Bybit Blocks $700M Losses After $1.46B Crypto Hack

9 min read
3 views
Aug 19, 2026

Bybit just revealed it blocked more than $700 million in potential losses during the first half of 2026. After suffering one of the biggest crypto heists ever, the exchange rebuilt its defenses from the ground up. What they did next changed everything for users.

Financial market analysis from 19/08/2026. Market conditions may have changed since publication.

Imagine waking up one morning to discover that more than a billion dollars vanished from an exchange’s cold wallet overnight. That is exactly what happened to Bybit in February 2025. Fast forward to the first half of 2026, and the same platform is claiming it stopped over $700 million in potential losses before they could even reach users’ accounts. The turnaround feels almost unreal, yet the numbers keep stacking up.

How Bybit Turned a Massive Breach Into a Security Overhaul

The original attack drained roughly 400,000 ETH and staked Ether worth about $1.46 billion at the time. Investigators later tied the operation to North Korean actors, and the event still ranks as one of the largest single crypto thefts on record. Instead of folding, Bybit treated the disaster as a forced upgrade path. The latest Risk and Security Report covering January 1 through June 15 of 2026 shows the results of that rebuild.

Three distinct layers now sit at the core of the exchange’s defense model. One layer watches user accounts in real time. Another scans every relevant on-chain movement connected to the platform. The third leans on artificial intelligence to sort through mountains of alerts so human specialists can focus on the decisions that actually matter. I’ve watched similar rebuilds at other platforms, and the speed here stands out.

Stopping Suspicious Withdrawals Before They Happen

More than 30,000 withdrawal requests flagged as suspicious never left the system. Those blocks protected nearly 20,000 individual users and kept more than $700 million from potentially walking out the door. The average initial risk review took just 4.7 minutes. Ninety-five percent of those reviews finished inside ten minutes.

That kind of speed changes the game. When someone tries to empty an account after a phishing hit or a compromised device, every extra minute raises the chance the money disappears into a mixer. Bybit’s numbers suggest the new process closes that window fast enough to matter. In my view, the real test is whether the same pace holds when volume spikes during a market frenzy.

Alongside the withdrawal filters, the team flagged roughly $212 million in funds that showed patterns linked to fraud. More than 10,000 blockchain addresses landed on the internal blacklist. Behavioral analysis and AI models helped surface those patterns early, before the same tactics hit a larger group of users.

Full On-Chain Visibility Becomes Standard

The monitoring system now covers 100 percent of on-chain activity considered relevant to the business. That includes listed token contracts, ecosystem contracts, and the exchange’s own cold, warm, and hot wallets. During the reporting period the system caught and handled ten security incidents involving token projects listed on the platform. None of those incidents produced losses for Bybit itself.

In eight of the ten cases the security team completed its emergency response ahead of other major exchanges. Two of the incidents were spotted before the affected projects even realized something was wrong. That level of early detection is rare in this industry. Most platforms still treat monitoring as an optional extra rather than a core operating system.

A separate industry survey from July found that compromised keys, signers, and infrastructure accounted for 88.3 percent of the roughly $764 million stolen in the second quarter of 2026 alone. Only 9 percent of the 1,427 projects reviewed showed evidence of third-party monitoring. Just 4 percent combined monitoring, an active bug bounty, and a proper audit. Fourteen projects still got exploited even after completing audits, because the attackers targeted signer devices, admin keys, backend systems, or older contracts that the original audits never examined.

Bybit’s decision to watch everything connected to its ecosystem, including activity that starts outside its own walls, looks like a direct response to those gaps. Suspicious contract behavior or wallet movements can trigger a review even when the first sign of trouble appears on a completely different chain.

AI Shortens the Security Cycle From Weeks to Hours

More than 100,000 security alerts received AI-assisted analysis during the first half of the year. According to the report, AI-supported security audits caught high-severity vulnerabilities three to five times more often than pure manual review. The gap between finishing an assessment and starting the next round of testing shrank from about two weeks to roughly two hours.

