Illustration of an institutional exchange building representing centralized exchange custody and security

Centralized cryptocurrency exchanges hold enormous concentrations of user funds in a comparatively small number of wallets, which makes them, year after year, the single highest value target in the entire industry. Custody practices have matured considerably since the early exchange collapses of the previous decade, yet the past two years have produced some of the largest thefts in the industry's history. Examining exactly how three of the most significant recent incidents happened reveals that the weak point has consistently shifted away from the blockchain itself and toward the infrastructure, people, and processes surrounding it.

Bybit, February 2025: the largest crypto heist in history

On February 21, 2025, Bybit suffered the largest cryptocurrency theft ever recorded, losing approximately one and a half billion dollars, more than four hundred thousand ETH and staked ETH, in a single incident. The FBI publicly attributed the attack to North Korea's Lazarus Group, operating under the cluster it tracks as TraderTraitor.

The breach did not originate inside Bybit's own systems. Attackers compromised development infrastructure belonging to Safe Wallet, the multiple signature wallet platform Bybit relied on, specifically an Amazon Web Services storage bucket used to host JavaScript files for the wallet interface. They replaced a legitimate file with a malicious version designed to detect Bybit specific wallet addresses and silently substitute the transaction details being displayed. When Bybit's own executives reviewed what appeared on screen to be a routine transfer and signed it, they were unknowingly approving a transaction that routed funds directly to wallets controlled by the attackers. Reporting on the incident indicates that at least one hundred sixty million dollars of the stolen funds were laundered within the first forty eight hours, underscoring how quickly proceeds move once a theft of this scale succeeds.

WazirX, July 2024: a multiple signature wallet compromise

On July 18, 2024, Indian exchange WazirX disclosed a theft of approximately two hundred thirty four million dollars from a multiple signature wallet held under a third party custody arrangement. According to public reporting on the incident, attackers created a fake account on the exchange, deposited funds, and began purchasing a specific token in a pattern designed to draw the wallet's signing process into a transaction they controlled. Once WazirX's own signatories reviewed and approved what they believed was a standard transaction, the underlying smart contract governing the multiple signature wallet had already been altered in the attacker's favor, giving them full control of the wallet without needing any of WazirX's actual private keys going forward. The incident was later linked by researchers to the Lazarus Group.

CoinDCX, July 2025: when the breach is not the smart contract

Almost exactly one year after the WazirX incident, Indian exchange CoinDCX disclosed a theft of approximately forty four million dollars in July 2025. Unlike the two prior cases, this breach did not involve a smart contract vulnerability or a manipulated multiple signature transaction at all. Reporting on the incident describes attackers compromising an internal account used for liquidity provisioning on a partner platform, essentially conventional backend infrastructure, rather than directly breaching the exchange's cold storage. The incident illustrated that even exchanges with well secured customer cold wallets remain exposed through the operational accounts and third party integrations that support day to day liquidity management.

CoinDCX publicly stated that customer funds were unaffected and that the loss was absorbed by the exchange's own treasury, a response pattern that has become more common among established exchanges following a breach, and one that stands in sharp contrast to earlier eras of the industry when a comparable theft could threaten an exchange's ability to honor customer withdrawals at all.

The common threads across all three

Trust in infrastructure and third parties

None of the three breaches involved a direct assault on a well secured cold wallet. Each instead targeted a layer of trusted infrastructure surrounding it, a third party wallet interface's development pipeline, a multiple signature contract's logic, and an internal liquidity account, respectively.

Human approval as the last line of defense, and its failure

Both the Bybit and WazirX incidents specifically defeated the human review step that multiple signature setups are designed around. In each case, a person looked at what they believed was a legitimate transaction and approved it, because the information presented to them had already been manipulated before it reached their screen.

Speed of laundering after the breach

In the Bybit case specifically, a significant portion of the stolen funds moved through laundering channels within the first two days. This pace is consistent with the broader patterns covered in our guide on cross chain laundering, and reflects how little time exchanges and investigators typically have to intervene once a major theft is detected.

