Bybit says it intercepted more than $700 million in potential user losses in the first half of 2026, a blunt reminder that exchange security is now a nonstop race against attackers who move fast and steal first.
- More than 30, 000 suspicious withdrawals blocked
- Nearly 20, 000 users protected
- Average initial review time: 4.7 minutes
- Bybit is still pursuing North Korea-linked actors in U.S. court
The figure is self-reported by Bybit, and it refers to potential user losses rather than confirmed theft that was later clawed back. That distinction matters. In crypto security, “intercepted” can mean blocked withdrawals, halted fraud attempts, or activity stopped before funds actually left the building. Same neighborhood, very different crime scene.
According to Bybit's AI-Driven Security Enhancements Protect $700M in the exchange blocked more than 30, 000 suspicious withdrawal requests between January 1 and June 15, 2026. It says those controls protected nearly 20, 000 users and prevented more than $700 million in potential losses. The company also says 95% of initial risk reviews were completed within 10 minutes, with an average review time of 4.7 minutes.
That speed is the real story. In this market, security teams are not dealing with leisurely fraud. They are dealing with attackers who can move funds, chain-hop, and launder before a human even finishes reading the alert.
David Zong, Bybit’s head of group risk control and security, put it plainly:
“The cybersecurity arms race has entered an era of minutes.”
He’s right, and not in the cheerful keynote-slide way companies usually mean. If an exchange is still waiting around for a weekly review meeting while funds are already in motion, it is not running security. It is hosting a delayed reaction.
Bybit says it rebuilt its defenses after the February 21, 2025 breach that drained roughly $1.46 billion from its Ethereum cold wallet. The attack, widely described as the largest recorded cryptocurrency theft by value, was later attributed by U.S. authorities to North Korean actors tied to the Lazarus Group and the TraderTraitor campaign.
The company says the post-hack overhaul now leans heavily on real-time blockchain monitoring, AI-assisted threat detection, and much faster response workflows. It reports processing more than 100, 000 security alerts with AI support, while AI-assisted audits detected high-severity vulnerabilities at three to five times the rate of manual review.
Those are Bybit’s own numbers, not independent benchmark results. Useful? Yes. Automatically gospel? No. Crypto firms love dashboards almost as much as they love saying “AI” in a press release, and neither should be mistaken for proof on its own.
Still, the operational claims are specific. Bybit says automation cut some security assessment cycles from about two weeks to roughly two hours. Its automated red-team platform assessed 1, 489 public-facing assets and found more than 100 high-severity vulnerabilities. The average time from discovering an asset to starting initial penetration testing fell below 24 hours.
For readers not steeped in security jargon: a red-team platform simulates attacks to expose weak spots before criminals do. Penetration testing is controlled ethical hacking. In plain English, it’s trying the doors and windows before the burglars do.
Bybit also says it handled 10 token project security incidents with no platform losses. In eight of those cases, it says it responded before other major exchanges, and in two cases it detected the attack before the affected project itself did.
That matters because exchanges are not just private businesses with glossy apps. They are giant custody vaults. When one gets hit, the blast radius reaches users, counterparties, and confidence in the market itself.
The exchange says it identified about $212 million in funds potentially connected to fraud and blacklisted more than 10, 000 malicious blockchain addresses. It also says its monitoring now covers 100% of the on-chain activity it considers relevant to its business, including listed token contracts, ecosystem contracts, and its cold, warm, and hot wallets.
That “relevant to its business” wording is doing a lot of work. It does not mean Bybit is watching every transaction on every chain. It means it is monitoring the slice of on-chain activity that matters to its own products and custody flows. Still, that is a far cry from the old exchange-school approach of crossing fingers and hoping the attackers picked someone else.
The 2025 breach remains the background thud behind all of this. On February 21, 2025, attackers drained more than 400, 000 ETH and staked Ether from Bybit’s Ethereum cold wallet, worth about $1.46 billion at the time. U.S. authorities later attributed the theft to North Korean actors, and the FBI said the stolen funds were rapidly moved through multiple blockchains, with some converted to Bitcoin and dispersed across thousands of addresses.
Bybit CEO Ben Zhou said the exchange could cover the loss and continue processing customer withdrawals. That helped prevent panic from turning into a full-blown run, but the incident still exposed the brutal truth of custodial crypto: if you hold user funds in one place, you are not just a financial platform. You are a target with a balance sheet.
