Why CZ Urged Bybit to Pause Withdrawals After the $1.46 Billion Safe{Wallet} Hack
Key Takeaways
- β’A phishing attack on the Safe{Wallet} signing interface enabled the theft of $1.46 billion from Bybit's Ethereum multisig cold wallet on February 21, 2025, the largest exchange-level exploit on record.
- β’Changpeng Zhao publicly recommended that Bybit temporarily halt withdrawals, describing the move as crisis-containment protocol to buy time for assessing exposure rather than a signal of insolvency.
- β’Bybit kept withdrawals open and processed 99.994% of more than 350,000 withdrawal requests within 10 hours, completing all requests in under 12 hours.
- β’Blockchain tracing firm TRM Labs reported that at least $160 million of the stolen funds moved through illicit channels within 48 hours, with more than $400 million moved by February 26.
- β’The FBI linked the attack to North Korean hackers, and the breach drew new attention to the user-interface layer of multisig wallets as a vulnerability alongside on-chain smart contracts.

Changpeng Zhao publicly urged Bybit to pause withdrawals on February 21, 2025, hours after a phishing attack on the Safe{Wallet} interface drained $1.46 billion from a single Ethereum multisig cold wallet, the largest exchange-level exploit on record. His reasoning was straightforward: when the scope of a breach is still unknown, limiting outflows buys time to assess exposure and prevents potential contagion from compounding an already catastrophic loss.
What Happened in the Bybit Hack
The attack targeted Bybit's Ethereum multisig cold wallet on February 21, 2025. According to Bybit's official incident timeline, a phishing attack against the Safe{Wallet} interface altered the wallet's smart-contract logic, allowing the attacker to redirect a routine transfer and drain the wallet's full balance.
The compromised wallet held 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH, together worth $1.46 billion at the time of the exploit. No other Bybit wallets or user funds beyond that single cold wallet were reported as compromised.
Shortly after news of the exploit broke, CZ posted publicly recommending that Bybit temporarily halt withdrawals, framing the suggestion as standard crisis-containment protocol rather than an indication of broader insolvency. CoinDesk reported that CZ also offered assistance, a signal that the recommendation came from an industry-support posture rather than competitive commentary. The advice set the stage for one of the incident's central questions: whether an exchange under attack should halt outflows or keep them running.
Why CZ Recommended Pausing Withdrawals
The Containment Rationale
The core logic behind a temporary withdrawal pause after an exploit is asymmetric risk management. In the immediate aftermath of a smart-contract compromise, the full attack surface is rarely known: whether other wallets share the same signing infrastructure, whether additional phishing vectors are live, or whether the attacker retains some form of privileged access. A pause creates a window to audit custody architecture before any further outflows leave the exchange. In that framing, the pause is not a judgment about solvency but a tool for buying investigative time.
CZ's recommendation reflected a well-established playbook in exchange security: contain first, investigate second, resume with confidence third. A $1.5 billion loss is already material; an additional few hundred million drained during an uncontrolled withdrawal surge while the security team is still mapping the breach compounds the damage and reduces recovery options. That arithmetic, in CZ's framing, is what makes the first hours the most consequential.
Bybit Chose to Keep Withdrawals Open
Bybit took a different path. Rather than pause, the exchange kept withdrawals open and processed them at scale, ultimately handling 99.994% of more than 350,000 withdrawal requests within 10 hours, with all requests completed in under 12 hours. That operational throughput was Bybit's primary counterargument: demonstrating solvency through performance rather than assertion.
The tension between the two approaches is the real risk-management lesson. A pause protects the exchange from residual attack vectors but risks triggering the bank-run dynamic it is meant to prevent; continuing withdrawals demonstrates solvency but leaves the exchange exposed if the initial breach assessment was incomplete. Neither choice is risk-free, which is why the decision hinges on how quickly the security team can scope the exploit.
For users watching an active exchange incident, the most reliable signal is the quality of official communications rather than the withdrawal policy itself. Exchanges that disclose the specific compromised component, the isolation steps taken, and a timeline for third-party audit are demonstrating the kind of operational transparency that reduces the informational asymmetry driving withdrawal pressure. Bybit's granular incident timeline is a case study in that approach.
Stolen Funds Moved Within Hours
Post-incident blockchain tracing reinforced how quickly stolen funds move once an exploit succeeds. TRM Labs reported that at least $160 million had moved through illicit channels within 48 hours of the exploit, with more than $400 million moved by February 26. The FBI publicly linked the attack to North Korean hackers on that same date, consistent with the Lazarus Group's established pattern of rapid cross-chain laundering designed to outpace exchange freezes and blacklist responses.
This pace underlines why the containment window CZ referenced is measured in hours, not days, and why pausing withdrawals on exchanges that hold bridging liquidity or share custody infrastructure can affect recovery odds in the DeFi stack as well. The exchange-flow implications of rapid, large-scale laundering are relevant context for anyone monitoring on-chain risk.
New Scrutiny on Multisig Wallet Interfaces
The incident also renewed scrutiny of multisig wallet UIs as an attack surface. The Safe{Wallet} phishing vector used here targeted the signing interface rather than the underlying smart contract, a distinction that matters for protocol risk assessments: the contract logic was sound, but the human-facing layer was compromised. Governance frameworks and custody standards in DeFi increasingly need to account for UI-layer attacks alongside on-chain vulnerabilities, a concern directly relevant to any protocol that relies on Safe or similar multisig infrastructure for treasury management. Regulatory attention on these gaps has already been flagged in broader crypto regulatory developments throughout 2025.
Taken together, the episode shows that withdrawal policy is a means rather than an end: whichever route an exchange takes in the first hours of a breach, the decisive factors are how quickly its security team can scope the exploit and how clearly it communicates what it finds. The indicators worth tracking from here are the ones that shaped the incident's first days: further movement of the stolen funds as tallied by tracing firms, and updates to Bybit's official incident timeline.