Bybit Blocks $700M After $1.46B Hack; Boosts AI Security

Bybit says AI-assisted monitoring and continuous on-chain surveillance blocked over $700M in potential losses during H1 2026 after its $1.46B 2025 Ethereum cold-wallet breach, while legal action targets Lazarus Group.

.3 Comments
Bybit Blocks $700M After $1.46B Hack; Boosts AI Security

7 Minutes

Follow on Google

Bybit intercepts more than $700 million in potential losses

Bybit says its upgraded security stack stopped over $700 million in suspected withdrawals during the first half of 2026, a dramatic improvement after the platform’s February 2025 Ethereum cold-wallet breach that drained roughly $1.46 billion. The exchange credits a layered defence strategy—combining account controls, continuous on-chain monitoring and AI-enhanced detection—with preventing more than 30,000 suspicious withdrawal attempts and shielding nearly 20,000 users from potential loss.

Three layers of defence: accounts, on-chain visibility and AI operations

Bybit’s H1 2026 Risk & Security Report outlines a three-tiered security model. The first layer focuses on account-level protections to spot and block suspicious withdrawals; the second layer extends continuous monitoring across all business-relevant on-chain activity; the third layer uses AI to triage alerts, accelerate testing and support security analysts while preserving human oversight for high-risk decisions.

Account controls: fast review, effective blocks

During H1, the exchange intercepted more than 30,000 withdrawal requests classified as suspicious. Initial automated reviews averaged just 4.7 minutes, and 95% of cases were resolved within 10 minutes—reducing the window attackers rely on to execute automated theft chains. Bybit reported that these account-level interventions covered potential exposure exceeding $700 million, a conservative figure the company describes as potential losses rather than confirmed stolen assets.

On-chain coverage: 100% of business-relevant activity

Bybit expanded its blockchain monitoring to cover all on-chain elements relevant to its operations. That includes listed token contracts, partner ecosystem contracts and the exchange’s cold, warm and hot wallets. This end-to-end visibility let Bybit flag suspicious contract behaviour and wallet movements even when an incident began off-platform. The system reportedly detected and managed 10 security incidents affecting tokens listed on the exchange during H1, with zero platform losses recorded.

In eight of those token-related incidents, Bybit’s emergency response outpaced other major exchanges, and in two cases the company detected the attacks before the projects themselves had identified problems. The results highlight how continuous on-chain monitoring can limit contagion and protect traders when threats originate in external infrastructure like bridges, validators or third-party signers.

AI accelerates threat detection, triage and testing

Artificial intelligence now plays a key role in processing alerts, surfacing anomalous transaction patterns and speeding up security assessments. Bybit reports that more than 100,000 security alerts received AI-supported analysis in H1 2026, improving both the depth and speed of investigations.

Faster audits and red-team coverage

AI-assisted security audits identified high-severity vulnerabilities at three to five times the rate of manual reviews, the report says. Automation reduced the time between an initial security assessment and follow-up testing from roughly two weeks to about two hours. Bybit’s automated red-team platform scanned 1,489 public-facing assets and surfaced more than 100 high-severity issues, while the average time from asset discovery to the start of penetration testing dropped below 24 hours.

The exchange emphasizes that AI is a force multiplier rather than a replacement for human judgement: automated systems are used to triage and process large-scale telemetry, but specialists retain control over critical mitigation decisions and complex incident responses.

Behavioral analytics and blacklist enforcement

Across accounts and on-chain signals, behavioural analysis and pattern recognition were essential to identifying the latest fraud campaigns. Security teams flagged approximately $212 million in funds potentially linked to illicit activity and added more than 10,000 malicious blockchain addresses to internal blacklists. These measures complement traditional countermeasures—such as KYC and withdrawal limits—by tracking how funds move through mixers, bridges and cross-chain services.

Tracing, recovery and legal action after the 2025 breach

The Feb. 21, 2025 compromise of Bybit’s Ethereum cold wallet remains a defining moment for the exchange’s security overhaul. That breach—later attributed by U.S. authorities to North Korean actors associated with the Lazarus Group—removed more than 400,000 ETH and staked Ether, valued at about $1.46 billion at the time. Following the attack, Bybit said it could absorb the loss and continue customer withdrawals while pursuing technical and legal avenues to recover assets.

