Bybit says its upgraded security systems prevented more than $700 million in potential user losses during the first half of 2026, marking a major shift in the exchange’s security strategy following the devastating $1.46 billion hack it suffered in February 2025.
According to Bybit’s H1 2026 Risk & Security Report, the exchange intercepted more than 30,000 suspicious withdrawal requests and protected nearly 20,000 users between Jan. 1 and June 15.
The company has expanded real-time blockchain monitoring, automated security testing, and AI-assisted threat detection as it attempts to strengthen its defenses against increasingly sophisticated crypto attacks.
Bybit Intercepted More Than 30,000 Suspicious Withdrawals
Account security was one of Bybit’s biggest priorities during the first half of the year.
The exchange said it blocked more than 30,000 withdrawal requests that its systems identified as suspicious. Those interventions potentially protected more than $700 million in user funds.
Nearly 20,000 users were affected by the alerts.
Bybit said its security teams were also able to react relatively quickly. Initial risk assessments took an average of 4.7 minutes, while around 95% of cases were reviewed within 10 minutes.
The $700 million figure represents potential losses rather than funds that attackers had already successfully stolen. Still, it shows the scale of suspicious activity that centralized crypto exchanges are now required to monitor.
Bybit also identified approximately $212 million worth of funds potentially connected to fraudulent activity and added more than 10,000 suspicious blockchain addresses to its blacklist.
Bybit Now Monitors All Relevant On-Chain Activity
The exchange has also significantly expanded its blockchain-monitoring infrastructure.
Bybit says its systems now monitor 100% of on-chain activity considered relevant to its operations.
That includes listed token contracts, ecosystem contracts, and transactions involving the exchange’s cold, warm, and hot wallets.
This wider monitoring allows Bybit to detect suspicious behavior even when an attack begins outside its own platform.
For example, unusual activity involving a listed token’s smart contract or a suspicious wallet movement can be investigated before it directly affects Bybit users.
During the first half of 2026, the exchange said it responded to 10 security incidents involving token projects listed on its platform.
None of those incidents resulted in losses for Bybit.
In eight cases, Bybit said its security teams completed emergency responses before other major exchanges. In two cases, the exchange reportedly detected the incidents before the affected projects themselves had identified the attacks.
Crypto Security Is Moving Beyond Traditional Audits
Bybit’s approach reflects a wider change taking place across the crypto industry.
Traditional smart contract audits remain important, but recent attacks have shown that vulnerabilities often exist outside the code reviewed during an audit.
Compromised administrator keys, signer devices, backend systems, bridge validators, and outdated contracts can all become attack vectors.
A security report cited in the original article found that compromised keys, infrastructure, and signers accounted for 88.3% of approximately $764 million stolen during the second quarter of 2026.
The same research found that only a small portion of monitored projects had strong continuous security systems in place.
This helps explain why exchanges such as Bybit are increasingly focusing on real-time monitoring rather than relying only on one-time security audits.
A platform can pass an audit today and still become vulnerable tomorrow if an administrator’s device is compromised or an attacker gains access to critical infrastructure.
AI Is Speeding Up Bybit’s Security Response
Artificial intelligence has become another major part of Bybit’s security operations.
The exchange said more than 100,000 security alerts received AI-assisted analysis during the first half of 2026.
According to its report, AI-supported security reviews detected high-severity vulnerabilities at roughly three to five times the rate achieved through manual assessment.
Automation has also dramatically reduced the time needed for certain security-testing cycles.
Processes that previously took around two weeks can now reportedly be completed in approximately two hours.
Bybit’s automated red-team platform reviewed 1,489 publicly accessible assets and identified more than 100 high-severity vulnerabilities.
The company also said the average time between discovering a new asset and starting penetration testing had fallen below 24 hours.
Previously, similar manual processes could take weeks.
Humans Still Make Critical Security Decisions
Despite its growing use of artificial intelligence, Bybit says it has not handed full control of security decisions to automated systems.
AI is primarily being used to process large volumes of information, identify suspicious patterns, find potential vulnerabilities, and speed up testing.
Human security specialists remain responsible for complex and critical decisions.
That distinction is particularly important as attackers themselves begin using AI and automation.
Cybercriminals can now accelerate reconnaissance, scan systems for weaknesses, and identify potential attack surfaces much faster than before.
For exchanges, reducing the time between detection and response has therefore become increasingly important.
Bybit’s head of group risk control and security, David Zong, described modern cybersecurity as an arms race measured increasingly in minutes rather than days.
The $1.46 Billion Hack Changed Bybit’s Security Strategy
Bybit’s security upgrades follow one of the most damaging crypto hacks ever recorded.
On Feb. 21, 2025, attackers compromised the process used to transfer funds from the exchange’s Ethereum cold wallet.
More than 400,000 ETH and staked Ether were drained, worth approximately $1.46 billion at the time.
