February 2025, in full
On 21 February 2025 attackers compromised the signing flow for a cold-wallet transfer and removed roughly $1.5bn in ETH — the largest theft in the sector's history, later attributed by the FBI to North Korean actors. The mechanism matters: a Safe{Wallet} developer machine was compromised and tampered JavaScript showed Bybit's signers a routine transaction while altering what they were actually approving.
What followed is the reason the venue is still in this table. Bybit replaced the missing assets from its own balance sheet and borrowed liquidity, honoured withdrawals throughout the run that followed, and published a timeline. A company that can absorb a loss of that size without pausing redemptions has demonstrated something about its balance sheet, even as the incident demonstrated something unflattering about its operational controls.
The trading product was never the problem
Execution quality on perpetuals is excellent, taker fees sit at the low end of the category, funding is published per market, and new markets list quickly. For derivatives traders this is the venue's actual argument, and it is a strong one.
Thin regulatory cover
A licence in Dubai and registrations in several smaller markets is a lighter footprint than the licensed Western venues carry, and Bybit has been fined or restricted in some jurisdictions and has withdrawn from others, including the UK retail market and France. Fiat access mostly runs through third-party providers rather than direct bank rails.