
Bybit's post-breach security controls blocked $700M in attempted outflows. The exchange now faces external audits tied to MiCA's cybersecurity standards.
Alpha Score of 43 reflects weak overall profile with moderate momentum, weak value, weak quality. Based on 3 of 4 signals — score is capped at 90 until remaining data ingests.
Bybit said its security overhaul after the February 2025 hack prevented more than $700 million in additional losses. The exchange released a technical report Tuesday detailing upgrades to its institutional custody systems.
The new controls blocked roughly $700 million in "unscheduled capital outflows," according to the report. The blocked amount is separate from the funds taken in the original breach. The Feb. 21 attack drained about $1.5 billion in Ethereum (ETH) from Bybit's wallets, or 401,000 ETH. Security agencies attributed the hack to the Lazarus Group, a North Korean state-backed hacking unit.
The intrusion worked through malicious code injected into the frontend of Safe{Wallet}, a third-party multisignature custody provider. The attackers exploited the delegatecall function in the Ethereum Virtual Machine, a mechanism that lets one contract invoke another's code, to redirect transactions. Bybit's authorized signers approved what looked like routine transfers without noticing the interface had been altered, and funds moved to unauthorized wallets.
In response, Bybit said it completed a full audit of its custody systems and rebuilt how it connects to third-party services. The exchange now uses isolated, air-gapped signing environments, with transaction keys handled offline. Smart contract verification is mandatory and runs independently of web interfaces, so a compromised page can't mask what a contract actually does. Transactions are also decoded at the mempool level before being broadcast to the network. The extra decoding removes blind reliance on the visual layer during multi-party signing, Bybit said. It gives signers an independent view of the transaction data before broadcast. Bybit said the changes are meant to prevent a repeat of the February attack.
The exchange said these measures caught multiple operational anomalies before they could compromise its balance sheet. In total, the framework blocked successive exploit attempts that would have moved $700 million out of the platform, the technical report said. The report pointed to real-time transaction validation as the core of the new setup. It did not give a timeframe for the blocked attempts or say how they were structured.
Bybit did not suspend user withdrawals during the incident. It covered the stolen ETH with corporate reserves and bridge liquidity instruments. Management said its solvency under the new contingency standard remains intact.
Bybit's settlement modules are now scheduled for a new round of external audits before the end of the current quarter. The exchange said the audits align with cybersecurity standards under the European Union's MiCA regulation, which sets security requirements for crypto-asset service providers and applies to exchanges operating in the EU.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.