$85,326+0.48%
BTC7D TREND
$2,702+0.65%
ETH7D TREND
$121.61+1.42%
SOL7D TREND
$788.53-0.16%
BNB7D TREND
DeFi Data →
Risk
Risk

Why CZ Urged Pausing Withdrawals After Bybit Hack

Changpeng Zhao publicly urged Bybit to pause withdrawals on February 21, 2025, hours after a phishing attack on the Safe{Wallet} UI drained $1. 46 billion from a single Ethereum multisig cold wallet, making it the largest exchange-level exploit on record.

·5 min readMakeDefilibanpreferred onGoogle

Changpeng Zhao publicly urged Bybit to pause withdrawals on February 21, 2025, hours after a phishing attack on the Safe{Wallet} UI drained $1.46 billion from a single Ethereum multisig cold wallet, making it the largest exchange-level exploit on record. CZ’s reasoning was straightforward: when the scope of a breach is still unknown, limiting outflows buys time to assess exposure and prevents potential contagion from compounding an already catastrophic loss.

What Happened in the Bybit Hack Response

The attack targeted Bybit’s Ethereum multisig cold wallet on February 21, 2025. According to Bybit’s official incident timeline, a phishing attack against the Safe UI altered the wallet’s smart-contract logic, allowing the attacker to redirect a routine transfer and drain the wallet’s full balance. For related coverage, see BlockCon Global Confirms 2026 Speaker Roster: Investors, iGaming Operators and the Web3 infraestructure.

The compromised wallet held 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH, totaling $1.46 billion at the time of the exploit. No other Bybit wallets or user funds beyond that single cold wallet were reported as compromised. For related coverage, see Traders Fair Uzbekistan 2026: A New Chapter for Central Asia’s Trading Community Begins in Tashkent.

Compromised cold-wallet loss
$1.46 billion
Reported by Bybit for the single compromised Ethereum multisig cold wallet.

Shortly after news of the exploit broke, CZ posted publicly recommending that Bybit temporarily halt withdrawals, framing the suggestion as standard crisis-containment protocol rather than an indication of broader insolvency. CoinDesk reported that CZ also offered assistance, signaling that the recommendation was made from an industry-support posture rather than as competitive commentary. For related coverage, see VanEck Updates BNB ETF Filing to Add Staking Objective.

Why CZ Recommended Pausing Withdrawals

The Containment Rationale

The core logic behind a temporary withdrawal pause after an exploit is asymmetric risk management. In the immediate aftermath of a smart-contract compromise, the full attack surface is rarely known: whether other wallets share the same signing infrastructure, whether additional phishing vectors are live, or whether the attacker retains some form of privileged access. A pause creates a window to audit custody architecture before any further outflows leave the exchange.

CZ’s recommendation reflected a well-established playbook in exchange security: contain first, investigate second, resume with confidence third. A $1.5 billion loss is already material; an additional few hundred million drained during an uncontrolled withdrawal surge while the security team is still mapping the breach compounds the damage and reduces recovery options.

What Users Should Monitor in Official Updates

Bybit chose a different path. Rather than pause, the exchange kept withdrawals open and processed them at scale, ultimately handling 99.994% of more than 350,000 withdrawal requests within 10 hours, with all requests completed in under 12 hours. That operational throughput was Bybit’s primary counterargument: demonstrating solvency through performance rather than assertion.

Withdrawal requests processed within 10 hours
99.994%
Of more than 350,000 requests, according to Bybit’s incident timeline.

The tension between those two approaches is the real risk-management lesson. A pause protects the exchange from residual attack vectors but risks triggering the bank-run dynamic it is meant to prevent; continuing withdrawals demonstrates solvency but leaves the exchange exposed if the initial breach assessment was incomplete. Neither choice is risk-free, which is why the decision hinges on how quickly the security team can scope the exploit.

For users watching an active exchange incident, the most reliable signal is the quality of official communications rather than the withdrawal policy itself. Exchanges that disclose the specific compromised component, the isolation steps taken, and a timeline for third-party audit are demonstrating the kind of operational transparency that reduces the informational asymmetry driving withdrawal pressure. Bybit’s granular incident timeline is a case study in that approach.

Post-incident blockchain tracing reinforced how quickly stolen funds move once an exploit succeeds. TRM Labs reported that at least $160 million had moved through illicit channels within 48 hours of the exploit, with more than $400 million moved by February 26. The FBI publicly linked the attack to North Korean hackers on that same date, consistent with the Lazarus Group’s established pattern of rapid cross-chain laundering designed to outpace exchange freezes and blacklist responses. This pace underlines why the containment window CZ referenced is measured in hours, not days, and why pausing withdrawals on exchanges that hold bridging liquidity or share custody infrastructure can affect recovery odds in the DeFi stack as well. The exchange-flow implications of rapid large-scale laundering are relevant context for anyone monitoring on-chain risk, similar to dynamics tracked in broader institutional capital flow analysis.

The incident also renewed scrutiny of multisig wallet UIs as an attack surface. The Safe{Wallet} phishing vector used here targeted the signing interface rather than the underlying smart contract, a distinction that matters for protocol risk assessments: the contract logic was sound, but the human-facing layer was compromised. Governance frameworks and custody standards in DeFi increasingly need to account for UI-layer attacks alongside on-chain vulnerabilities, a concern directly relevant to any protocol that relies on Safe or similar multisig infrastructure for treasury management. Regulatory attention on these gaps has already been flagged in broader crypto regulatory developments throughout 2025.

TLDR Keypoints

  • CZ recommended pausing withdrawals after the Bybit hack as a standard containment measure, arguing that a $1.46 billion cold-wallet loss was sufficient justification to prioritize securing the remaining custody infrastructure before resuming outflows.
  • A temporary withdrawal pause is a risk-management tool designed to buy time for breach scoping; its value depends entirely on how quickly the exchange can audit its custody architecture and communicate findings to users.
  • Bybit declined to pause and processed over 350,000 withdrawal requests within 10 hours, demonstrating solvency through operational performance; TRM Labs tracked at least $160 million in illicit fund movements within 48 hours, illustrating how narrow the post-exploit containment window actually is.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Defiliban · Oliver Benjamin

Oliver Benjamin

Oliver Benjamin

@oliver-benjamin