The Biggest Theft in Cryptocurrency History “Bybit Exploit”
Full Investigation (Part 2)
AML Crypto team publishes exclusive investigation of ByBit hack for more than $1.4 billion. We publish the most detailed report with a graph of blockchain transactions and lists of addresses of the attackers.
Get advice from AML Crypto experts
Not even 24 hours later, the stolen ByBit funds are back in motion. Surely, many crypto research analyst teams, intelligence agencies around the world and Bybit's compliance department are following every transaction.
However, apart from Zach, no one publishes detailed reports and lists of hacker addresses. We decided to rectify this and show the public what's going on right now. By publishing the most detailed report with a graph of blockchain transactions and lists of the attackers' addresses.
Attackers using cryptocurrency exchanges
As part of the laundering process, criminals used the Exch crypto exchange.
Screenshot from the Bholder solution from the AmlCrypto team
When the Bybit team realised that some of the stolen funds had gone to cryptocurrency exchange Exch they tried contacting and requesting assistance:
Apparently Exch remembered past misunderstandings with Bybit. He replied to their mail, plus published data about communication with Bybit on the BitcoinTalk forum thread.
In the meantime, transactions do not stop leaving from addresses under the attacker's control, confusing the trail more and more.
UPD: 22.02.2025 17:00 UTC Attackers are constantly creating new addresses and transferring funds between them, seeking not so much to hide assets as to buy time and complicate the scheme, making subsequent investigations more difficult.
We at AML crypto analyse every transaction, record every attacker's blockchain address, add it to the Btrace and Bholder databases, notify crypto exchanges and exchanges about risky addresses, and improve scoring algorithms.
In some cases, analysis is made clearer by visualizing the flow of funds. Contact each service to obtain valuable leads for a productive investigation.
Blockchain addresses leveraged by attackers (1868 at this time):
Want to learn more and get expert advice? Leave your email and we will contact you promptly!
Check blockchain address using Btrace
In seconds, determine the risk level of the counterparty’s address, find out the source of his funds and make an informed decision about interacting with him.