An automated red-team platform examined 1,489 public-facing assets and found more than 100 high-severity issues. The average time from discovering a new asset to beginning the first penetration test dropped below 24 hours. Older manual processes sometimes needed weeks just to get started.

David Zong, the head of group risk control and security, put it bluntly: the cybersecurity arms race has entered an era of minutes. He also stressed that protecting the AI systems themselves is now a priority, while human judgment stays central for any decision that carries real weight. That balance feels right. Pure automation can miss context. Pure human review cannot keep up with the volume.

The cybersecurity arms race has entered an era of minutes.

– David Zong, Bybit Head of Group Risk Control and Security

Attackers are also using automation and AI to speed up reconnaissance. Cutting the time between first detection and first action has therefore become one of the most important metrics on the table. I’ve seen exchanges talk about “AI security” for years without showing measurable results. The concrete numbers here—alerts processed, vulnerabilities found, time saved—make the claim more credible than most.

Account Controls and On-Chain Screening Work Together

User accounts formed a third major focus. The 30,000-plus blocked withdrawals sat at the center of that effort. The combined value exceeded $700 million, though the report carefully labels the figure as potential losses rather than confirmed thefts that were stopped mid-flight. That distinction matters. Potential losses still represent real risk that never materialized for customers.

On-chain screening ran in parallel. The $212 million in potentially fraudulent funds and the 10,000 blacklisted addresses give a sense of the scale. Behavioral models helped surface new fraud campaigns as they appeared rather than after they had already hit a large group of users.

The original February 2025 breach remains the backdrop for everything that followed. Attackers compromised the process used to move funds out of the Ethereum cold wallet. Bybit’s CEO stated at the time that the exchange could cover the shortfall and keep processing customer withdrawals without interruption. That promise appears to have held.

Legal Pressure Joins the Technical Response

Technical upgrades have been matched by legal efforts. Earlier this month the exchange filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group. The case seeks recovery of assets tied to the February 2025 theft. A federal judge issued a preliminary injunction that stops certain unidentified defendants from moving or disposing of covered assets while the case continues.

Bybit has described the civil action as separate from ongoing U.S. criminal investigations. The FBI previously attributed the attack to North Korean actors and asked exchanges, validators, and other blockchain companies to block transactions linked to the laundering addresses. Tracing the stolen funds grew harder over time. In March 2025 the exchange reported that 88.87 percent of the funds remained traceable, 7.59 percent had gone dark, and 3.54 percent had been frozen. By April the share that could no longer be tracked had risen to 27.6 percent after the attackers moved assets into Bitcoin and scattered them across thousands of wallets, cross-chain bridges, and mixers.

A bounty program and voluntary freezes by other industry participants also played roles in the recovery process. Bybit covered the original shortfall through Ether purchases, loans, and deposits from counterparties while keeping customer withdrawals open. The U.S. civil case remains open; no final judgment has been issued.

The Broader Threat Landscape in 2026

North Korean actors did not stop after the Bybit event. Estimates published in May showed they stole about $2.02 billion in cryptocurrency during 2025, with the Bybit theft making up the largest single share. Cumulative crypto theft linked to the same actors reached roughly $6.75 billion according to one tracking firm. The pattern continued into 2026. Two attacks tied to the same group hit Drift Protocol and KelpDAO in April and drained a combined $577 million. Those incidents relied on social engineering, compromised devices, and bridge infrastructure rather than classic smart-contract bugs.

That shift in tactics is important. Conventional audits still matter, but they no longer cover the full attack surface. Signer devices, administrator keys, backend systems, and older contracts have become preferred targets. Continuous monitoring and rapid response therefore carry more weight than they did even two years ago.

I’ve found that the exchanges that treat security as a living process rather than a one-time checklist tend to weather these storms better. Bybit’s report shows measurable progress on detection speed, coverage, and automated testing. Whether those gains hold through the next major market cycle remains an open question, but the early data looks stronger than most post-hack rebuilds I’ve reviewed.