Key Point

In each of these incidents, the underlying blockchain performed exactly as designed. The failure occurred in the surrounding software, infrastructure, or human review process that decided which transactions to sign.

What is changing in exchange security

  • Exchanges are placing more scrutiny on the software supply chain behind third party wallet infrastructure, not just the wallet contracts themselves.
  • Transaction verification is increasingly moving toward independent, out of band confirmation methods rather than trusting what a single interface displays before signing.
  • Internal accounts used for liquidity provisioning and partner integrations are being treated with the same security posture previously reserved for cold storage.
  • Regulatory and industry pressure has increased expectations around rapid public disclosure and coordination with law enforcement following a breach.

A meaningful shift visible across all three incidents is that the exchanges involved were able to absorb the loss and continue operating normally for customers, a marked difference from earlier exchange collapses where a comparable theft could threaten the platform's solvency outright. That resilience reflects larger balance sheets and more mature reserve practices at established exchanges, but it does not change the underlying fact that the funds were still stolen, still had to be traced, and still moved through the same laundering channels regardless of who ultimately bore the financial loss.

Why maturity has not eliminated the risk

It would be reasonable to assume that after more than a decade of high profile exchange collapses and thefts, the industry's largest platforms would have closed off this category of risk by now. What these three incidents show instead is that the target has moved rather than disappeared. Exchanges have genuinely improved core custody practices, cold storage segregation, and reserve transparency compared to a decade ago. Attackers responded by shifting toward the layers surrounding that custody, the software supply chains, the multiple signature approval workflows, and the operational accounts that even a well secured exchange still depends on to function day to day. Each improvement in one area has been met with attackers probing the next weakest link rather than giving up.

What this means for users

None of these breaches were caused by a user's own mistake, and none could have been prevented by better personal security habits alone. That does not mean users are powerless. Spreading significant holdings across more than one platform limits exposure to any single exchange's failure, and understanding what to expect if your chosen exchange is ever affected matters. Our guide on exchange account compromise covers what individual account level compromise looks like, and our guide on what happens after a wallet hack covers the practical steps to take if you are affected by an incident at any platform you use.

It is also worth watching how an exchange communicates in the immediate aftermath of a breach. Each of the exchanges discussed here disclosed the incident publicly and committed to covering user losses from their own reserves, a response that meaningfully differs from platforms that go quiet, delay withdrawals without explanation, or blame users after a large scale breach, and it is a reasonable factor to weigh when deciding which platforms to trust with significant holdings going forward.

exchange hackbybitwazirxcoindcxcryptocurrency security

Frequently asked questions

Yes, at approximately one and a half billion dollars stolen in February 2025, it stands as the largest single cryptocurrency theft publicly recorded to date, surpassing prior record incidents by a wide margin. The FBI publicly attributed the attack to North Korea's Lazarus Group.

Bybit stated it covered the loss through its own reserves and lending arrangements to ensure user withdrawals were not affected, which is a notable contrast to some earlier exchange collapses where user funds were directly lost. The stolen funds themselves largely remain the subject of ongoing tracing and law enforcement efforts.

A multiple signature, or multisig, wallet requires more than one authorized party to approve a transaction before it executes, intended to prevent a single compromised key from moving funds. In both the Bybit and WazirX cases, attackers did not steal the signing keys directly. They manipulated what the signers saw or altered the underlying contract logic, causing legitimate signers to unknowingly approve a fraudulent transaction.

This varies significantly by case. Some breaches are detected within minutes through automated monitoring of unusual withdrawal patterns, while others, particularly those involving manipulated interfaces or backend accounts, may not be identified until funds have already been moved and partially laundered.


Sources and further reading


Related reading

State Linked Hacking Groups and Large Scale Crypto TheftWhat Happens When Your Exchange Account Is CompromisedCryptocurrency Theft in 2026, What the Numbers ShowWhy Exchange Cooperation Has Improved in Recent Years