$ETH #Bybit事件 "Hacker's identity confirmed: North Korea's Lazarus Group"
After Bybit was attacked, on-chain detective ZachXBT submitted a detailed analysis report to Arkham, confirming that the incident was caused by the North Korean hacker organization Lazarus Group.
According to Bybit CEO Ben Zhou’s explanation on the X platform: Hackers took control of Bybit’s Ethereum cold wallet through a carefully planned phishing attack, tricking the signatories of the multi-signature wallet into approving malicious transactions. Although the UI displayed the correct transfer address, the signing information actually changed the logic of the smart contract, causing the funds to be transferred to an unknown address.
In this attack, the hackers stole the following assets:
🔸401,347 Ether (
$ETH , about $1.12 billion)
🔸90,376 Lido Staked Ether ($stETH, about $253 million)
🔸15,000 Mantle re-staked ether ($cmETH, about 44.13 million USD)
🔸 8,000 Mantle staked ETH ($mETH, ~$23 million)
On-chain data shows that the hacker has quickly converted part of the stolen assets into Ether and liquidated them on decentralized exchanges.