Loading ForensicBlock
Preparing your blockchain forensics platform...
Preparing your blockchain forensics platform...
Bybit Exploiter (DPRK / Lazarus Group) · ~$1.5B at the time of the incident · attributed 2025-02
Runs on the same methodology-versioned engine a client matter uses, and can be sealed into a court-ready exhibit whose SHA-256 hash anyone can verify in a browser.
Primary recipient EOA of the ~$1.5B drained from Bybit's Safe{Wallet} multisig ETH cold wallet on 2025-02-21 (the largest crypto theft on record), publicly labeled 'Bybit Exploiter 1'. The U.S. FBI (IC3 PSA I-022625-PSA, 26 Feb 2025) formally attributed the theft to the DPRK under the 'TraderTraitor'/Lazarus Group designation and requested industry-wide blocking of the associated addresses; corroborated by Chainalysis, Elliptic, and TRM Labs. Funds were laundered via liquid-staking-token swaps to ETH, a 40-wallet fan-out of exactly 10,000 ETH each, and onward routing through THORChain, eXch, and Bitcoin bridges; substantially unrecovered. The FBI PSA is a law-enforcement attribution/blocking request, NOT an OFAC SDN designation and not a court conviction — cite the sources and confirm the current OFAC designation before relying on it.
Attribution confidence recorded at 95/100 (source strength, never a bare 100). Last verified 2026-07-23.
ForensicBlock asserts no new attribution. Every fact on this page is public record, cited to a primary source you can open, restated so you can verify it independently. This restates the public record and does not by itself establish legal culpability — an indictment is an allegation, not a conviction, and the on-chain address below is attributed by the cited sources, not by us.