Bybit's security systems intercepted more than $700 million in potential user losses during the first half of 2026, the exchange said, as it built out real-time blockchain monitoring and AI-assisted threat detection following its $1.46 billion hack in February 2025. The exchange now tracks all business-relevant on-chain activity, and AI assistance has cut some security-testing cycles from two weeks to two hours.
Bybit's security teams intercepted more than 30,000 suspicious withdrawal requests, protecting nearly 20,000 users and blocking over $700 million in potential losses during the first half of 2026, according to the exchange's H1 2026 Risk & Security Report, which covers Jan. 1 through June 15. Initial risk reviews took an average of 4.7 minutes, with 95% completed within 10 minutes, and the report described the $700 million figure as potential losses rather than assets attackers actually reached.
Security teams also identified about $212 million in funds potentially connected to fraud and blacklisted more than 10,000 malicious blockchain addresses.
Monitoring now covers all relevant on-chain activity
Bybit said its monitoring system now covers 100% of on-chain activity considered relevant to its business, including listed token contracts, ecosystem contracts and its cold, warm and hot wallets. The system identified and handled 10 security incidents affecting token projects listed on the exchange during the period, with none causing losses to Bybit. In eight of those cases, security teams completed emergency responses before other major exchanges, and two incidents were caught before the affected projects had identified the attacks themselves.
AI cuts security testing from weeks to hours
More than 100,000 security alerts received AI-assisted analysis during the first half of the year, Bybit said. AI-supported audits detected high-severity vulnerabilities at three to five times the rate achieved through manual review, and automation cut the gap between a security assessment and follow-up testing from about two weeks to roughly two hours. According to crypto.news: "The cybersecurity arms race has entered an era of minutes," said David Zong, Bybit's head of group risk control and security.
Bybit takes the Lazarus recovery fight to US court
Bybit has also pursued recovery of the funds taken in the 2025 hack, which drained more than 400,000 ETH and staked Ether worth about $1.46 billion from its Ethereum cold wallet. Earlier this month, the exchange filed a US lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group in the U.S. District Court for the District of Columbia, and a federal judge issued a preliminary injunction blocking certain unidentified defendants from moving assets tied to the case.
Tracing the stolen funds has grown harder since the attack. By April, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked after attackers converted the assets into Bitcoin and dispersed them through thousands of wallets, cross-chain services and crypto mixers.
Source: Bybit
Trading involves risk.