Bybit attack shows ‘fundamental’ need for institutional-grade security: Ledger

This year, so far, has been the “worst year” for cybercrime in history, Ledger CTO Charles Guillemet told Blockworks

article-image

Ledger chief technology officer Charles Guillemet | Permissionless III by Mike Lawrence for Blockworks

share


This is a segment from the Empire newsletter. To read full editions, subscribe.


Bybit’s hack, which took place Friday morning, has sparked a slew of different conversations from security experts about how Bybit handled the situation. Last night, Bybit CEO Ben Zhou said the exchange was able to fully close the ETH gap and promised an audit report soon. 

Loading Tweet..

I had the opportunity this weekend to chat with Ledger’s chief technology officer Charles Guillemet, who told me that, for the foreseeable future, this year is so far “the worst year for cybercrime in history.” 

Ledger fell victim to an attack just two years ago after a former employee was phished, giving attackers access to the package manager. Roughly $600,000 was stolen from Ledger users, a far smaller number than the $1.4 billion that Bybit suffered, but it led to Ledger removing the blind signing ability back in June of last year. Ledger’s CEO (and DAS speaker) Pascal Gauthier said in a statement that Ledger’s offered to support Bybit.

“This incident highlights once again that our industry needs to move beyond trust-based security models as attackers become more sophisticated. We can’t keep signing blind cheques and expecting it to be ok. The key evolution we’re seeing is the shift toward enterprise-grade security solutions that combine Clear Signing with robust governance frameworks,” Guillemet said. 

His point is that attackers — like Lazarus, the North Korean group linked to the attack — are evolving and the current security measures used by the industry need to evolve as well. 

“We need proactive security infrastructure that eliminates vulnerabilities like blind signing,” he explained. 

Loading Tweet..

Guillemet also noted he has some concerns that this isn’t the end of Lazarus targeting Bybit. He said that he believes Lazarus “compromised several” of Bybit’s endpoints. 

“This suggests that Bybit’s machines and networks were compromised. I know pretty well their tactics and it’s possible that they are still at work attempting a lateral move to compromise other parts of Bybit’s IT,” he told me, noting that this is clearly speculative but it’s better safe than sorry in these situations. 

“Pausing certain central functions of the exchange could have been wise, waiting for forensic investigations.”

I asked Guillemet what kind of lessons we can learn from this — especially given that $1.4 billion seems to mark this attack as the biggest digital heist in history of any kind, and not just the biggest crypto heist of all time.

“We’ve been saying this for years now. When the stakes are high, attackers raise the bar for their attacks. They won’t stop here. And others will come. Stop signing blank cheques — instead, use enterprise-grade security and custody solutions built for managing a significant amount of value,” he said.

“Institutional-grade security isn’t optional – it’s fundamental.”


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template (11).png

Research

Union’s technical design brings measured improvements to crosschain interoperability. By combining a consensus-verified hub with novel constructs like state lenses and ZK proofs for client updates, Union achieves an interoperability protocol that is highly performant, trust-minimized, and scalable.

article-image

The SEC is still working on a framework for token sales.

article-image

Bubbles are how markets create the future

article-image

21Shares files for active crypto ETF, leveraged funds to “deliver strategies that adapt in real time to a rapidly evolving market”

article-image

Supporters call the proposal a credit line to scale crvUSD, but critics warn it could set a dangerous precedent

article-image

New PeerDAS design raises throughput ahead of Fusaka upgrade