Bybit’s Security Enhancements in 2026
In the first half of 2026, cryptocurrency exchange Bybit successfully thwarted over $700 million in potential losses for its users, owing to the enhancement of its security measures including real-time blockchain monitoring and AI-driven threat detection. This proactive approach comes in the wake of a monumental hack in February 2025, where the platform lost around $1.46 billion, marking it as the largest theft in cryptocurrency history, attributed to North Korean cybercriminals by U.S. authorities.
Robust Security Framework
Bybit’s Risk & Security Report for the period from January 1 to June 15 outlines a robust security framework now comprised of three primary defense layers: protective measures for user accounts, continuous on-chain surveillance, and AI-assisted security operations, all while human specialists retain oversight for critical decisions. In total, more than 30,000 suspicious withdrawal attempts were flagged and managed, effectively safeguarding nearly 20,000 users. The initial assessments for risk identification averaged a swift 4.7 minutes, with a remarkable 95% completed in under 10 minutes.
Fraud Detection and Monitoring
In addition to their monitoring capabilities, Bybit’s security teams identified approximately $212 million in funds suspected to be connected with fraudulent activities, culminating in the blacklisting of over 10,000 malicious blockchain addresses. Employing behavioral analysis and AI-enhanced monitoring techniques allowed the exchange to spot transaction patterns related to evolving fraud schemes.
Continuous Monitoring Necessity
Following the massive breach in 2025, Bybit has made significant strides in redesigning its security infrastructure, ensuring that its monitoring systems now encompass 100% of relevant on-chain activities linked to the business. This includes oversight of listed token contracts, ecosystem contracts, and various wallet types.
In the realm of cryptocurrency security, the necessity for continuous monitoring has become starkly evident. A July report highlighted that significant vulnerabilities accounted for a staggering 88.3% of roughly $764 million stolen during Q2 of 2026. Of the 1,427 projects analyzed, only 9% had indicators of third-party monitoring, while a mere 4% exhibited comprehensive security monitoring measures alongside audits.
AI Technology in Defense Strategies
AI technology has become integral to Bybit’s defense strategies, allowing the organization to process over 100,000 security alerts during the first half of the year. According to their report, AI-assisted security audits demonstrated a capability to detect severe vulnerabilities at a rate three to five times faster than traditional manual reviews. The automation of these processes significantly reduced turnaround time, allowing security assessments to transition seamlessly from initial discovery to testing within hours rather than weeks.
Automated Threat Evaluation
The exchange’s automated red-team platform evaluated 1,489 public-facing assets and uncovered over 100 high-severity vulnerabilities, demonstrating that timely action against detected threats is crucial. Bybit’s David Zong emphasized that in the escalating cybersecurity landscape, where even attackers may leverage AI, minimizing latency between incident detection and response has become vital.
User Account Protection and Legal Actions
The report also highlights the steps taken toward user account protection, particularly with suspicious withdrawal requests, resulting in significant intercepted funds during the January to June period. The aftermath of the 2025 attack undoubtedly drove Bybit to adapt and enhance its security apparatus, with Bybit CEO Ben Zhou previously assuring stakeholders that the exchange could absorb the losses and continue to maintain withdrawal operations.
In light of the ongoing threats in the crypto space, Bybit has not only fortified its defenses but is also pursuing legal action against North Korea and its related entities in a bid to recover stolen assets. A recent lawsuit aims to address the significant losses sustained during the hacking incident, with a federal injunction currently in place to prevent asset transfers by certain defendants implicated in the theft. The challenges of asset recovery have only compounded since the breach, leading to ongoing collaborative efforts with law enforcement agencies to navigate this complex landscape while continuing customer service operations effectively.