Bybit has expanded its security infrastructure to address increasingly sophisticated cryptocurrency threats, intercepting more than $700 million in potential user losses during the first half of 2026.
The cryptocurrency exchange strengthened its defences following the theft of approximately $1.46 billion in digital assets in February 2025. Its updated approach focuses on detecting threats earlier, accelerating response times and adapting to new attack methods, including those powered by artificial intelligence.
According to Bybit’s H1 2026 Risk & Security Report, covering January 1 to June 15, the company’s security framework operates across three main areas: account protection, real-time blockchain monitoring and AI-assisted security operations.
Table of Contents
ToggleBybit security performance in H1 2026
| Security measure | H1 2026 result |
| Potential user losses intercepted | More than $700 million |
| Average initial risk-review time | 4.7 minutes |
| Business-relevant on-chain monitoring | 100% coverage |
| Token-project security incidents handled | 10, with no platform losses |
| Alerts processed using AI assistance | More than 100,000 |
“The cybersecurity arms race has entered an era of minutes. Using AI to strengthen our security and risk-control capabilities, while securing the AI systems themselves, is our top priority, with human judgement remaining at the centre of critical security decisions,” said David Zong, Head of Group Risk Control and Security at Bybit.
Suspicious withdrawals intercepted
During the reporting period, Bybit intercepted more than 30,000 suspicious withdrawal requests and protected nearly 20,000 users from potential losses exceeding $700 million.
The average initial review was completed in 4.7 minutes, while 95% of cases were reviewed within 10 minutes.
Bybit also identified around $212 million in funds potentially linked to fraudulent activity and blacklisted more than 10,000 malicious blockchain addresses. The company used on-chain behavioural analysis and AI-assisted monitoring to detect suspicious transactions and emerging fraud patterns.
Monitoring expands across blockchain activity
Bybit said its monitoring systems now cover all business-relevant on-chain activity, including listed token contracts, ecosystem contracts and the company’s cold, warm and hot wallets.
The exchange identified and responded to 10 security incidents involving listed token projects during the first half of 2026, with none resulting in losses for the platform.
In eight cases, Bybit said it completed emergency measures before other major cryptocurrency exchanges. Two attacks were detected before the affected token projects had identified the incidents themselves.
AI accelerates security testing
As cybercriminals increasingly use automation and AI to discover vulnerabilities, Bybit is applying the same technologies across threat monitoring, code auditing and penetration testing.
More than 100,000 security alerts were processed using AI-assisted analysis during the reporting period. The company said its AI-supported auditing systems identified high-severity vulnerabilities at three to five times the rate of manual reviews.
Automation also reduced the time required to move from a security assessment to testing from around two weeks to approximately two hours.
Bybit’s automated red-team platform assessed 1,489 publicly accessible assets and identified more than 100 high-severity vulnerabilities. The average time between discovering an asset and beginning initial penetration testing was reduced to less than 24 hours, compared with manual processes that can take several weeks.
The exchange said AI is primarily being used to improve the speed and scale of detection, while experienced security specialists continue to make critical and complex threat-related decisions.
Cooperation with investigators and law enforcement
Alongside its technical security measures, Bybit has worked with law enforcement agencies, blockchain intelligence companies and industry partners to trace and recover stolen digital assets.
The company has also pursued legal action against North Korea and the Lazarus Group as part of its efforts to establish accountability and recover assets linked to the February 2025 attack.
Bybit said effective cryptocurrency security requires coordination between exchanges, blockchain networks, investigators and law enforcement agencies. Its latest security strategy is intended to make attacks more difficult to carry out and less financially rewarding for those responsible.
The exchange added that its defensive systems will continue to evolve as attackers adopt new technologies, automation and AI-based methods.