Asset tracing and the limits of forensics

Investigators initially reported high traceability, but asset-flow analysis became more difficult as attackers converted assets into Bitcoin and fragmented funds across thousands of wallets, cross-chain services and crypto mixers. Bybit’s public disclosures showed traceability estimates deteriorating over time: what was largely visible in March 2025 became substantially more opaque by April, when a larger percentage of stolen funds could no longer be tracked.

The broader picture is stark: Chainalysis and other blockchain-intelligence firms estimated North Korean-linked thefts at roughly $2.02 billion during 2025, with the Bybit incident accounting for the largest share. Cumulative estimates tied to North Korea’s cyber-theft campaigns have since climbed into the billions of dollars.

U.S. civil lawsuit versus North Korea and Lazarus

Beyond forensic and freezing efforts, Bybit has pursued civil remedies. In mid-2026 the exchange filed a lawsuit in U.S. federal court seeking recovery of assets stolen in the February 2025 breach, naming North Korea, the Reconnaissance General Bureau and the Lazarus Group. The court issued a preliminary injunction preventing certain unnamed defendants from transferring or disposing of assets identified in the order while the case proceeds.

Bybit stresses these civil proceedings are distinct from ongoing criminal investigations led by U.S. authorities. The FBI previously attributed the attack to North Korean actors and coordinated requests for exchanges, validators and blockchain service providers to block transactions tied to laundering addresses.

Industry context: why continuous monitoring and AI matter

Bybit’s report comes amid a larger industry wake-up call about the limits of conventional security measures. Independent security firms found that compromised keys, signers and infrastructure—rather than exploitable smart contract code—accounted for a large share of value stolen in recent quarters. In one analysis, compromised infrastructure explained the majority of roughly $764 million stolen in the second quarter of 2026, with many projects lacking integrated monitoring, active bug bounties and up-to-date audits.

AI-driven tooling and automated red-team testing address several of these gaps by enabling faster recognition of attacker reconnaissance and quicker validation of mitigation controls. However, attackers are also adopting automation and AI to speed up vulnerability discovery and social-engineering campaigns, so the timeline for detection and response has tightened from days and weeks to minutes and hours.

Operational lessons and best practices for exchanges and projects

Bybit’s experience suggests several operational priorities for crypto exchanges, DeFi projects and blockchain infrastructure providers:

  • Maintain continuous on-chain monitoring for all business-relevant contracts and wallets to detect off-platform attack vectors early.
  • Combine automated AI triage with human decision-making to ensure speed without sacrificing judgement for complex incidents.
  • Implement automated red-team and penetration-testing pipelines to reduce the time between asset discovery and remediation.
  • Blacklist and share indicators of compromise quickly across industry participants to limit re-use of stolen funds.
  • Pursue legal and law-enforcement channels alongside technical recovery measures to maximize the chances of asset recovery.

Outlook: a faster, more automated security posture

Bybit’s H1 2026 report paints a picture of a crypto platform that has shifted from reactive incident handling toward proactive, automated defence. The exchange’s investments in AI, continuous monitoring and faster penetration testing reduced incident response windows and increased the volume of threats it can manage without human bottlenecks. Still, the company underscores that human specialists remain central for judgment calls during high-severity incidents.

For the wider market, the lesson is clear: continuous, AI-assisted monitoring and rapid automated testing are becoming baseline expectations for any service that custody or moves meaningful crypto assets. Attackers will continue to evolve—using automation and social engineering to exploit weak links—so exchanges and projects must accelerate detection, containment and industry-wide information sharing if the sector is to limit future large-scale thefts.

Bybit’s combined technical improvements and legal actions illustrate a multichannel approach to incident response: better visibility, faster mitigation and parallel legal efforts aimed at recovering stolen assets. As the crypto ecosystem matures, these layered defenses and faster reaction times will be essential to protect users and uphold market integrity.

Sourcecrypto.news
Daniel Rivers
"Hey there, I’m Daniel. From vintage engines to electric revolutions — I live and breathe cars. Buckle up for honest reviews and in-depth comparisons."

Leave a Comment

Comments (3)

Reza

feels a bit like PR spin, sure they improved response times, but calling $700M 'potential' is handy. show some proof, independent trace or i'll stay skeptical.

atomwave

wow didnt expect that level of upgrade! 30k withdrawals stopped, 100k AI alerts triaged, impressive but still nervous about attacker AI tho

blocktone

Is this for real? 700M stopped sounds great but how many false positives? 30k blocks in 6 months... feels wild, need independent audit