The attack became the largest recorded cryptocurrency theft by dollar value.
Bybit CEO Ben Zhou said shortly after the incident that the exchange remained solvent and could cover the losses while continuing to process customer withdrawals.
Investigators later linked the attack to North Korea’s Lazarus Group.
The incident demonstrated that even cold-wallet systems can become vulnerable when attackers compromise the processes or devices used to authorize transactions.
For Bybit, the attack appears to have accelerated investment in continuous monitoring, automated testing, behavioral analysis, and real-time risk controls.
Lazarus Group Remains a Major Crypto Threat
North Korean-linked hackers continue to represent one of the biggest cybersecurity threats to the cryptocurrency industry.
Estimates published in 2025 suggested that North Korean actors stole approximately $2.02 billion in cryptocurrency during that year, with the Bybit attack accounting for a major portion of the total.
Chainalysis estimated that cumulative cryptocurrency theft linked to North Korea had reached roughly $6.75 billion.
The threat continued into 2026.
Two Lazarus-linked attacks involving Drift Protocol and KelpDAO reportedly resulted in combined losses of approximately $577 million in April.
Those attacks relied on techniques such as social engineering, compromised devices, and bridge infrastructure rather than straightforward smart-contract exploits.
This reinforces an important point for crypto security teams: attackers are increasingly targeting people, devices, credentials, and operational processes rather than focusing only on blockchain code.
Bybit Is Also Trying to Recover the Stolen Funds
Improving security is only one part of Bybit’s response to the 2025 attack.
The exchange is also pursuing legal and investigative efforts to trace and potentially recover stolen assets.
Earlier in August, Bybit filed a lawsuit in the United States against North Korea, the country’s Reconnaissance General Bureau, and the Lazarus Group.
The case was filed in the U.S. District Court for the District of Columbia and seeks recovery of assets linked to the February 2025 attack.
A federal judge also issued a preliminary injunction preventing certain unidentified defendants from transferring or disposing of assets covered by the order while proceedings continue.
The civil lawsuit is separate from U.S. criminal investigations into North Korean cyber operations.
Tracing the Stolen Crypto Became Increasingly Difficult
Immediately after the hack, blockchain investigators were able to track a large portion of the stolen funds.
In March 2025, Bybit said approximately 88.87% of the assets remained traceable.
Around 7.59% had gone dark, while approximately 3.54% had been frozen.
However, tracking became increasingly difficult as the attackers moved the assets across different networks and services.
By April, Ben Zhou said approximately 27.6% of the stolen funds could no longer be traced.
The attackers had converted portions of the assets into Bitcoin and distributed them through thousands of wallets, cross-chain platforms, and crypto mixers.
Such laundering techniques make recovery increasingly difficult as stolen funds move further away from their original wallets.
Bybit Used Bounties and Industry Cooperation
Bybit has also relied on cooperation from other crypto companies and blockchain investigators.
The exchange introduced a bounty program intended to encourage individuals and companies to help identify and freeze assets linked to the attack.
Other industry participants voluntarily froze some suspicious funds when they were identified.
At the same time, Bybit covered the financial gap caused by the hack through a combination of Ether purchases, loans, and deposits from counterparties.
The exchange continued customer withdrawals throughout the recovery process, helping reduce concerns about a wider liquidity crisis.
Why Real-Time Monitoring Matters More After the Hack
The biggest lesson from Bybit’s security report is that modern crypto security increasingly depends on speed.
Hackers no longer need to rely solely on finding one vulnerable smart contract.
They can target employee devices, private keys, signers, bridges, token contracts, backend systems, and users themselves.
That makes continuous monitoring essential.
Bybit’s strategy now combines account-level controls, blockchain surveillance, behavioral analysis, automated penetration testing, AI-assisted alert processing, and human oversight.
The goal is not simply to prevent every attack.
It is also to identify suspicious behavior early enough to prevent an attempted attack from turning into a successful loss.
The Bigger Picture
Bybit’s experience shows how quickly security priorities can change after a major breach.
The $1.46 billion hack in 2025 exposed vulnerabilities in the exchange’s transaction-authorization process and demonstrated the enormous financial consequences of operational security failures.
One year later, Bybit says it is intercepting tens of thousands of suspicious transactions, continuously monitoring relevant blockchain activity, and using AI to analyze security alerts at a much faster pace.
Preventing more than $700 million in potential losses does not erase the impact of the earlier hack, but it does show how aggressively the exchange has expanded its defenses.
The larger challenge remains whether those systems can keep pace with attackers who are also becoming faster, more automated, and increasingly sophisticated.
For centralized exchanges holding billions of dollars in customer assets, real-time security is quickly becoming just as important as custody itself.
Disclaimer: This content is provided for informational and educational purposes only and should not be considered financial or investment advice.






















































