One Year After $1.46B Loss, Bybit Turns to AI for $700M in Savings
Bybit says artificial intelligence has helped it strengthen its security operations and prevent more than $700 million in potential losses, roughly 18 months after the exchange was hit by a $1.46 billion hack linked to North Korea.
The exchange said its AI-assisted auditing tools discovered serious vulnerabilities at up to five times the rate of manual reviews. The technology also reduced the time needed to go from assessing an asset to testing it from approximately two weeks to just two hours.
From Jan. 1 to June 15, Bybit said its AI systems stopped more than 30,000 suspicious withdrawal attempts, potentially protecting nearly 20,000 users from losses exceeding $700 million. The company said the first review of a flagged withdrawal took an average of 4.7 minutes.
Bybit’s latest disclosure comes after its February 2025 breach, when about $1.46 billion in crypto was stolen. The incident, attributed to North Korea’s Lazarus Group, remains the largest crypto theft on record. Bybit has since taken legal action against the group and the North Korean state.
The exchange emphasized that the $700 million figure refers to losses it believes were prevented, rather than confirmed theft attempts. Its AI systems also reportedly detected about $212 million in funds connected to suspected fraud and blacklisted more than 10,000 addresses. These figures have not been independently verified.
Bybit Turns to AI for Faster Threat Detection
During the period, Bybit’s automated red-team system scanned 1,489 assets accessible from the public internet and discovered more than 100 high-severity vulnerabilities.
The company said the interval between identifying an asset and testing it was reduced to under 24 hours. AI tools also helped Bybit process more than 100,000 security alerts.
The shift toward AI-driven security comes as crypto firms and independent developers increasingly use artificial intelligence to find vulnerabilities before malicious actors can exploit them.
BTCPay Server, which recently suffered an attack involving merchant Lightning nodes, said AI is changing the cybersecurity race. Powerful models can search through large codebases faster and more cheaply, although state-sponsored attackers may have access to significantly greater resources.
Crypto Companies Push for Stronger AI Access
The growing role of AI in cybersecurity has also prompted crypto companies to seek better access to advanced models.
Dozens of firms, including Coinbase and Block, recently signed an open letter asking AI laboratories to provide security teams with early access to their strongest models. The companies argued that defenders should not be left with weaker tools while attackers potentially gain access to more capable systems.
Separately, the volunteer Bitcoin Red Team has spent the month using AI models to inspect Bitcoin-related codebases and identify security weaknesses. The group has reported thousands of findings across hundreds of projects, including research that helped BTCPay address a vulnerability.
The Bitcoin Red Team relies on donated computing resources and sponsored accounts, while Bybit has developed its own AI-based security infrastructure. As a result, Bybit’s figures provide an early indication of what AI-powered security can accomplish when deployed at scale.
David Zong, Bybit’s head of group risk control and security, said the cybersecurity arms race is increasingly unfolding within minutes.
He added that Bybit is focused on using AI to improve security and risk controls while also protecting the AI systems themselves, with human oversight remaining essential for critical security decisions.
Share this content:













