Bybit security report reveals $700 million in blocked losses. The exchange expanded real-time blockchain monitoring.
AI-assisted threat detection also improved. This followed the $1.46 billion hack in 2025.
Bybit security report highlights H1 2026
The report covers Jan. 1 through June 15. Bybit now operates three main defense layers. These span user accounts and on-chain monitoring. AI-supported security operations form the third layer. Human specialists retain control over critical decisions.
The exchange intercepted over 30,000 suspicious withdrawal requests. This protected nearly 20,000 users. Initial risk reviews took an average of 4.7 minutes. 95% completed within 10 minutes.
Security teams identified about $212 million in fraud-linked funds. They blacklisted more than 10,000 malicious blockchain addresses. Bybit used behavioral analysis and AI-supported monitoring. This detected transaction patterns linked to new fraud campaigns.
Bybit security report shows AI advancements
AI-assisted security audits detected high-severity vulnerabilities. They did this at three to five times the manual rate. Automation reduced security testing time drastically. The period between assessments fell from weeks to about two hours.
The automated red-team platform assessed 1,489 public-facing assets. It identified more than 100 high-severity vulnerabilities. The average time between discovery and testing fell below 24 hours. Manual processes previously required weeks.
AI processes information and finds vulnerabilities. It increases the speed of security testing. Human specialists remain responsible for complex decisions nevertheless.
“The cybersecurity arms race has entered an era of minutes,” said David Zong, Bybit’s head of group risk control and security.
The exchange prioritizes AI for security and protecting AI systems. “Human judgement” remains central for critical security decisions.
Ongoing threats and recovery efforts
North Korean actors targeted Bybit in February 2025. The attack drained roughly $1.46 billion from its Ethereum cold wallet. It became the largest recorded cryptocurrency theft.
Chainalysis estimated cumulative North Korean crypto theft reached $6.75 billion. Two Lazarus-linked attacks hit Drift Protocol and KelpDAO in April. They drained a combined $577 million. The incidents used social engineering and compromised devices.
Bybit security report outlines legal action
Bybit filed a US lawsuit against North Korea earlier this month. The case targets the Reconnaissance General Bureau and Lazarus Group. The lawsuit was filed in the U.S. District Court for the District of Columbia.
A federal judge issued a preliminary injunction. It prevents unidentified defendants from transferring assets. The civil proceedings are separate from U.S. criminal investigations.
The FBI previously attributed the attack to North Korean actors. They asked exchanges to block connected addresses. Tracing stolen assets became progressively harder after the attack.
Bybit covered its asset shortfall through Ether purchases. It also used loans and deposits from counterparties. Customer withdrawals continued throughout the process.