Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

Prediction markets are ditching the 'casino' label to become a regular part of how people track the news

May 2, 2026

Altura Enables On-chain Lending With AVLT on Morpho

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Over 500 Phishing Domains Emerge Following Bybit Heist
Over 500 Phishing Domains Emerge Following Bybit Heist
Security

Over 500 Phishing Domains Emerge Following Bybit Heist

February 17, 2026No Comments2 Mins Read

A large number of phishing campaigns emerged in the aftermath of the Bybit heist, designed to siphon cryptocurrency from its customers, according to BforeAI.

The security vendor detected 596 suspicious domains originating from at least 13 different countries in the three weeks following news of the biggest crypto theft in history.

Dozens of these domains spoofed the cryptocurrency exchange itself, many using typosquatting techniques and including keywords such as “refund,” “wallet,” “information,” “check” and “recovery.”

“There were also instances of popular crypto keywords such as ‘metaconnect,’ ‘mining,’ and ‘airdrop,’ as well as the use of free hosting and subdomain registration services such as Netlify, Vercel, and Pages.dev,” BforeAI said.

“The use of free hosting services and dynamic subdomains is a widely used tactic in this dataset. Many phishing pages are hosted on platforms that provide fast, anonymous deployment without requiring domain purchases.”

Interestingly, the largest number of confirmed malicious domains was registered in the UK.

Read more on phishing: Phishing Campaigns Use SVB Collapse to Harvest Crypto

Bybit said at the time of the incident that no customers would be left out of pocket by the incident, but that didn’t stop the scammers from trying to create a sense of anxiety and urgency.

Many of the phishing websites were designed to resemble a recovery service for customers that may have lost funds in the heist, with some purporting to be a “Bybit Help Center.”

The end goal appears to have been to trick victims into entering their Bybit/crypto passwords.

A few weeks after the heist, phishing campaigns segued from “withdrawals, information and refunds” via lookalike Bybit sites, to offering “crypto and training guides” and exclusive rewards in order to lure would-be investors, the report claimed.

See also  New ‘Chihuahua Stealer' Targets Browser Data and Crypto Wallets

“Despite the shift to these crypto and training guides, the campaigns maintained a connection to the earlier withdrawal scams by including ‘how to withdraw from Bybit guides.’ This creates a flow of traffic between learning resources fakes and withdrawal phishing attempts,” BforeAI explained.

North Korean hackers were blamed for the attack on Bybit, which is thought to have cost the firm nearly $1.5bn in stolen crypto.

It helped Q1 2025 to an infamous record: hackers stole almost $1.7bn in the quarter, more than any other in history.

Source link

Bybit Domains emerge Heist Phishing

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

The Magic Show That Doesn’t Seem So…Magical

November 3, 2023

MITRE Launches New Framework to Tackle Crypto Risks

February 12, 2026

Magic Eden Launches LayerZero for Token Swaps

October 13, 2023

Type above and press Enter to search. Press Esc to cancel.