
Bybit's security systems blocked more than $700 million in potential user losses during the first half of 2026, intercepting over 30,000 suspicious withdrawal requests that protected nearly 20,000 users. According to the exchange's H1 2026 Risk & Security Report published on August 18, initial risk reviews took an average of 4.7 minutes, with 95% completed within 10 minutes. Security teams also identified approximately $212 million in funds potentially connected to fraud and blacklisted more than 10,000 malicious blockchain addresses during the period. The scale represents a significant increase from the $300 million intercepted throughout 2025, demonstrating the exchange's enhanced detection capabilities.
The exchange now monitors 100% of business relevant on-chain activity including listed token contracts, ecosystem contracts and all wallet types. During H1 2026, Bybit's system identified and handled 10 security incidents affecting token projects listed on the exchange, with none causing losses to Bybit. Security teams completed emergency responses before other major exchanges in 8 cases, while 2 incidents were detected before the affected projects had identified the attacks themselves. The system allows continuous monitoring of both trading platform activity and transactions occurring directly on supported blockchains, with the exchange handling 10 incidents involving listed token projects with zero platform losses. Bybit's follow-up recovery work covered roughly $48.4 million recovered and an additional $30.5 million frozen tied to the 2025 theft.
AI has significantly accelerated Bybit's security operations, with the exchange processing more than 100,000 security alerts with AI assistance during H1 2026. According to the report, AI-supported security audits detected high-severity vulnerabilities at 3-5 times the rate achieved through manual review. Automation reduced security assessment cycles from approximately two weeks to two hours, with the automated red-team platform assessing 1,489 public-facing assets and identifying more than 100 high-severity vulnerabilities. The average time between asset discovery and initial penetration testing fell below 24 hours compared to weeks for manual processes. Bybit describes three layers of protection: user and account security, real-time on-chain monitoring, and AI-assisted security operations, with the stated aim to detect threats earlier, respond faster, and narrow the gap between discovery and intervention.
Bybit has filed a US lawsuit against North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group in the U.S. District Court for the District of Columbia regarding the February 2025 breach that drained $1.46 billion from its Ethereum cold wallet. The exchange seeks recovery of assets connected to the theft, with a federal judge issuing a preliminary injunction preventing certain defendants from transferring or disposing of covered assets. The breach became the largest recorded cryptocurrency theft by value, with investigators later linking the operation to North Korea's Lazarus Group. Chainalysis estimates North Korean actors stole approximately $2.02 billion in cryptocurrency during 2025, with the Bybit theft accounting for most of that total.