NewsCryptoBybit Strengthens Security Defences Against Evolving Crypto Threats, Intercepting $700 Million in Potential User Losses

Bybit Strengthens Security Defences Against Evolving Crypto Threats, Intercepting $700 Million in Potential User Losses

Author: ChainWire·

Key Takeaways

  • The February 2025 breach, in which roughly $1.46 billion was stolen through a manipulated signing interface on Bybit's multisig cold wallet, remains the largest cryptocurrency theft on record and was publicly attributed by the FBI to North Korea's Lazarus Group.
  • In the first half of 2026, Bybit blocked more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users from potential losses exceeding $700 million, with 95% of reviews completed within ten minutes.
  • Bybit expanded monitoring to 100% of business-relevant on-chain activity and handled 10 security incidents involving listed token projects during H1 2026 with zero losses to the platform.
  • AI-assisted security auditing identified high-severity vulnerabilities at three to five times the rate of manual review, and automation reduced the time from security assessment to testing from about two weeks to two hours.
  • Beyond technical controls, Bybit has pursued legal action against North Korea and the Lazarus Group while working with law enforcement and blockchain-intelligence firms to trace and recover stolen assets.
Bybit Strengthens Security Defences Against Evolving Crypto Threats, Intercepting $700 Million in Potential User Losses

DUBAI, UAE, Aug. 19, 2026 /PRNewswire/ — Bybit, the world's second-largest cryptocurrency exchange by trading volume, has strengthened and expanded its security systems following the February 2025 theft of approximately $1.46 billion in digital assets, moving toward a model designed to detect threats earlier, respond faster and continuously adapt as attackers adopt new techniques, including artificial intelligence.

That February 2025 theft remains the largest cryptocurrency theft on record. The attackers manipulated the signing interface used for transactions from Bybit's multisig cold wallet — a storage tier long treated as among the hardest for outsiders to reach — and the FBI publicly attributed the incident to North Korea's Lazarus Group. The loss also landed amid a broader wave of industry incidents, with blockchain-analytics firms tracking more than $2 billion in crypto assets stolen in hacks during 2024 alone, the majority of it attributed to North Korea-linked actors.

In its H1 2026 Risk & Security Report, covering January 1 through June 15, Bybit details the operation of three layers of protection: user and account security, real-time on-chain monitoring, and AI-assisted security operations. The objective is not simply to add more controls, the exchange explains, but to build a security system that can continuously learn from emerging threats and reduce the time between detection and intervention.

"The cybersecurity arms race has entered an era of minutes. Using AI to strengthen our security and risk-control capabilities, while securing the AI systems themselves, is our top priority, with human judgement remaining at the centre of critical security decisions," said David Zong, Head of Group Risk Control and Security at Bybit.

From incident response to always-on defence

Sophisticated attackers can exploit weaknesses at the intersection of technology, human behaviour and operational processes. In view of ongoing security challenges, Bybit has been expanding its security architecture across account protection, on-chain monitoring, fraud detection, security testing and incident response. The result, according to the exchange, is a shift from reactive incident response to always-on defence.

In H1 2026, Bybit intercepted more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users from more than $700 million in potential losses. The average initial review took 4.7 minutes, with 95% of reviews completed within 10 minutes.

The company also identified approximately $212 million in potential fraud-linked onchain funds and blacklisted more than 10,000 malicious addresses, using on-chain behavioural analysis and AI-assisted monitoring to identify emerging fraud patterns.

Watching the blockchain as well as the platform

Bybit has expanded monitoring to 100% of business-relevant on-chain activity, including listed token contracts, ecosystem contracts and the company's cold, warm and hot wallets. Cold wallets are kept offline and are generally treated as the most secure tier of exchange storage, while hot wallets remain internet-connected to support day-to-day withdrawals.

During the first half of 2026, Bybit identified and handled 10 security incidents involving listed token projects, with zero resulting losses to the platform. In eight cases, Bybit completed the relevant emergency responses before other major exchanges, while two incidents were detected before the affected projects themselves identified the attacks.

AI is shortening the defensive cycle

As attackers use automation and AI to accelerate reconnaissance and vulnerability discovery, Bybit is applying AI across security operations, code auditing and penetration testing. The concern is shared across the industry: security teams at Microsoft and OpenAI have published research documenting state-backed threat groups experimenting with generative AI to accelerate reconnaissance, vulnerability research and social engineering.

More than 100,000 security alerts were processed with AI-assisted analysis during H1. Bybit's AI-assisted security auditing identified high-severity vulnerabilities at 3–5 times the rate of manual review. Automation also reduced the time required to move from security assessment to testing from approximately two weeks to two hours, enabling the exchange to identify and investigate potential vulnerabilities at a substantially faster pace.

Its automated red-team platform assessed 1,489 public-facing assets and identified more than 100 high-severity vulnerabilities. The average time from asset discovery to initial penetration testing was reduced to under 24 hours, compared with a traditional manual cycle measured in weeks.

AI is being used primarily to increase the scale and speed of detection and testing, while human security specialists remain responsible for complex threat decisions. The combination of AI-driven scale and human oversight reflects the three-layer architecture outlined in the report.

A global fight to hold attackers accountable

Bybit's response extends beyond technical controls. The exchange has worked with law enforcement, blockchain intelligence firms and industry partners to trace and recover stolen assets, and it has pursued legal action against North Korea and the Lazarus Group, seeking accountability and the recovery of assets connected to the attack. The difficulty of that path was visible after the 2025 theft, when public blockchain tracking showed the proceeds being dispersed through mixers and cross-chain bridges, and only a small fraction of the stolen funds was frozen in the months that followed.

For Bybit, the broader security objective is to make attacks harder to execute and less profitable. That means not only strengthening the platform itself, but improving coordination across exchanges, blockchain networks, investigators and law enforcement.

Security is an ongoing process

The 2026 H1 Security Report is a testament to Bybit's transparency pledge and marks a chapter in the exchange's security evolution. As attackers adopt new technologies and methods, increasingly aided by the growing prevalence of AI, Bybit says its defensive systems are engineered to evolve in kind. For readers, the report's headline metrics — withdrawal-review times, intercepted amounts, incident counts and vulnerability-discovery rates — provide measurable baselines against which future security disclosures can be compared as both attack techniques and defences evolve.

The detailed security architecture, methodologies and supporting metrics are available in the H1 2026 Risk & Security Report.

Disclaimer: Unless otherwise stated, figures cover January 1 through June 15, 2026 and are based on Bybit's internal security, risk and engineering systems. The metrics are self-reported by Bybit and are intended to provide transparency into its security operations. They should not be interpreted as a guarantee of future security performance or as a comparative ranking of exchanges.

About Bybit

Bybit is The New Financial Platform. Built on the belief that every person should have access to every financial opportunity on earth, the exchange says it is building the first intelligent platform that connects anyone, anywhere to the world's finance. Trusted by more than 80 million users worldwide, Bybit brings together investing, trading, payments, and wealth-building in a single secure and intelligent ecosystem. Through the combination of AI-powered technology, deep global liquidity, robust security, and transparent operations, Bybit aims to make global finance more accessible, efficient, and empowering for everyone.

Built for everyone. Powered by intelligence. Open to the world.

Learn more at Bybit.com. For more details about Bybit, please visit Bybit Press. For media inquiries, please contact media@bybit.com.