Trakx Security: Zero Exposure to Bybit Hack

On February 21st, 2025, Bybit, one of the largest crypto exchanges in the world, was attacked by North Korean hackers called Lazarus Group, resulting in the largest crypto heist of all time: $1.46 billion stolen (ETH). Until now, the most significant crypto theft was the Poly Network hack in 2021, in which an attacker exploited the vulnerabilities in the smart contracts to steal over $600 million worth of cryptocurrencies. But now Bybit has gained the first place.
The scale of the Bybit hack has shocked the entire crypto industry, with significant volume and price swings in the last few days. Many users started complaining about Bybit’s security measures, and a lot of them moved their digital assets out of Bybit. At Trakx, we pride ourselves on remaining a safe haven built on a security-first philosophy. We have designed our platform with robust risk management protocols that effectively insulate us from the vulnerabilities that led to the Bybit incident. Additionally, we have no direct or indirect exposure to Bybit, ensuring our clients’ funds are still (and always) protected and safe.
On Trakx, every asset is 1:1 backed, ensuring that every crypto asset held on our platform has an equivalent reserve, allowing users to convert their assets whenever they want without liquidity issues. Security is always the top priority at Trakx, and unlike many other exchanges, we do not venture into high-risk activities such as lending or derivatives trading: our conservative approach minimizes counterparty risk and protects your investments from potential cyber threats and liquidity issues.
Bybit hack explained
The Lazarus Group (North Korean hackers) followed a well-crafted plan to steal and launder the funds, using numerous intermediary wallets and trying to split funds and use no-KYC swap services on DEXs (Decentralized Exchanges) to hide their tracks and launder money without being recognized or have their funds frozen by CEX (Centralized Exchange) platforms.
But the more important question is: How did they manage to steal the funds on ByBit?
At 02:16 PM UTC on Feb. 21, 2025, North Korean hackers made the main transaction, stealing 401,346 ETH from Bybit’s cold wallet (valued at around $1.1 billion at that time). Let’s explain it!

Source: https://etherscan.io/tx/0xb61413c495fdad6114a7aa863a00b2e3c28945979a10885b12b30316ea9f072c#internal
Step 1: Social engineering attack
In the first step, the North Korean hackers launched a sophisticated phishing attack targeting Bybit’s cold wallet signers. Through a compromised user interface, the hackers tricked the signers into approving what seemed a normal, safe transaction from a cold wallet to a hot wallet. In the user interface, it displayed all the correct details, such as a valid destination address and a trusted UI, ensuring that the transaction appeared completely safe.
Step 2: Replacement of the smart contract
Once the malicious transaction has been approved, the newly injected code modified the smart contract logic of Bybit’s multi-signature wallet. Specifically, it replaced the original smart contract with a compromised version, allowing the hackers to transfer the ownership of the cold wallet from Bybit to them.
Step 3: Unauthorized draining of assets
Following the manipulation of the wallet’s smart contract logic, the hackers drained more than $1.4 billion worth of assets from the Bybit cold wallet to the hackers’ one (401,345 ETH, along with roughly 100,000 tokens combined in stETH and mETH).
Step 4: Batch transfers of stolen funds
At this point, the attackers moved the stolen ETH in batches to avoid immediate detection. Specifically, the funds were split into 40 separate transactions of approximately 10,000 ETH each. The transfers occurred between 3:00 PM and 4:30 PM UTC, with nearly all funds leaving their primary wallets shortly after the attack.
Step 5: Asset dispersion through intermediary wallets
After the initial theft, the stolen assets were funneled through a complex network of intermediary wallets. This dispersion is a common tactic used to obfuscate the transaction trail, making it much more difficult for blockchain analysts to trace the flow of funds.
Step 6: Converting the stolen funds
The attackers then converted significant portions of the stolen ETH into other cryptocurrencies, including BTC and DAI. The North Korean attackers used various methods to launder and hide the loot, such as using decentralized exchanges (DEXs), cross-chain bridges, and no-KYC swap services. In this way, they moved the assets across different networks, which made it more complicated for authorities and investigators to track the flow of the money.
Step 7: Bybit’s response
Following the attack, Bybit, through a tweet from its CEO Ben Zhou, tried to reassure its worried users. The exchange confirmed that only the compromised cold wallet was affected and that all other assets remained secure. However, many users started moving their funds out of Bybit, worried about new possible attacks on the platform.

Source: https://x.com/benbybit/status/1892963530422505586
Security on Trakx: No exposure to Bybit or related risks
In light of recent concerns, we want to reassure our community that Trakx has no exposure to Bybit. Our risk management tools are designed to minimize counterparty risks and ensure asset protection.
Five years of uncompromised security
Trakx has operated for over five years without a single security breach. Our institutional-grade custody solutions, regulatory compliance, and cutting-edge security architecture safeguard user assets, setting us apart from platforms that have faced security failures.
A security-first approach
We follow a strict, risk-averse strategy to protect assets:
- Regulatory compliance: VASP license from a tier 1 regulator (French regulator).
- Avoid risky counterparty exposure: We carefully evaluate partners, avoiding high-risk activities. This has protected Trakx from crises like Terra Luna, FTX, Celsius and the recent Bybit hack.
- Industry-leading custody: Fireblocks’ MPC technology ensures no single point of failure, strict security policies, and resistance to both insider and external attacks.
Committed to security & transparency
Security is the foundation of Trakx. We remain dedicated to protecting assets, maintaining transparency, and upholding the highest industry standards.
If you have any questions, feel free to reach out to our team!
Enjoyed this article?