What Users Actually Gain From the New Setup

For everyday traders the most tangible benefit is the withdrawal screening layer. Being able to stop more than 30,000 suspicious requests before funds leave the platform reduces the chance that a compromised login turns into a total loss. The 4.7-minute average review time keeps friction low for legitimate users while still giving the system a chance to catch problems.

On-chain monitoring adds a second layer of protection that sits outside any single user’s control. When a listed project suffers an exploit, the exchange can often respond before the damage spreads to other platforms. That coordination is rare and valuable.

AI tools accelerate the internal feedback loop. Faster vulnerability discovery and shorter testing cycles mean fewer windows of exposure. The human specialists still make the final calls on complex cases, which reduces the risk of over-automated mistakes.

  • More than 30,000 suspicious withdrawals blocked
  • Nearly 20,000 users protected from potential losses
  • Over $700 million in potential losses prevented
  • $212 million in potentially fraudulent funds identified
  • More than 10,000 malicious addresses blacklisted
  • 100 percent coverage of relevant on-chain activity
  • Ten token-project incidents handled with zero platform losses
  • More than 100,000 alerts processed with AI assistance
  • Security assessment cycles cut from two weeks to two hours

Those figures paint a clearer picture than most exchange security updates. They also set a benchmark that other platforms will be measured against in the coming quarters.

Lessons That Extend Beyond One Exchange

The Bybit experience highlights several points that apply industry-wide. First, a major breach does not have to end an exchange’s story if leadership treats it as a forced modernization. Second, continuous monitoring of both internal systems and external on-chain activity can catch problems earlier than traditional audits alone. Third, AI works best as a force multiplier for human specialists rather than a full replacement.

Perhaps the most interesting aspect is the combination of technical controls and legal action. Most exchanges stop at the technical layer. Taking the fight into U.S. court against a nation-state actor is a higher-risk, higher-reward path. Whether it produces recoverable assets remains uncertain, but the signal it sends is clear.

The same July industry report that tracked $764 million in Q2 losses also showed how few projects maintain active monitoring. That gap creates systemic risk. When only a small percentage of platforms watch their own ecosystems in real time, attackers can move from one target to the next with relative ease. Broader adoption of the practices Bybit now describes would raise the cost of those campaigns.

Looking Ahead at the Arms Race

The phrase “era of minutes” captures the new reality. Attackers and defenders are both compressing timelines. Social engineering, compromised devices, and bridge infrastructure have joined smart-contract bugs as primary vectors. Defenders who still rely on quarterly audits and manual processes will keep losing ground.

Bybit’s report does not claim the platform is now invulnerable. It shows measurable improvement in detection speed, coverage, and response times after one of the most expensive lessons in crypto history. The $700 million in potential losses prevented during the first half of 2026 is the clearest single number attached to that improvement.

Whether those gains continue through the second half of the year and beyond will depend on execution. New attack methods will appear. AI systems will need constant protection of their own. Human judgment will remain the final filter. Still, the direction of travel is encouraging. An exchange that absorbed a $1.46 billion hit and then built a system capable of stopping hundreds of millions more in potential losses has at least demonstrated the capacity to adapt under pressure.

For users the practical takeaway is straightforward. Platforms that publish concrete security metrics, maintain continuous monitoring, and keep response times measured in minutes rather than days offer a clearer risk profile than those that do not. The Bybit numbers give the market one more data point to use when comparing those profiles. In a space where trust is rebuilt one prevented incident at a time, that kind of transparency carries real weight.


The story is still unfolding. Legal proceedings continue. New threats will test the upgraded systems. Yet the first half of 2026 already shows what determined post-breach reconstruction can look like when an exchange decides that “good enough” is no longer acceptable. The $700 million figure is only one measure of that decision. The broader shift in monitoring coverage, AI integration, and response speed may prove more lasting.

If investing is entertaining, if you're having fun, you're probably not making any money. Good investing is boring.
— George Soros
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>