Bybit Thwarts Over $700M in Potential Losses Following $1.46B Hack

BTC
ETH
LINK
NEAR
SUI
TON
UNI
on-chain monitoringsecurityhack
2 hours agoSource: crypto.news
Bybit Thwarts Over $700M in Potential Losses Following $1.46B Hack

Bybit’s security systems blocked more than $700 million in potential user losses during the first half of 2026 as the exchange expanded real-time blockchain monitoring and AI-assisted threat detection after its $1.46 billion 2025 hack.

Summary

  • Bybit blocked more than 30,000 suspicious withdrawals, preventing over $700 million in potential user losses during H1 2026.
  • The exchange now monitors 100% of business relevant on chain activity and handled 10 token project security incidents without platform losses.
  • More than 100,000 security alerts were processed with AI assistance, while automated testing cut some security assessment cycles from two weeks to two hours.
  • Bybit has also pursued legal action against North Korea and the Lazarus Group over the $1.46 billion hack in February 2025.

Bybit’s H1 2026 Risk & Security Report, covering Jan. 1 through June 15, said the exchange now operates three main layers of defence spanning user accounts, continuous on-chain monitoring and AI-supported security operations, with human specialists retaining control over critical decisions.

The exchange said more than 30,000 suspicious withdrawal requests were intercepted during the period, protecting nearly 20,000 users. Initial risk reviews took an average of 4.7 minutes, while 95% were completed within 10 minutes.

Security teams also identified about $212 million in funds potentially connected to fraud and blacklisted more than 10,000 malicious blockchain addresses. Bybit said behavioural analysis and AI-supported monitoring were used to detect transaction patterns linked to new fraud campaigns.

The exchange has been rebuilding its security architecture since the Feb. 21, 2025 attack that drained roughly $1.46 billion from its Ethereum cold wallet. The breach became the largest recorded cryptocurrency theft by value and was later attributed to North Korean actors by U.S. authorities.

Bybit security monitoring now covers all relevant on-chain activity

Bybit said its monitoring system now covers 100% of on-chain activity considered relevant to its business, including listed token contracts, ecosystem contracts and the exchange’s cold, warm and hot wallets.

During H1, the system identified and handled 10 security incidents affecting token projects listed on the exchange, with none causing losses to Bybit, according to the report. Security teams completed emergency responses before other major exchanges in eight cases, while two incidents were detected before the affected projects had identified the attacks themselves.

The company said the system allows its security operation to watch both activity inside the trading platform and transactions occurring directly on supported blockchains. Suspicious contract behaviour or wallet movements can therefore be reviewed even when an incident begins outside Bybit’s own infrastructure.

Continuous monitoring has also become a larger issue across the crypto sector. A July security report previously covered by crypto.news found that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter of 2026. Hacken, which tracked 1,427 projects, found evidence of third-party monitoring at only 9% of them and said just 4% combined monitoring, an active bug bounty and an audit.

Hacken also identified 14 projects that were exploited despite previously completing security audits. According to the firm, several attacks affected signer devices, administrator keys, backend systems, bridge validators or older contracts instead of the smart contract code examined during conventional audits.

AI has cut Bybit security testing from weeks to hours

AI has also taken a larger role in Bybit’s defensive systems, with the exchange saying more than 100,000 security alerts received AI-assisted analysis during the first half of the year.

According to the H1 report, AI-supported security audits detected high-severity vulnerabilities at three to five times the rate achieved through manual review. Automation also reduced the period between a security assessment and subsequent testing from about two weeks to roughly two hours.

The exchange’s automated red-team platform assessed 1,489 public-facing assets and identified more than 100 high-severity vulnerabilities. Bybit said the average time between discovering an asset and beginning initial penetration testing fell below 24 hours, compared with manual processes that could require weeks.

AI is being used mainly to process information, find vulnerabilities and increase the speed of security testing, while specialists remain responsible for more complex decisions, the company said.

“The cybersecurity arms race has entered an era of minutes,” David Zong, Bybit’s head of group risk control and security, said.

Zong said the exchange considers the use of AI for security and the protection of the AI systems themselves a priority, while “human judgement” remains central when critical security decisions are made.

The approach comes as attackers also use automation and AI to speed up reconnaissance and vulnerability discovery. Bybit said reducing the time between discovering suspicious activity and acting on it has therefore become a central part of its security strategy.

Account controls stopped more than 30,000 suspicious withdrawals

User accounts formed another part of the exchange’s H1 security work, particularly around withdrawals that its systems classified as suspicious.

More than 30,000 withdrawal requests were intercepted, with close to 20,000 users protected from potential losses, the company said. The combined value involved exceeded $700 million, although the report described the figure as potential losses rather than assets confirmed to have been targeted successfully by attackers.

On-chain screening operated alongside those account controls. Bybit said approximately $212 million in funds potentially linked to fraud were identified during the period, while more than 10,000 addresses were added to its blacklist.

The figures follow a security incident in which attackers compromised the process used to move funds from Bybit’s Ethereum cold wallet. The February 2025 breach drained more than 400,000 ETH and staked Ether worth about $1.46 billion at the time, with Bybit CEO Ben Zhou saying the exchange could cover the loss and continue processing customer withdrawals.

Investigators later linked the operation to North Korea’s Lazarus Group. Estimates published in May showed North Korean actors stole about $2.02 billion in cryptocurrency during 2025, with the Bybit theft accounting for most of that total. Chainalysis estimated the activity pushed cumulative crypto theft linked to North Korea to roughly $6.75 billion.

The threat continued into 2026. Two Lazarus-linked attacks against Drift Protocol and KelpDAO in April reportedly drained a combined $577 million, including $285 million from Drift and $292 million from KelpDAO. The incidents relied on social engineering, compromised devices, and bridge infrastructure instead of conventional smart contract exploits.

Bybit has taken the Lazarus recovery effort to US court

Technical controls have been accompanied by efforts to trace and recover assets taken in the 2025 attack, with Bybit working with law enforcement agencies, blockchain intelligence companies and other industry participants.

Earlier this month, the exchange filed a US lawsuit against North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group in the U.S. District Court for the District of Columbia.

The case concerns the Feb. 21 breach and seeks the recovery of assets connected to the theft. A federal judge also issued a preliminary injunction that prevents certain unidentified defendants from transferring or disposing of assets covered by the order while the case proceeds.

Bybit has said the civil proceedings are separate from U.S. criminal investigations into North Korean hacking activity. The FBI previously attributed the attack to North Korean actors and asked exchanges, validators and blockchain companies to block transactions connected to addresses used in the laundering operation.

Tracing the stolen assets became progressively harder after the attack. In March 2025, Bybit said 88.87% of the funds remained traceable, while 7.59% had gone dark and 3.54% had been frozen. By April, Zhou said 27.6% of the stolen funds could no longer be tracked after the attackers converted assets into Bitcoin and dispersed them through thousands of wallets, cross-chain services and crypto mixers.

Bybit has also used a bounty programme and voluntary freezes by other industry participants during the recovery process. Following the attack, the exchange covered its asset shortfall through Ether purchases, loans and deposits from counterparties while continuing customer withdrawals.

In the U.S. civil case, Bybit said it intends to pursue further relief as proceedings continue. The court has not issued a final judgment on the exchange’s claims against North Korea, the Reconnaissance General Bureau or the Lazarus Group.