Following the largest hack in the history of the crypto industry on February 21, Bybit saw more than $4 billion withdrawn from the exchange, equivalent to about 50% of its total assets. According to data from DeFiLlama, the balance on Bybit-related wallets dropped from $16.9 billion to $11.2 billion.
Bybit CEO Ben Zhou said the exchange is working hard to investigate the incident and ensure that withdrawals are processed quickly for customers. In a discussion on X Spaces, Zhou revealed that immediately after the attack, he directed the entire team to focus on helping users withdraw their funds and answering questions about the incident.

Ben Zhou, CEO of Bybit
Bybit struggles to handle liquidity amid wave of withdrawals
Zhou said the attack resulted in the hackers stealing about 70% of the ETH that customers held on the exchange. To ensure withdrawals, Bybit was forced to borrow ETH from outside sources. However, it is worth noting that ETH was not the most withdrawn asset—most users withdrew stablecoins from the exchange.
Bybit had enough reserves to meet withdrawal requests, but the situation became more tense when Safe, the decentralized custody protocol that Bybit uses, decided to temporarily disable the smart wallet function to ensure system security.

Total value on Bybit wallet | Source: DeFiLlama
Safe provides a smart contract wallet solution for digital asset management and has been integrated by several exchanges to enhance security. According to Zhou, 3 billion USDT of Bybit is in a Safe wallet that was temporarily closed, making it difficult for the exchange to disburse.
While Safe claims to have found no evidence of a breach, the platform has proactively disabled some features as a precaution. While Bybit has sought to withdraw the funds, withdrawal requests have continued to mount, with millions of dollars being withdrawn from the platform in the first two hours after the incident.
To address this, Zhou asked the security team to work with Safe to find a more efficient withdrawal method. Ultimately, the engineering team developed a new software that used Etherscan-based source code to manually verify transaction signatures, allowing Bybit to release $3 billion worth of stablecoins and continue processing withdrawals.
Bybit CEO Discusses the Possibility of Rolling Back the Ethereum Blockchain
Arthur Hayes, co-founder of BitMEX and a large holder of ETH, recently asked Vitalik Buterin, founder of Ethereum, to roll back the Ethereum network to support the Bybit exchange following a major cyberattack.
When asked about this issue, he replied:
“I'm not sure if this is an individual decision. In the spirit of blockchain, perhaps this should be put to a vote to see what the community wants, but I can't say for sure.”
Ethereum blockchain rollback is the process of returning the network to a state before an event, such as a hack, by undoing transactions. Ethereum previously underwent a rollback after the 2016 DAO hack, when 60 million ETH was stolen. This event led to a hard fork, splitting Ethereum into Ethereum Classic (ETC), the chain that maintains the old transaction history, and Ethereum (ETH), the current main chain that uses a proof-of-stake (PoS) consensus mechanism.
However, a rollback in the Bybit hack is unlikely because it requires community consensus, affects the immutability of the blockchain, and sets a dangerous precedent. Instead, transaction tracing and cooperation with authorities will be prioritized.
Bybit Starts Buying Back ETH
According to Arkham, the address believed to be Bybit (0x2E…1b77) received 100 million USDT from 0xEC…B5E76 10 hours ago and transferred 50 million USD to the OTC addresses of Galaxy Digital and FalconX 7 hours ago. In total, the exchange purchased 36,900 ETH and deposited it to Bybit. In addition, Bybit also purchased an additional 17,500 ETH OTC from Galaxy Digital.
Lazarus Group Continues Moving Stolen Assets
According to data from Arkham Intelligence, the Lazarus hacker group currently holds approximately 489,395 ETH, worth approximately $1.3 billion, of which 15,000 cmETH has been successfully recovered by mETH Protocol.

Funds linked to Bybit hackers | Source: Arkham Intelligence
Believed to be linked to North Korea, the group repeatedly moved the stolen funds through multiple wallets to conceal their origins and laundered them on the blockchain.
To speed up the asset recovery process, on February 22, Bybit announced a bounty program worth 10% of the stolen funds, up to $140 million, for white hat hackers who help track and recover the funds.
Bybit CEO also expressed gratitude to the organizations and individuals in the industry who supported the exchange after this historic hack.
Meanwhile, Tether CEO Paolo Ardoino confirmed that the company had frozen 181,000 USDT related to the hack. Bitget CEO Gracy Chen also announced that the exchange would block all transactions from wallets linked to the Lazarus group.
Source: https://tapchibitcoin.io/bybit-doi-mat-lan-song-rut-tien-4-ty-usd-ceo-ben-zhou-thao-luan-rollback-ethereum.html