Bybit Security Upgrades Prevent $700 Million in Potential Crypto Losses

1 hour ago 3 sources neutral

Key takeaways:

  • Bybit's security improvements reduce custodial tail risk, potentially supporting ETH market confidence.
  • AI-driven monitoring now differentiates exchanges, pressuring competitors to invest or lose institutional trust.
  • Lazarus Group's persistent threat means traders should diversify across custody providers and monitor upgrades.

Bybit has reported that a strengthened security architecture blocked more than $700 million in potential user losses during the first half of 2026. The update follows the February 2025 cyberattack, in which hackers stole approximately 401,000 ETH, valued at around $1.5 billion, from the exchange.

According to Bybit's H1 2026 Risk & Security Report, covering January 1 through June 15, the platform intercepted more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users from potential losses. The average initial review took 4.7 minutes, with 95% of cases completed within 10 minutes. Bybit also identified about $212 million in potential fraud-linked on-chain funds and blacklisted more than 10,000 malicious addresses.

The exchange says it now monitors 100% of business-relevant on-chain activity, including listed token contracts, ecosystem contracts, and its cold, warm, and hot wallets. During the reporting period, Bybit identified and handled 10 security incidents involving listed token projects with zero resulting losses. In eight cases, Bybit completed emergency responses before other major exchanges, and in two cases it detected attacks before the affected projects themselves did.

The original exploit on February 21, 2025 was attributed by security agencies to the Lazarus Group. Forensic analysis found that malicious code was injected into the frontend of Safe{Wallet}, a third-party multisignature wallet provider. Authorized signers processed routine transfers without noticing alterations in the application interface, and manipulation of the delegatecall function in the Ethereum Virtual Machine allowed funds to be diverted to unauthorized wallets.

Since then, Bybit has overhauled its interaction parameters with third-party services. The platform introduced isolated air-gapped signing environments, mandatory smart contract verification independent of web interfaces, and mempool-level data decoding before broadcasting transactions. These measures are designed to eliminate blind reliance on visual interfaces during multi-party signing procedures.

Bybit is also applying artificial intelligence across security operations, code auditing, and penetration testing. The company processed more than 100,000 security alerts with AI-assisted analysis, and its AI-assisted security auditing identified high-severity vulnerabilities at three to five times the rate of manual review. Automation reduced the time from security assessment to testing from about two weeks to two hours. An automated red-team platform assessed 1,489 public-facing assets and identified more than 100 high-severity vulnerabilities, with average time from asset discovery to initial penetration testing reduced to under 24 hours.

“The cybersecurity arms race has entered an era of minutes. Using AI to strengthen our security and risk-control capabilities, while securing the AI systems themselves, is our top priority, with human judgement remaining at the centre of critical security decisions,” said David Zong, Head of Group Risk Control and Security at Bybit.

Bybit has also pursued legal action against North Korea and the Lazarus Group, seeking accountability and recovery of assets connected to the attack. The exchange covered the entirety of the stolen 2025 balance using corporate reserves and bridge liquidity instruments without suspending user withdrawals. The company says it will subject its settlement modules to a new round of periodic external audits scheduled for the close of the current quarter.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.