Did Your Wallet Receive Funds From the Bybit Hack? How to Check

By Alexandr Kerya · · 6 min read

TL;DR - You can be exposed to the Bybit hack if your wallet received Ether or tokens that trace back to the February 2025 theft, and a screening tool will surface that link before an exchange does.

In February 2025, attackers drained roughly $1.46 billion from the exchange Bybit - the largest crypto theft on record. The money did not sit still. Within hours it was split, swapped, and pushed through dozens of services, and some of that value has since landed in ordinary wallets that had nothing to do with the attack. If you swap tokens, trade peer to peer, or accept payments on Ethereum, it is fair to ask whether any of it reached you. Here is how that exposure happens and how to check your own address.

How could my wallet be exposed to the Bybit hack?

Exposure does not mean you were hacked. It means tainted value reached your wallet along a chain of transactions that begins at the theft. Screening tools split this into two kinds. Direct exposure is a transfer straight from a wallet tied to the attack. Indirect exposure is the more common case: the funds passed through one or more intermediary addresses before they got to you.

The Bybit attackers, identified by the FBI and analytics firms as North Korea's Lazarus Group, moved fast to break the trail. Stolen Ether was peeled across many wallets, swapped for other assets, and bridged to other chains. Each hop adds distance, but distance does not erase the link. If you bought a token on a decentralized exchange, received an over-the-counter payment, or took funds from a counterparty who had themselves touched the laundered flow, a slice of that origin can ride along with the coins.

A flow diagram showing the Bybit cold wallet feeding the attacker address, which splits into 50 wallets of about 10,000 ETH each, then fans out through decentralized exchanges, cross-chain bridges, and mixers into many downstream wallets, one of which may be your wallet.
The stolen funds were split within hours, then layered through swaps, bridges, and mixers - which is how tainted value reaches wallets far from the original theft.

Because the laundering fanned the money out so widely, a clean-looking wallet several hops downstream can still carry measurable exposure. That is the gap most people miss: your transaction history can look unremarkable while an analytics engine still traces an inbound transfer back to a flagged source.

How were the stolen Bybit funds laundered?

The pattern is well documented by blockchain analytics firms. Within about two hours of the theft, the stolen Ether was sent to roughly 50 wallets, each holding close to 10,000 ETH. From there the funds moved in stages.

  • Staked tokens such as stETH and cmETH were swapped for plain Ether on decentralized exchanges, since wrapped assets are harder to move quietly.
  • Bybit's chief executive reported in March 2025 that the attackers had converted about 86% of the stolen Ether into Bitcoin, spreading it across many addresses.
  • Value was bridged across chains and run through mixers, including services that analytics firms named as Cryptomixer and Wasabi Wallet, to obscure the path.
  • A no-questions swap service called eXch processed an estimated $200 million of the proceeds before announcing it would shut down on May 1, 2025, after facing the threat of US sanctions.

Investigators responded just as fast. Bounties were posted within a day to crowdsource the tracing, exchanges updated their internal blacklists, and industry coordination helped freeze tens of millions of dollars of the stolen value. That is the environment your deposit now lands in: the flagged addresses are widely shared, and exchanges screen incoming funds against them.

How do I check my wallet for Bybit hack exposure?

You can start by hand. Open your address on a block explorer like Etherscan and read the inbound transfers, then click into each sender to walk back a hop and see where its funds came from. The trouble is that an explorer shows you transfers, not risk. It will not tell you that a sender two hops back belongs to the Bybit attacker cluster, a sanctioned mixer, or an exchange that already froze related deposits, and it only covers the one chain you are looking at. Rather than tracing each path manually, screen the address with Plastron - it runs the same sanctions, mixer, and stolen-funds checks an exchange uses, traces across Ethereum and six more EVM chains at once, and returns your risk score in seconds.

Whichever route you take, you are answering three questions: did any inbound transfer come from an address tied to the Bybit theft, how many hops away is it, and how large was the tainted portion relative to the rest of your balance. A large, direct, recent inflow is a serious finding. A tiny, distant, one-off transfer is usually low risk - but you still want to know it is there before an exchange does. The mechanics of hop distance are covered in how many hops from a sanctioned address still flag your wallet.

A three-step checklist panel: step one, screen the receiving address; step two, identify the tainted inbound transaction and its source; step three, decide whether to hold, document, or move the funds based on how direct and how large the exposure is.
A screen answers the three questions that matter: is there a link to the theft, how close is it, and how much of your balance does it touch.

What should I do if my wallet shows exposure?

First, do not panic and do not rush the funds onto an exchange hoping the distance hides them. Forwarding tainted value tends to spread the problem to a second wallet you control. Work it in order instead.

  • Pin down the inbound transaction that introduced the exposure and the source it traces back to, so you know exactly which transfer is the issue.
  • Leave the affected funds where they are until you understand the link. Moving them can complicate a later explanation.
  • Gather provenance. If the coins reached you through a regulated exchange withdrawal or a counterparty who passed know-your-customer checks, that paper trail gives a compliance reviewer something concrete to work with.
  • Screen before you off-ramp, not after. Knowing your score in advance lets you address a flagged inflow in a source-of-funds note rather than being blindsided by a frozen account.

A distant, low-value link to the Bybit flow is often cleared quickly once you can show where your funds came from. The same playbook applies to any hacked-protocol drain, which is covered in what to do if you received crypto from a hacked protocol. Because this attack is tied to North Korea, it also overlaps with broader sanctions screening - see how to check if your wallet is exposed to Lazarus Group.

FAQ

Can my wallet really be flagged for funds from the Bybit hack?

Yes. Analytics firms labelled the attacker wallets quickly, and exchanges screen incoming deposits against those labels. If a transfer in your history traces back to the theft, a screen can surface it as stolen-funds exposure, even when the link is several hops away.

How far back do exchanges trace stolen Bybit funds?

There is no fixed cutoff. Screening engines walk the transaction graph back to the source rather than stopping at a set number of hops. Distance lowers the weight of the exposure, but it does not reset a tainted history to clean.

Is a small Bybit-linked transfer a problem?

Usually less of one. A tiny, distant, one-off inflow generally scores low, and a tolerant exchange may pass it. A conservative exchange can still route it to manual review, so it is worth knowing the link exists and being ready to explain it.

What does a block explorer miss compared with a screening tool?

An explorer shows transfers but not risk. It will not label a sender as part of the attacker cluster, a sanctioned mixer, or a frozen-deposit address, and it only covers one chain. A screening tool attributes each source and aggregates the exposure into a single cross-chain score.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

How to Check If Your Wallet Is Exposed to Lazarus Group (North Korea) CryptoWhat to Do If You Received Crypto From a Hacked ProtocolHow Many Hops From a Sanctioned Address Still Flag Your Wallet?Can Wallet Screening See Through an EIP-7702 Delegation?