Exchange Risk & Security

Bybit Reports Intercepting Over $700M in Potential Losses Following H1 2026 Security Overhaul

According to crypto.news, Bybit's security systems blocked over $700 million in potential user losses during the first half of 2026 following real-time blockchain monitoring and artificial intelligence threat detection expansions. These claims, detailed in the platform's H1 2026 Risk & Security Report, remain not officially confirmed by independent or regulatory authorities.

Bybit security monitoring and risk control dashboard illustration
Image: crypto.news

Overview of H1 2026 Security Metrics

According to reporting by crypto.news, Bybit released its H1 2026 Risk & Security Report covering the period from January 1 through June 15, highlighting significant expansions in automated defense mechanisms. The publication stated that the exchange intercepted more than 30,000 suspicious withdrawal requests during the first half of the year, effectively protecting approximately 20,000 users from potential financial harm. The total combined value associated with these intercepted requests exceeded $700 million, although the report characterized this figure as potential losses rather than confirmed targeted thefts successfully thwarted at the final hour. Furthermore, the risk operations team handled initial withdrawal reviews within an average timeframe of 4.7 minutes, with 95% of all evaluations concluded inside a ten-minute window.

In addition to account-level withdrawal controls, the exchange reported that on-chain screening mechanisms identified approximately $212 million in funds potentially linked to fraudulent activities. The security infrastructure blacklisted more than 10,000 malicious blockchain addresses during the same timeframe, utilizing behavioral analysis and artificial intelligence-supported monitoring to flag anomalous transaction patterns connected to emerging fraud campaigns. These reported statistics reflect a concerted push by the platform to harden its perimeter following the historic security breach it experienced in early 2025. However, industry observers note that these internal figures and self-reported metrics have not been independently verified by external regulatory bodies or third-party auditing firms, leaving questions about the exact methodology open to interpretation.

Comprehensive On-Chain Coverage and Incident Handling

Crypto.news reported that Bybit’s monitoring architecture now encompasses 100% of on-chain activity deemed relevant to its commercial operations. This comprehensive oversight includes listed token contracts, ecosystem infrastructure contracts, and the enterprise's cold, warm, and hot wallets. Throughout the first half of 2026, the monitoring framework successfully identified and managed ten distinct security incidents affecting token projects listed on the exchange. Crucially, the report asserted that none of these ten project-level incidents resulted in direct financial losses to Bybit itself. Security operations teams reportedly completed emergency response protocols ahead of other major industry exchanges in eight of those instances, while two events were detected internally prior to the affected token projects identifying the breaches within their own setups.

This continuous visibility enables the exchange's security apparatus to observe internal trading engine activities alongside direct transactions occurring across supported public blockchains. Consequently, suspicious smart contract behavior or wallet movements can undergo rigorous review even when an incident initiates completely outside the infrastructure owned and operated by Bybit. External industry analyses highlighted by crypto.news indicate that continuous monitoring remains a critical vulnerability across the broader cryptocurrency sector. For instance, data from Hacken showed that compromised keys, signers, and administrative infrastructure accounted for the vast majority of thefts during the second quarter of 2026, with very few projects maintaining comprehensive multi-layered monitoring alongside active bug bounty programs and robust audits.

Artificial Intelligence Integration in Vulnerability Assessment

According to the published findings, artificial intelligence has assumed a progressively prominent role within Bybit's defensive posture, processing more than 100,000 security alerts during the first half of 2026. The exchange reported that AI-supported security audits detected high-severity vulnerabilities at a rate three to five times greater than traditional manual review methods. Furthermore, automation successfully compressed the interval between a security assessment and subsequent testing from approximately two weeks down to roughly two hours. The enterprise's automated red-team platform evaluated 1,489 public-facing assets, uncovering over one hundred high-severity vulnerabilities and reducing the time required to initiate penetration testing to under twenty-four hours.

David Zong, Bybit’s head of group risk control and security, remarked via crypto.news that the cybersecurity industry has entered an era measured in minutes. Zong emphasized that while artificial intelligence is heavily utilized to parse complex datasets, discover latent vulnerabilities, and accelerate testing velocity, human specialists retain absolute control over critical decision-making processes. This operational philosophy seeks to counterbalance the tactics employed by sophisticated malicious actors who similarly leverage automation and machine learning to expedite reconnaissance. Nevertheless, security experts remind stakeholders that reliance on artificial intelligence tools introduces new attack surfaces that require careful governance, rendering self-reported speed metrics subject to ongoing verification.

Context of Past Breaches and Ongoing Threat Landscape

The comprehensive security overhaul at Bybit follows the severe February 2025 breach that drained approximately $1.46 billion from its Ethereum cold wallet, marking the largest recorded cryptocurrency theft by nominal value. United States authorities and blockchain investigators subsequently attributed the operation to North Korean threat actors, specifically the Lazarus Group. Estimates from blockchain analytics firms indicate that North Korean cyber operations accumulated billions in stolen digital assets across 2025 and early 2026, leveraging social engineering, compromised signer devices, and bridge infrastructure rather than conventional smart contract flaws to bypass perimeter defenses.

Bybit has continuously maintained that it successfully covered the asset shortfall resulting from the 2025 incident through strategic counterparty loans, internal reserves, and asset purchases, allowing customer withdrawals to proceed without interruption. However, the sheer scale of the initial theft has left lasting repercussions across the digital asset ecosystem. The persistence of advanced persistent threat groups targeting centralized exchanges underscores the necessity of the multi-layered defensive strategies currently reported by the platform, even as independent analysts continue to monitor the broader implications of these cross-border cyber campaigns.

Conclusion, Entity Impact, and Next Action

In conclusion, crypto.news reported that Bybit implemented extensive security upgrades during the first half of 2026, intercepting over $700 million in potential user losses following its prior $1.46 billion breach. The affected entity, Bybit, along with its nearly 20,000 protected users, experienced enhanced account controls and automated monitoring. However, these reported improvements and performance metrics remain not officially confirmed by independent regulatory or third-party auditing authorities.

As the next action, affected user groups and industry participants must monitor official platform communications and maintain rigorous personal account security practices. Stakeholders should separate the reported internal risk mitigation measures from unconfirmed operational efficiency claims while awaiting further verification from authorized legal and investigative bodies regarding ongoing asset recovery proceedings in U.S. courts.

Cexvia conclusion

Conclusion and Outlook on Exchange Risk Management

Bybit claims its H1 2026 security upgrades intercepted over 30,000 suspicious withdrawals and protected nearly 20,000 users, though these performance metrics remain not officially confirmed by external regulators or third-party auditors.

Risk meaning
The deployment of automated artificial intelligence testing and continuous on-chain screening highlights an industry-wide race to compress detection windows, though lingering risks from advanced threat actors and compromised infrastructure persist.
User action
Users should maintain vigilant account security practices, enable multi-factor authentication, and remain aware of ongoing risk mitigation efforts across centralized trading venues.
Bybit