The Largest CEX Hack in History: How Liquid Staking Tokens Became Prime Targets
Krzysztof Gogol
Blockchain Researcher | DeFi | Digital Asset | Layer2 | MultiChain | Tech entrepreneur & PhD candidate
The crypto industry has witnessed its biggest hack ever. ByBit, the second-largest centralized exchange (CEX) by trading volume, has been struck by a security exploit resulting in the loss of $1.5 billion worth of ETH. This hack, attributed to North Korea's Lazarus Group, surpasses all previous records—140% larger than the infamous $625 million Ronin Bridge exploit.
As the dust settles, we explore what went wrong, why it matters, and how the crypto world can recover.
What Exactly Happened?
In a statement, Zhou, a representative from ByBit, said:
"This hacker took control of a specific ETH cold wallet we signed and transferred all ETH in the wallet to an unidentified address. All other cold wallets remain secure."
ByBit insists it remains solvent and can cover the loss. But how did the attack occur?
The Attack Breakdown:
1?? Malware in ByBit's Approval Machines:
2?? Compromised Safe{Wallet} Infrastructure:
?? The Escape Route: ETH to BTC via Chainflip
The stolen ETH is reportedly being converted to BTC using Chainflip, a method linked to previous high-profile crypto heists.
Staked ETH & Liquid Staking Tokens (LSTs): What’s the Deal?
Staked ETH represents ETH locked to secure the Ethereum network, generating staking rewards that offset token inflation. Liquid staking tokens (LSTs) like mETH and stETH that were stolen, are tokenized representation of staked ETH but offer liquidity. Benefits include:
Why Do CEXs Offer Liquid Staking?
Centralized Exchanges (CEXs) like ByBit provide these tokens to:
CEX vs. DEX: Control, Security, and the Bigger Picture
When trading crypto, you typically choose between:
Centralized Exchanges (CEXs):
Decentralized Exchanges (DEXs):
The major difference is that CEX is a custodian solution, meaning CEX is a custodian of your crypto. In contrast, at DEX, you can only swap your tokens; you must have your own wallet to manage any transactions.
Lessons from the ByBit Hack
This breach serves as a cautionary tale for the entire crypto industry. Key lessons include:
1?? Control Matters:
2?? Centralization Risks:
3?? Stronger Security Protocols:
Conclusion
The ByBit hack is a harsh reminder of the risks inherent in centralized systems and the growing sophistication of threat actors like the Lazarus Group. The crypto industry must now reflect and respond. Strengthening approval mechanisms, enhancing infrastructure integrity, and embracing decentralization could provide the resilience required for future growth.
Will 2025 set new records for crypto security incidents? Time will tell. But one thing is clear: The industry must evolve—or risk repeating history.
Thanks for reading From PhD Research in DeFi! This post is public so feel free to share it.
Software engineer
1 周I lead an R&D activity to develop a protocol to enhance the self-custody experience. We're using #ZK to do that at scale and in a trust-minimized manner. For more details: https://www.dhirubhai.net/posts/walid-khemiri_microchain-white-paper-activity-7299721979891245056-IgsY
Stronger together! Networkerin, Fundraiserin, Querdenkerin, verhandlungssicher, Yoga Praktikerin, Projekt Initiatorin des Filmprojekts "Sound Healing", HERZMENSCH
1 周Very well explained???? it‘s great to see, how the crypto community stick together in such a difficult situation. Most important, the customer funds are safe.
Senior Legal Counsel at Bitvavo
1 周Krzysztof Gogol - thank you for sharing your write-up, very insightful. Can you elaborate on the role of staked ETH and LSTs and how they were impacted?