Bybit Says It Blocked $700M in Potential Losses After $1.46B Hack
Key Takeaways
- •Bybit blocked more than 30,000 suspicious withdrawal requests in the first half of 2026, protecting nearly 20,000 users, with initial risk reviews averaging 4.7 minutes.
- •The exchange identified approximately $212 million in potentially fraud-linked on-chain funds and blacklisted more than 10,000 malicious addresses during the period.
- •AI-assisted audits detected high-severity vulnerabilities three to five times more frequently than manual reviews, while automation cut the time between security assessment and testing from about two weeks to two hours.
- •Bybit handled 10 security incidents involving listed token projects in H1 2026 without recording losses to the platform, including two cases detected before the affected projects identified the attacks themselves.
- •The report follows the February 2025 theft of $1.46 billion from Bybit, attributed by the FBI to North Korea's Lazarus Group, which remains the largest single cryptocurrency theft on record.

Cryptocurrency exchange Bybit says it intercepted more than $700 million in potential user losses during the first half of 2026, as the Dubai-based company continued expanding its security systems following the $1.46 billion theft it suffered in February 2025.
The figures were disclosed Tuesday in Bybit's H1 2026 Risk & Security Report. According to the report, the company's security work over the period concentrated on three areas: user and account security, real-time on-chain monitoring, and AI-assisted security operations. The disclosure continues a broader industry shift toward regular transparency reporting that accelerated after the collapse of the FTX exchange in November 2022, which pushed trading platforms to publish proof-of-reserves attestations and other trust metrics.
Blocked Withdrawals and Fraud-Linked Funds
Bybit said it blocked more than 30,000 suspicious withdrawal requests during the first six months of the year, protecting nearly 20,000 users from potential losses. Initial risk reviews took an average of 4.7 minutes, with 95% of reviews completed within 10 minutes.
The exchange also identified approximately $212 million in potentially fraud-linked on-chain funds and blacklisted more than 10,000 malicious addresses, according to the report.
Expanded Real-Time On-Chain Monitoring
The security push follows one of the largest cryptocurrency thefts on record. In February 2025, roughly $1.46 billion in digital assets was stolen from the exchange after attackers compromised the signing interface used for its Ethereum multisig cold wallet during a routine transfer, tricking signers into approving a transaction that silently altered the wallet's underlying logic. Roughly 400,000 ETH was drained in the attack. The U.S. Federal Bureau of Investigation later attributed the theft to North Korea's Lazarus Group, a state-sponsored hacking unit sanctioned by the U.S. Treasury and linked by United Nations monitors to earlier crypto thefts used to fund the country's weapons programs. Since then, Bybit says it has expanded its ability to monitor transactions and respond to threats across its infrastructure.
The incident remains the largest single cryptocurrency theft on record, and it accounted for the majority of the more than $2 billion that blockchain analytics firms estimated was stolen from crypto platforms across 2025.
The company said it now monitors 100% of business-relevant on-chain activity, including listed token contracts, ecosystem contracts, and its cold, warm, and hot wallets.
During the first half of 2026, Bybit said it handled 10 security incidents involving listed token projects without recording losses to the platform. In eight cases, the company said it completed emergency responses before other major exchanges, and in two cases it detected the incidents before the affected projects identified the attacks themselves.
Bybit said the goal is to shorten the time between detecting suspicious activity and taking action, as attackers adopt new techniques.
AI Tools Accelerate Security Testing
Bybit is also increasing its use of AI and automation in security operations. During the first half of 2026, AI-assisted analysis processed more than 100,000 security alerts, according to the report, and the company said AI-assisted audits identified high-severity vulnerabilities three to five times more frequently than manual reviews.
Automation also reduced the time between security assessment and testing from about two weeks to two hours, the company said.
An automated red-team platform assessed 1,489 public-facing assets and identified more than 100 high-severity vulnerabilities. Bybit said the average time from discovering an asset to beginning initial testing fell to less than 24 hours, compared with weeks under its previous manual process.
Despite the increased use of automation, Bybit said human security specialists remain responsible for complex security decisions.
Security Architecture After the 2025 Breach
The new figures are part of Bybit's effort to demonstrate how its security architecture has changed since the 2025 breach. The exchange has said it has worked with law enforcement agencies, blockchain intelligence firms, and industry partners to trace assets linked to the theft. It has also pursued legal action against North Korea and the Lazarus Group over assets linked to the attack. According to blockchain analysts, tracing the stolen ETH has been complicated by the movement of the funds through mixing services, cross-chain bridges, and decentralized exchanges in the months after the attack.