
Bybit's H1 security report: $700M+ blocked, 30,000+ suspicious withdrawals stopped, and a lawsuit against North Korea over the record $1.46B hack.
Bybit said its security systems blocked more than $700 million in potential user losses during the first half of 2026. The exchange released the figures in its H1 2026 Risk & Security Report, covering January 1 through June 15.
The report comes after Bybit’s February 2025 hack, when attackers drained roughly $1.46 billion from its Ethereum cold wallet. That breach remains the largest crypto theft on record.
Bybit said it intercepted more than 30,000 suspicious withdrawal requests during the period. Close to 20,000 users were protected from potential losses as a result. Initial risk reviews took an average of 4.7 minutes to complete. About 95% of reviews were finished within 10 minutes, according to the company.
Security teams also flagged around $212 million in funds potentially tied to fraud. More than 10,000 malicious blockchain addresses were added to the exchange’s blacklist.
Bybit says its monitoring system now tracks 100% of on-chain activity it considers relevant to its business. This includes listed token contracts and ecosystem contracts, along with its own cold and hot wallets.
During H1, the system flagged 10 security incidents tied to token projects listed on the exchange. None of the incidents caused losses for Bybit, the report said. In eight of those cases, Bybit’s team responded before other major exchanges did. Two incidents were caught before the affected projects had even identified the attacks themselves.
Monitoring has become a wider issue across the crypto industry. A separate report from Hacken found that compromised keys and infrastructure accounted for 88.3% of about $764 million stolen in Q2 2026. Hacken reviewed 1,427 projects and found only 9% had third-party monitoring in place. Just 4% combined monitoring with a bug bounty and a security audit.
Bybit says AI now plays a larger role in its defenses. More than 100,000 security alerts received AI-assisted analysis during the first half of the year. According to the report, AI-supported audits caught high-severity vulnerabilities at three to five times the rate of manual review. Automation also cut the time between a security assessment and follow-up testing from about two weeks to roughly two hours.
The exchange’s automated red-team platform assessed 1,489 public-facing assets. It found more than 100 high-severity vulnerabilities during the process.
Bybit’s David Zong, head of group risk control and security, said the cybersecurity field has “entered an era of minutes.” He added that human judgment still guides the most critical security decisions.
Bybit has also taken legal steps tied to the 2025 hack. Earlier this month, it filed a lawsuit in the U.S. District Court for the District of Columbia against North Korea and the Lazarus Group. A federal judge issued a preliminary injunction blocking certain unidentified defendants from moving or disposing of assets tied to the case. The civil case is separate from ongoing U.S. criminal investigations into North Korean hacking activity.
Tracing the stolen funds has grown harder over time. In March 2025, Bybit said 88.87% of the funds remained traceable. By April, that figure had dropped, with CEO Ben Zhou saying 27.6% of the funds could no longer be tracked after being converted into Bitcoin and spread across thousands of wallets.
The court has not issued a final ruling on Bybit’s claims against North Korea or the Lazarus Group. The exchange says it plans to pursue further legal relief as the case continues.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.