Loading prices…
🩸BEARISH

Bybit Lost $1.46B to an Attack Audits Never Covered

Half the value stolen since 2022 came from key theft, phishing, and governance, not contract bugs. The 'audited' badges never claimed to cover those layers.

Bybit's Feb. 21 cold-to-warm wallet transfer looked routine on the screens of authorized signers: the destination address matched what they expected. Underneath, the transaction gave an attacker control of the wallet. The exchange later put the loss at $1.46 billion, the FBI attributed it to North Korea, and CryptoSlate reported roughly 401,347 ETH plus several staked Ethereum positions were drained. Safe said a compromised developer machine shaped the malicious proposal; its smart contracts and front end were never the vulnerability.

Why it matters

The incident is the clearest demonstration yet that an 'audited' badge has never covered the layer where the largest losses actually originate. An Oak Security preprint by Stefan Beyer compared 23,818 public audit findings from 22 firms against 218 incidents cataloged by rekt.news between January 2022 and March 2026, a dataset totalling an estimated $7.764 billion in losses. Logic and business-logic defects made up 14.6 percent of all audit findings, with code quality at 13 percent, input validation at 10 percent, and access control at 9.8 percent. The three leading categories together account for 37.6 percent of what auditors find. By contrast, private-key compromise and phishing, which sit largely outside standard contract review, accounted for 43.9 percent of stolen value. Adding dependency and governance attacks brings Beyer's 'human-vector' share to 49.6 percent of losses.

Market impact

Of the 218 incidents, 105 involved a protocol that had previously been audited; those events represented roughly $4.3 billion, or 55 percent of observed losses. The number does not establish that auditors missed exploitable code, since audits cover a specific commit hash and perimeter that frequently diverge from production deployment, configuration, and operational controls. Bybit alone contributed $1.43 billion of the $1.51 billion phishing total, around 18.4 percent of every dollar in the dataset. The paper's prescription, replacing the 'audited' badge with a standardized nutrition label naming the audited commit, deployed bytecode match, production configuration, key management, and front-end infrastructure, gives every layer of the stack its own review line. Bybit could absorb the lesson without losing users; most protocols cannot fund a $1.46 billion replenishment, and rebuilding reserves fixes the balance sheet but not the approval process that emptied it.

Related tokens
$ETH

Frequently asked questions

  1. What happened in the Bybit $1.46B hack?

    On Feb. 21, 2025, attackers manipulated the signing interface so signers approved a transaction they believed was routine. About 401,347 ETH drained; the FBI attributed the theft to North Korea.

  2. Why didn't the audit catch the Bybit hack?

    Safe said a compromised developer machine shaped the malicious proposal, and the smart contracts themselves were never the vulnerability. Standard contract audits don't cover developer endpoints or signing UI.

  3. What share of crypto theft comes from outside audited code?

    Stefan Beyer's preprint puts private-key theft, phishing, dependencies, and governance, his 'human-vector' category, at 49.6% of the $7.764B lost across 218 incidents from January 2022 through March 2026.

  4. How many hacked protocols had been audited before?

    105 of the 218 incidents in Beyer's dataset involved protocols with prior audits, totaling roughly $4.3 billion or about 55% of observed losses. Audits cover a specific commit and perimeter that often diverge from production.

  5. What would replace the 'audited' badge?

    Beyer proposes a standardized nutrition label naming the audited commit, deployed bytecode match, production configuration, key management procedures, and front-end infrastructure, so each layer carries its own review line.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →