
Bybit's H1 report shows $700M+ in intercepted withdrawals, 20,000 users protected, and AI audits detecting 3-5x more vulnerabilities than manual review.
Bybit’s security systems blocked more than $700 million in potential user losses during the first half of 2026, the exchange said in its H1 Risk & Security Report. The figure comes a year after a $1.46 billion breach of its Ethereum cold wallet, later attributed to North Korean actors.
The report, covering Jan. 1 through June 15, described three layers of defence: user account controls, continuous on-chain monitoring, and AI-assisted security operations. Human specialists keep final say on critical decisions, the exchange said.
More than 30,000 suspicious withdrawal requests were intercepted during the period, protecting nearly 20,000 users. Initial risk reviews averaged 4.7 minutes, with 95% completed within 10 minutes.
Security teams also identified about $212 million in funds potentially connected to fraud and added more than 10,000 malicious blockchain addresses to Bybit’s blacklist, the report said. Behavioural analysis and AI-supported monitoring were used to detect transaction patterns linked to new fraud campaigns, the company said.
The February 2025 attack drained roughly 400,000 ETH and staked Ether from Bybit’s Ethereum cold wallet. The exchange said at the time it could cover the loss and continue processing customer withdrawals. U.S. authorities later linked the operation to North Korea’s Lazarus Group. Chainalysis estimated that North Korean actors stole about $2.02 billion in cryptocurrency during 2025, with the Bybit theft accounting for most of that total. The firm said cumulative crypto theft linked to North Korea had reached roughly $6.75 billion.
Bybit’s monitoring system now covers 100% of on-chain activity relevant to its business, including listed token contracts, ecosystem contracts, and the exchange’s cold, warm and hot wallets, the report said.
During H1, the system identified and handled 10 security incidents affecting token projects listed on the exchange. None caused losses to Bybit, the company said. Security teams completed emergency responses before other major exchanges in eight of those cases, and two incidents were detected before the affected projects had identified the attacks themselves.
Continuous monitoring has become a larger issue across the crypto sector. A July security report by Hacken, previously covered by crypto.news, found that compromised keys, signers and infrastructure accounted for 88.3% of roughly $764 million stolen during the second quarter of 2026. Hacken tracked 1,427 projects and found evidence of third-party monitoring at only 9% of them. Just 4% combined monitoring, an active bug bounty and an audit, the firm said.
Hacken also identified 14 projects that were exploited despite previously completing security audits. According to the firm, several attacks affected signer devices, administrator keys, backend systems, bridge validators or older contracts instead of the smart contract code examined during conventional audits.
AI has taken a larger role in Bybit’s defensive systems. The exchange said more than 100,000 security alerts received AI-assisted analysis during the first half of the year. According to the H1 report, AI-supported security audits detected high-severity vulnerabilities at three to five times the rate achieved through manual review. Automation also reduced the period between a security assessment and subsequent testing from about two weeks to roughly two hours.
Bybit’s automated red-team platform assessed 1,489 public-facing assets and identified more than 100 high-severity vulnerabilities. The exchange said the average time between discovering an asset and beginning initial penetration testing fell below 24 hours, compared with manual processes that could require weeks.
AI is used mainly to process information, find vulnerabilities and increase the speed of security testing, while specialists remain responsible for more complex decisions, the company said.
“The cybersecurity arms race has entered an era of minutes,” David Zong, Bybit’s head of group risk control and security, said. Zong said the exchange considers the use of AI for security and the protection of the AI systems themselves a priority, while “human judgement” remains central when critical security decisions are made.
The approach comes as attackers also use automation and AI to speed up reconnaissance and vulnerability discovery. Bybit said reducing the time between discovering suspicious activity and acting on it has therefore become a central part of its security strategy.
User accounts formed another part of the exchange’s H1 security work. More than 30,000 withdrawal requests were intercepted, with close to 20,000 users protected from potential losses, the company said. The combined value involved exceeded $700 million, although the report described the figure as potential losses rather than assets confirmed to have been targeted successfully by attackers.
On-chain screening operated alongside those account controls. Bybit said approximately $212 million in funds potentially linked to fraud were identified during the period, while more than 10,000 addresses were added to its blacklist.
The threat continued into 2026. Two Lazarus-linked attacks against Drift Protocol and KelpDAO in April reportedly drained a combined $577 million, including $285 million from Drift and $292 million from KelpDAO. The incidents relied on social engineering, compromised devices, and bridge infrastructure instead of conventional smart contract exploits.
Technical controls have been accompanied by efforts to trace and recover assets taken in the 2025 attack. Bybit has worked with law enforcement agencies, blockchain intelligence companies and other industry participants.
Earlier this month, the exchange filed a US lawsuit against North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group in the U.S. District Court for the District of Columbia. The case concerns the Feb. 21 breach and seeks the recovery of assets connected to the theft. A federal judge also issued a preliminary injunction that prevents certain unidentified defendants from transferring or disposing of assets covered by the order while the case proceeds.
Bybit has said the civil proceedings are separate from U.S. criminal investigations into North Korean hacking activity. The FBI previously attributed the attack to North Korean actors and asked exchanges, validators and blockchain companies to block transactions connected to addresses used in the laundering operation.
Tracing the stolen assets became progressively harder after the attack. In March 2025, Bybit said 88.87% of the funds remained traceable, while 7.59% had gone dark and 3.54% had been frozen. By April, Zhou said 27.6% of the stolen funds could no longer be tracked after the attackers converted assets into Bitcoin and dispersed them through thousands of wallets, cross-chain services and crypto mixers.
Bybit has also used a bounty programme and voluntary freezes by other industry participants during the recovery process. Following the attack, the exchange covered its asset shortfall through Ether purchases, loans and deposits from counterparties while continuing customer withdrawals.
In the U.S. civil case, Bybit said it intends to pursue further relief as proceedings continue. The court has not issued a final judgment on the exchange’s claims against North Korea, the Reconnaissance General Bureau or the Lazarus Group.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.