Newsroom

Bybit Blocks Over $700 Million in Potential Losses Using AI a Year After $1.46 Billion Hack

19 August, 2026   /   News   /  AI   /   Tags:  bybit, security, theft, north, lazarus

Bybit Blocks Over $700 Million in Potential Losses Using AI a Year After $1.46 Billion Hack

Exchange reports intercepting more than 30,000 suspicious withdrawals and accelerating vulnerability detection in first-half 2026 security update

Crypto exchange Bybit said its security systems prevented more than $700 million in potential user losses during the first half of 2026, according to its latest risk and security report covering January 1 through June 15. The figures come roughly a year and a half after the platform suffered a $1.46 billion theft from its Ethereum cold wallet in February 2025, an incident U.S. authorities attributed to North Korea’s Lazarus Group.

Suspicious Withdrawals and On-Chain Screening

Bybit reported intercepting more than 30,000 suspicious withdrawal requests in the period, shielding nearly 20,000 users. Initial risk reviews of flagged requests averaged 4.7 minutes, with 95 percent completed within 10 minutes. The exchange described the $700 million total as potential losses rather than confirmed thefts underway.

Alongside account-level controls, security teams identified approximately $212 million in funds potentially connected to fraud and added more than 10,000 malicious blockchain addresses to the platform’s blacklist. Behavioral analysis combined with AI-supported monitoring helped detect emerging fraud patterns.

Three-Layer Defense and Full On-Chain Coverage

The exchange outlined a three-layer defense model consisting of user account controls, continuous on-chain monitoring, and AI-supported security operations, with human specialists retaining final authority on critical decisions. Monitoring now covers 100 percent of on-chain activity the company considers relevant to its operations, including listed token contracts, ecosystem contracts, and cold, warm, and hot wallets.

During the reporting window the system identified and managed 10 security incidents involving token projects listed on Bybit. None resulted in losses to the exchange. In eight cases teams completed emergency responses ahead of other major platforms, and in two instances the incidents were detected before the affected projects themselves recognized the attacks.

AI Accelerates Detection and Testing

Artificial intelligence processed more than 100,000 security alerts. AI-supported audits identified high-severity vulnerabilities at rates three to five times higher than traditional manual reviews. The interval between a security assessment and follow-up testing fell from roughly two weeks to about two hours.

An automated red-team platform evaluated 1,489 public-facing assets and flagged more than 100 high-severity vulnerabilities. The average time from discovering an asset to beginning penetration testing dropped below 24 hours, compared with manual processes that previously stretched across weeks.

The cybersecurity arms race has entered an era of minutes.
David Zong, Bybit head of group risk control and security

Zong stated that protecting the AI systems themselves ranks as a priority alongside their use in defense, while human judgment remains central for the highest-stakes decisions.

Background of the 2025 Breach and Legal Steps

On February 21, 2025, attackers compromised the process for moving funds from Bybit’s Ethereum cold wallet, draining roughly 400,000 ETH and staked Ether valued at about $1.46 billion at the time. The incident stands as the largest recorded cryptocurrency theft by value. Bybit covered the shortfall through Ether purchases, loans, and counterparty deposits and continued processing customer withdrawals.

The exchange has worked with law enforcement, blockchain intelligence firms, and industry partners to trace the stolen assets. In recent weeks it filed a lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, seeking recovery of assets linked to the breach. A federal court issued a preliminary injunction restricting certain parties from moving or liquidating specified assets while the case proceeds.

North Korean-linked actors accounted for an estimated $2.02 billion in cryptocurrency theft during 2025, with the Bybit incident forming the bulk of that total. Cumulative crypto theft attributed to North Korea has been estimated at approximately $6.75 billion. Separate Lazarus-linked incidents against other protocols in April 2026 reportedly involved a combined $577 million.

Bybit’s report presents the first detailed numerical account from a major centralized exchange of how AI-assisted tools are being applied to shorten detection and response windows in an environment where both attackers and defenders increasingly rely on automation.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.