Bybit says it stopped more than $700 million in potential losses during the first half of 2026, a figure the exchange disclosed in a new security report released roughly a year and a half after hackers drained $1.46 billion from its Ethereum cold wallet in what remains the largest cryptocurrency theft on record. The numbers, laid out in the Bybit security report 2026 covering January 1 through June 15, offer the clearest picture yet of how the exchange has rebuilt its defenses after the February 2025 breach linked to North Korea’s Lazarus Group.
Summary
Key takeaways
- Bybit intercepted more than 30,000 suspicious withdrawal requests in H1 2026, protecting nearly 20,000 users and blocking over $700 million in potential losses.
- The exchange blacklisted more than 10,000 malicious blockchain addresses and flagged about $212 million in funds tied to suspected fraud.
- AI-assisted audits cut vulnerability detection time from roughly two weeks to about two hours, finding three to five times more high-severity issues than manual reviews.
- The report follows the February 21, 2025 hack that drained about $1.46 billion in Ethereum and staked Ether, an attack U.S. authorities attributed to North Korea’s Lazarus Group.
- Bybit has filed a lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group.
Bybit thwarts over $700 million in potential losses in early 2026
Bybit’s numbers show a security operation moving faster than the fraud attempts it’s designed to catch. More than 30,000 suspicious withdrawal requests were intercepted between January and mid-June, protecting close to 20,000 users from losses that could have totaled over $700 million, according to the exchange’s H1 2026 Risk & Security Report.
The report is careful to note that the $700 million figure reflects potential losses, not assets confirmed to have been stolen. Initial risk reviews averaged 4.7 minutes to complete, and 95% wrapped up within 10 minutes — a turnaround speed the exchange credits to behavioral analysis paired with AI-supported monitoring designed to catch new fraud patterns as they emerge.
Suspicious withdrawals and user protection
Account-level controls formed one pillar of that defense. Withdrawal requests flagged as suspicious were intercepted before funds left the platform, with the combined value involved exceeding $700 million across the period.
Blacklist of malicious blockchain addresses
On-chain screening ran alongside those account controls. Security teams identified roughly $212 million in funds potentially connected to fraud and added more than 10,000 malicious addresses to Bybit’s blacklist, a scale of enforcement the exchange says reflects the growing sophistication of fraud campaigns hitting crypto platforms broadly.
Security architecture and AI-driven defense
Bybit’s rebuilt security model rests on three layers working together: user account controls, continuous on-chain monitoring, and AI-supported security operations, with human specialists retaining final say over critical decisions. That structure is the backbone of what the exchange now describes as a defense system built to close the gap between detecting a threat and acting on it.
Three-layer defense system
The monitoring layer now covers 100% of on-chain activity the exchange considers relevant to its business, including listed token contracts, ecosystem contracts, and its cold, warm, and hot wallets. During the first half of the year, that system identified and handled 10 security incidents affecting token projects listed on Bybit, and none resulted in losses to the exchange. In eight of those cases, Bybit’s teams completed emergency responses before other major exchanges did, and two incidents were caught before the affected projects had even identified the attacks themselves.
AI accelerated vulnerability detection
Artificial intelligence has taken on a bigger share of the workload. During the initial six months, AI-assisted analysis processed in excess of 100,000 security alerts, and AI-supported Through audits, high-severity vulnerabilities were identified at rates three to five times higher compared to traditional manual approaches. Automated systems additionally cut the gap between a security assessment and follow-up testing from about two weeks down to roughly two hours.
An automated red-team platform assessed 1,489 public-facing assets and flagged more than 100 high-severity vulnerabilities, with the average time between discovering an asset and beginning penetration testing falling below 24 hours — compared with manual processes that could stretch on for weeks.
“The cybersecurity arms race has entered an era of minutes,” said David Zong, Bybit’s head of group risk control and security. Zong said protecting the AI systems themselves is now treated as a priority alongside using AI for defense, adding that human judgment stays central when the stakes are highest. That framing matters beyond Bybit: as attackers increasingly lean on automation to speed up reconnaissance, exchanges that can’t match that pace risk falling permanently behind.
