GapLimit

Breach · Incident record

Bybit 2025: the transaction looked routine until it did not

A sourced forensic account of the $1.5 billion theft, separating operator report, government attribution and durable lesson.

The most dangerous signing failure can preserve the appearance of procedure.

Why it matters

The incident shows why multisignature counts do not help when signers approve a deceptive interpretation of the transaction.

Known

The FBI published its attribution and approximate loss. Bybit described the affected signing path and said the compromise did not represent a broad breach of its exchange infrastructure.

Operator account versus independent record

The operator's technical account is material but interested evidence. Government attribution answers a different question and can also evolve; the two sources should not be collapsed into one voice.

Trust boundary

The boundary included signer devices, displayed transaction meaning, front-end and dependency integrity, approval policy and the ability to halt or contain movement after detection.

Durable lesson

High-value signing needs independent decoding, destination allowlists, human-readable intent, separation of preparation from approval, and drills for emergency containment. This is defensive architecture, not an exploitation recipe.

Source trail

Follow the thread