure or later upgrade is secure. Readers should check the audit scope, unresolved findings and whether deployed code matches the reviewed version.