Bybit intercepted more than 30,000 suspicious withdrawal requests during the first half of 2026, protecting almost 20,000 users from potential losses exceeding $700m.
The cryptocurrency exchange said the figures were included in its H1 2026 Risk & Security Report, which covers the period from 1 January to 15 June. The report details an expanded security operation introduced after the company suffered a $1.46bn hack in February 2025.
Bybit said its systems now operate across three main defensive layers: user-account protection, continuous monitoring of blockchain activity and artificial-intelligence-supported security operations. Human specialists remain responsible for critical decisions.
Initial reviews of suspicious activity took an average of 4.7 minutes, with 95% completed within 10 minutes.
The exchange also identified approximately $212m in funds potentially linked to fraud and blacklisted more than 10,000 malicious blockchain addresses. It said behavioural analysis and AI-assisted monitoring helped detect transaction patterns associated with emerging fraud campaigns.
The $700m figure represents potential losses prevented by the exchange’s controls. Bybit stressed that the report did not claim all of the assets involved had been successfully targeted by attackers.
The security overhaul follows the 21 February 2025 breach, when attackers drained roughly $1.46bn from Bybit’s Ethereum cold wallet. The incident, which involved more than 400,000 ETH and staked Ether, became the largest cryptocurrency theft ever recorded by value.
US authorities later attributed the attack to North Korean actors, including the Lazarus Group.
Bybit said its blockchain monitoring now covers 100% of on-chain activity considered relevant to its business. That includes listed token contracts, ecosystem contracts, and the exchange’s cold, warm and hot wallets.
During the first half of 2026, the system identified and handled 10 security incidents involving token projects listed on Bybit. None resulted in losses for the exchange, according to the report.
Security teams responded before other major exchanges in eight of those cases. In two incidents, Bybit detected the attacks before the affected projects had identified them.
The exchange said its monitoring operation can track activity both within its trading platform and directly on supported blockchains. That means suspicious smart-contract behaviour or movements between wallets can be investigated even when an incident begins outside Bybit’s own infrastructure.
Continuous monitoring has become an increasing concern across the wider cryptocurrency industry. A July security report previously covered by crypto.news found that compromised keys, signers and infrastructure accounted for 88.3% of approximately $764m stolen during the second quarter of 2026.
Hacken, which examined 1,427 projects, found evidence of third-party monitoring at only 9% of them. The firm said just 4% combined monitoring with an active bug bounty programme and an audit.
It also identified 14 projects that were exploited despite having completed security audits. Several attacks targeted signer devices, administrator keys, backend systems, bridge validators or older contracts rather than the smart-contract code assessed in conventional audits.
AI becomes larger part of defence
Bybit said AI-assisted analysis was used on more than 100,000 security alerts during the first half of the year.
According to the exchange’s report, AI-supported security audits found high-severity vulnerabilities at three to five times the rate achieved through manual reviews. Automation also cut the time between a security assessment and follow-up testing from about two weeks to approximately two hours.
The exchange’s automated red-team platform assessed 1,489 publicly accessible assets and found more than 100 high-severity vulnerabilities. The average time between an asset being discovered and initial penetration testing beginning fell below 24 hours, compared with weeks under some manual processes.
Bybit said AI is mainly being used to process information, identify vulnerabilities and accelerate testing. Specialists continue to make more complex judgements.
Zong said the exchange regarded both the use of AI in security and the protection of AI systems themselves as priorities, while “human judgement” remained central to important security decisions.
The changes come as attackers increasingly use automation and AI to accelerate reconnaissance and the search for vulnerabilities. Bybit said reducing the time between detecting suspicious activity and taking action had consequently become a key part of its security strategy.
The exchange’s account-protection systems were particularly focused on withdrawals during the reporting period. Alongside the 30,000-plus requests that were stopped, on-chain screening identified about $212m in potentially fraudulent funds and led to more than 10,000 addresses being added to Bybit’s blacklist.
The security measures follow the attack on the process used to transfer assets from Bybit’s Ethereum cold wallet. Chief executive Ben Zhou said at the time that the exchange could absorb the loss and continue processing customer withdrawals.
Estimates published in May indicated that North Korean actors stole about $2.02bn in cryptocurrency during 2025, with the Bybit attack accounting for most of that amount. Chainalysis estimated that the activity took the cumulative value of cryptocurrency theft linked to North Korea to about $6.75bn.
The threat has continued in 2026. Two Lazarus-linked attacks on Drift Protocol and KelpDAO in April reportedly drained a combined $577m. The Drift Protocol attack accounted for $285m and the KelpDAO incident for $292m.
Those operations relied on social engineering, compromised devices and bridge infrastructure rather than conventional smart-contract exploits.
Bybit has been working with law-enforcement agencies, blockchain intelligence companies and other industry participants to trace and recover assets taken in the 2025 attack.
Earlier this month, the exchange filed a lawsuit in the US against North Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group. The case was brought in the U.S. District Court for the District of Columbia and concerns the 21 February breach.
Bybit is seeking the recovery of assets connected to the theft. A federal judge has also issued a preliminary injunction preventing certain unidentified defendants from transferring or disposing of assets covered by the order while the case continues.
The company has said the civil action is separate from US criminal investigations into North Korean hacking activity. The FBI previously attributed the attack to North Korean actors and urged exchanges, validators and blockchain companies to block transactions linked to addresses used to launder the stolen funds.
Tracing the assets became increasingly difficult after the breach. Bybit said in March 2025 that 88.87% of the funds remained traceable, while 7.59% had gone dark and 3.54% had been frozen.
By April, Zhou said 27.6% of the stolen funds could no longer be tracked after the attackers converted assets into Bitcoin and distributed them across thousands of wallets, cross-chain services and cryptocurrency mixers.
Bybit has used a bounty programme and voluntary freezes by other industry participants as part of its recovery efforts. After the hack, it covered the shortfall through Ether purchases, loans and deposits from counterparties while continuing to allow customer withdrawals.
In the US civil case, Bybit said it intended to seek further relief as the proceedings continued. The court has not issued a final judgment on the exchange’s claims against North Korea, the Reconnaissance General Bureau or the Lazarus Group.
