Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen.
The largest single crypto theft on record at the time.
A proof-of-reserves attestation published days earlier was accurate and irrelevant. It described what was held, not whether the signing workflow could be subverted.
These are the custody configurations structurally exposed to this kind of event. It describes the failure class, not any individual holder.
Whether your own arrangement sits in one of those groups is the question our Custody Independence Standard is designed to answer, and the four questions in Is your custody setup actually safe? walk through it.
FBI advisory, exchange post-mortem, NCC Group analysis
Figures are as reported by the named sources. Proof of Custody has not independently reproduced the underlying analysis.
Proof of Custody, "Bybit" incident record, proofofcustody.io/incidents/bybit-2025Attackers compromised a developer machine at a wallet-interface provider and injected code, so cold-wallet signers approved a transaction that appeared legitimate on screen. Reported loss: ~$1.4 to 1.5B.
A proof-of-reserves attestation published days earlier was accurate and irrelevant. It described what was held, not whether the signing workflow could be subverted.
This class of failure could reach: bitcoin left on an exchange. It describes the failure class rather than any individual holder.