North Korea-linked crypto theft is not a one-off problem. In May, Chainalysis estimated that North Korean actors stole about $2.02 billion in cryptocurrency during 2025. The firm also places cumulative crypto theft linked to North Korea at roughly $6.75 billion.
That is not a hobby. That is an industrialized theft machine.
And it has not slowed down. In April 2026, two Lazarus-linked attacks against Drift Protocol and KelpDAO reportedly drained a combined $577 million, including $285 million from Drift and $292 million from KelpDAO. The pattern is familiar by now: fast exploitation, cross-chain movement, mixers, and a trail designed to become a headache for investigators and a shrug for the criminals.
For anyone newer to the space, cross-chain services move assets between blockchains, often making the flow harder to follow. Crypto mixers blend funds together to obscure their origin. Cold wallets are offline storage, warm wallets sit somewhere in the middle, and hot wallets are internet-connected and used for active transfers. The more connected the wallet, the easier it is to use, and the easier it is to attack.
Bybit is also trying to recover value through the legal system. Earlier this month, it filed a U.S. lawsuit against North Korea, the Reconnaissance General Bureau, and the Lazarus Group in the U.S. District Court for the District of Columbia. A federal judge also issued a preliminary injunction preventing certain unidentified defendants from transferring or disposing of covered assets.
Will that translate into actual recovery? Maybe, but nobody should pretend it is simple. Once stolen assets are broken up, converted, and pushed through layers of wallets and services, the trail gets messy fast. In March 2025, Bybit said 88.87% of the funds remained traceable, 7.59% had gone dark, and 3.54% had been frozen. By April, Zhou said 27.6% of the stolen funds could no longer be tracked after conversion into Bitcoin and dispersion through thousands of wallets, cross-chain services, and crypto mixers.
That sequence is not contradictory; it is what laundering looks like over time. Traceability drops as attackers keep moving the money and adding layers. Bitcoin’s transparency helps investigators, but a public ledger is not a magic shield. It is a flashlight. Criminals still try to smear the lens.
Lazarus Group’s $1.4B Bybit Hack: 62, 200 ETH Moved, Full also underscores a broader truth about AI in security: it helps, but it is not some shiny robot savior. AI can accelerate alert triage, surface vulnerabilities, and reduce response times. It can also help attackers scale phishing, reconnaissance, and impersonation. The sensible position is the one Bybit says it takes: use AI aggressively for defense, but keep human judgement in the loop when real money is on the line.
The bigger shift here is operational. Security reviews that used to take days or weeks now need to happen in minutes or hours. Monitoring can’t be periodic. It has to be continuous. If attackers are acting at machine speed, the defense cannot show up after lunch.
That is the uncomfortable reality for custodial exchanges. No amount of branding, AI theater, or “trust us, bro” energy changes the fact that concentrated assets attract concentrated attacks. The best systems are the ones that assume someone is already trying to break in.
Key takeaways
-
Did Bybit really stop more than $700 million in losses?
Bybit says it intercepted more than $700 million in potential user losses. That is a self-reported figure, so it should be read as prevented or blocked activity, not independently audited confirmed theft. -
Was the 2025 hack linked to North Korea?
Yes. U.S. authorities, including the FBI, attributed the attack to North Korean actors tied to the TraderTraitor campaign. -
Is the $1.46 billion figure the same as the FBI’s estimate?
Essentially yes. Bybit cites roughly $1.46 billion, while the FBI described the theft as approximately $1.5 billion. That is the same loss rounded differently. -
Did AI solve Bybit’s security problems?
No. Bybit says AI improved detection, audit speed, and alert handling, but it still relies on human judgement for critical decisions. AI is a tool, not a shield made of fairy dust. -
What is the main lesson for crypto exchanges?
Security has to move at machine speed. Attackers already do, and the gap between “suspicious” and “stolen” can be measured in minutes.
Further reading
A few useful documents and background pieces for anyone tracking the Bybit/North Korea thread a little closer.
- FBI alert on North Korea’s responsibility for the $1.5 billion Bybit hack
- Beyond the voluntary trap: harmonizing global threat responses
- Bybit Security Report 2026 on $700M in loss prevention
- North Korea’s Lazarus Group targets crypto devs via npm
- North Korea’s Lazarus Group and the record $1.5B Bybit hack