The $1.46 billion 2025 hack attributed to North Korea’s Lazarus Group
Bybit’s current defenses exist because of a breach that redefined the scale of crypto theft. On February 21, 2025, attackers compromised the process used to move funds from Bybit’s Ethereum cold wallet, draining approximately 400,000 ETH alongside staked Ether valued at roughly $1.46 billion during that period. CEO Ben Zhou said at the time the exchange could absorb the loss and keep processing customer withdrawals, and it covered the shortfall through Ether purchases, loans, and counterparty deposits.
Details of the 2025 Ethereum cold wallet breach
The breach became the largest recorded cryptocurrency theft by value. U.S. authorities later attributed the attack to North Korean actors, and the FBI asked exchanges, validators, and blockchain companies to block transactions tied to the addresses used in the laundering operation.
Context of North Korean crypto theft operations
The Bybit hack wasn’t an isolated event. Estimates published in May showed In 2025, North Korean-linked actors obtained approximately $2.02 billion in cryptocurrency, with the Bybit incident representing the majority of this amount. Blockchain analytics firm According to Chainalysis, this activity brought the total cryptocurrency theft attributable to North Korea to approximately $6.75 billion. Such threats didn’t stop with the calendar year, either — two Lazarus-linked attacks against Drift Protocol and KelpDAO in April 2026 reportedly drained a combined $577 million, split between $285 million from Drift and $292 million from KelpDAO, using social engineering, compromised devices, and bridge infrastructure rather than conventional smart contract exploits.
That pattern — attackers pivoting away from code-level exploits toward human and infrastructure weak points — is part of why the industry conversation around crypto hardware wallet and cyberattack risk has widened beyond a single exchange or exploit. It suggests defenders can’t rely on smart contract audits alone; the attack surface now includes signers, devices, and the people operating them.
Ongoing recovery and legal actions
Recovering the stolen funds has proven far harder than detecting the breach itself. Bybit continues working with law enforcement agencies, blockchain intelligence firms, and other industry participants to trace assets from the 2025 attack, but the trail has grown fainter with time.
Bybit’s collaboration with law enforcement and blockchain intelligence
In March 2025, Bybit reported that 88.87% of the stolen remained subject to tracking, whereas 7.59% had become untraceable and 3.54% had been immobilized. Zhou noted that by April, 27.6% of the pilfered funds had become untrackable following attackers converted the converted assets to Bitcoin and moved them across numerous wallets, inter-chain bridges, and mixing protocols — a laundering pattern that illustrates why recovering funds after a large-scale theft becomes exponentially harder the longer stolen assets stay in motion.
Lawsuit filed in US District Court
Bybit has pursued legal action in U.S. courts as well. In recent weeks, the platform initiated proceedings in the U.S. District Court for the District of Columbia, naming North Korea, its Reconnaissance General Bureau intelligence division, and the Lazarus Group as defendants, with the objective of recovering assets connected to the February 21 incident. A federal court granted a preliminary injunction barring certain unnamed parties from moving or liquidating assets subject to the order pending resolution of the matter.
According to Bybit, the civil litigation operates independently from U.S. criminal probes regarding North Korean cyber operations, and no final ruling has been rendered on Bybit’s allegations. The platform has indicated its commitment to seeking additional remedies as the legal process advances, though any settlement faces significant delays given the complexities inherent in enforcing court orders against state entities.
Challenges in tracing stolen funds
The gap between Bybit’s 2026 security metrics and its unresolved 2025 losses says something about where the crypto industry stands right now: exchanges can build faster detection systems and cut response times to hours, but once stolen funds hit mixers and cross-chain bridges, recovery still depends on international legal processes that move at a very different speed. That mismatch — real-time defense against slow-motion justice — is likely to remain a defining tension for the sector as long as state-linked hacking groups keep targeting crypto infrastructure.
FAQ
How much potential loss did Bybit prevent in the first half of 2026?
Bybit intercepted over $700 million in potential losses by capturing more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users.
What was the scale and cause of the 2025 Bybit hack?
The 2025 breach drained about $1.46 billion worth of Ethereum and staked Ether from Bybit’s cold wallet and was attributed by U.S. authorities to North Korean Lazarus Group hackers.
What security measures does Bybit currently employ to protect users?
Bybit uses a three-layer defense system involving user account controls, continuous on-chain monitoring covering all relevant activities, and AI-supported security operations.
What legal steps has Bybit taken following the 2025 hack?
Bybit filed a lawsuit in the U.S. District Court against North Korea, its Reconnaissance General Bureau, and the Lazarus Group seeking recovery of stolen assets.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

