Bybit's AI security push intercepts $700m in crypto threats

Bybit's H1 2026 security report shows AI-assisted defences stopping 30,000 suspicious withdrawals as crypto exchanges race attackers using the same tools.

Hands type on a keyboard on a desk, positioned before a curved array of multiple computer monitors displaying glowing blue circuit patterns, with a bright, out-of-focus windowed room in the background.

Bybit, the Dubai-headquartered cryptocurrency exchange the company describes as the world's second-largest by trading volume, has published a detailed account of its rebuilt security architecture, one shaped directly by the February 2025 theft of approximately $1.46 billion in digital assets, the largest exchange breach on record at the time.

The H1 2026 Risk and Security Report, covering January through mid-June, describes a three-layer system spanning account protection, real-time on-chain monitoring, and AI-assisted security operations. The headline numbers are striking on their own terms: more than 30,000 suspicious withdrawal requests intercepted, nearly 20,000 users protected, and roughly $700 million in potential losses prevented. The average initial review, the company says, took 4.7 minutes, with 95% of cases closed within ten minutes.

AI on both sides of the firewall

The more strategically significant element of the report is what it reveals about the changing nature of the threat itself. Bybit's framing is explicit: attackers are now deploying automation and AI to accelerate reconnaissance, vulnerability discovery, and exploitation. Its response is to apply the same tooling on the defensive side.

During the first half of 2026, more than 100,000 security alerts were processed with AI-assisted analysis. AI-augmented code auditing identified high-severity vulnerabilities at three to five times the rate of manual review, the company reports. Separately, an automated red-team platform assessed 1,489 public-facing assets and found more than 100 high-severity vulnerabilities, cutting the average time from asset discovery to initial penetration testing to under 24 hours against a traditional manual cycle measured in weeks.

"The cybersecurity arms race has entered an era of minutes," said David Zong, Bybit's Head of Group Risk Control and Security. "Using AI to strengthen our security and risk-control capabilities, while securing the AI systems themselves, is our top priority, with human judgement remaining at the centre of critical security decisions."

Bybit also reports that its on-chain monitoring now covers 100% of business-relevant activity across listed token contracts and its cold, warm, and hot wallets. In ten security incidents involving listed token projects during the period, the company says it recorded zero platform losses, and in eight cases completed emergency responses before other major exchanges had acted.

Convergence implications for the wider digital-asset infrastructure stack

The Bybit report is a company self-assessment rather than an independent audit, and all figures carry that caveat. The compliance flags below reflect that. But the structural dynamics it describes carry implications beyond any single exchange.

The arms-race framing, AI accelerating attack cycles, AI required to keep pace defensively, is not unique to crypto. It is the same pressure playing out across cloud infrastructure, financial-services fraud detection, and critical national infrastructure. What distinguishes the crypto context is the absence of a systemic safety net: there is no deposit insurance, no central bank backstop, and no standardised cross-platform incident-response protocol. When Bybit notes that it has worked with law enforcement and blockchain intelligence firms to trace assets connected to the 2025 breach, and has pursued legal action against North Korea's Lazarus Group, it is pointing to a governance gap that regulators in the EU, the UK, and the US are only beginning to address under frameworks such as MiCA and the FIT21 Act.

For capital allocators assessing exposure across fintech and cybersecurity, the report signals a structural shift: security is now a first-order cost of operating at scale in digital assets, not a variable overhead. Exchanges competing on liquidity will increasingly need to compete on demonstrable security infrastructure, and independent attestation of that infrastructure, not self-reported metrics, is likely to become a licensing condition in mature regulatory markets. The vendors, auditors, and blockchain intelligence firms sitting between exchanges and regulators represent a growing and largely uncrowded capital opportunity in that context.