RISK & SECURITY REPORT · H1 2026
Six months, told in
numbers — not promises.
Eighteen months after absorbing the largest theft in crypto history, this is what Bybit's risk and security teams rebuilt — measured, published, and open to scrutiny.
EXECUTIVE SUMMARY
One governing idea, proven three ways.
A breach anywhere in the chain — account, chain, or code — should be caught before it becomes a loss. �Bybit’s H1 security report offers the glimpse into the operating data behind this premise in the first half of 2026.
01 · USER PROTECTION
$700M+
in potential user losses intercepted; average risk-review time under 5 minutes.
02 · ON-CHAIN DEFENSE
100%
monitoring coverage of business-relevant on-chain activity; zero platform losses across 10 incidents.
03 · AI-NATIVE SECURITY
10x
faster alert response; missed-detection rate down an order of magnitude.
02
BYBIT H1 2026 SECURITY REPORT
CONTEXT
Why this report, and why now.
The threat landscape is shifting in two directions at once: user-facing scams exploiting cognitive trust, and AI compressing vulnerability-to-exploit timelines from weeks to hours. Static rules and after-the-fact response no longer cover either.
FEB 2025
$1.5B stolen
Cold wallet compromised via a third-party signing interface. Bybit covered the loss in full and stayed solvent.
H1 2026
$700M+ protected, $0 lost
100% on-chain monitoring coverage and zero platform losses from token-project attacks this half.
03
BYBIT H1 2026 SECURITY REPORT
PILLAR 01 · USER PROTECTION
Real protection requires smart systems, vigilant defenders, and cognizant users.
$700M+
in potential user losses intercepted, at an average risk-review time under 5 minutes.
% of USERS WHO ENABLED �ADVANCED SECURITY FEATURE ADOPTION
30,000+
risky withdrawal requests intercepted
~20,000
users protected from takeover cash-out
$212M
funds at fraud risk identified & blocked
10,000+
malicious addresses blacklisted
8,600+ cases
assisted for global law enforcement, across 18 categories of crime
04
BYBIT H1 2026 SECURITY REPORT
PILLAR 01 · PROACTIVE FRAUD INTERDICTION
Scams don't need to break a password — just a moment of trust.
On-chain behavior-tagging and AI-agent-driven scanning let the team identify and model new scam patterns early, before victim counts scale.
Lookalike-address impersonation
Fraudsters registered custom-readable addresses mimicking exchange names or victims' usernames, using fake "arbitrage rebate" offers to build trust.
Behavioral detection + staged blocklisting; platform risk levels fell to near zero after a hard-block rollout.
Cross-exchange wallet spoofing
Attackers registered addresses matching Bybit's official hot wallet on another chain, targeting users active across platforms.
Joint action with the affected partner exchange closed the cross-platform attack vector entirely.
Malicious contract-approval phishing
Fake airdrop emails led users to sign malicious contract approvals, letting attackers move stablecoins without ever obtaining a private key.
Real-time tagging and hard-block policy suppressed the pattern's spread.
05
BYBIT H1 2026 SECURITY REPORT
PILLAR 02 · ON-CHAIN DEFENSE
Every dollar on the platform is watched, all the time.
100%
monitoring coverage of all business-relevant on-chain activity — every listed contract, every ecosystem contract, every wallet.
All high-risk response decisions run under a Four-Eyes principle — independent dual confirmation before action.
10 incidents
token-project security events handled, zero platform losses
8 of 10
resolved ahead of other major exchanges industry-wide
2 of 10
caught before the affected project itself noticed
5 for 5
confirmed fake-deposit attacks blocked, zero funds lost
14 new patterns
previously unseen deposit-fraud transaction types discovered and archived this half
06
BYBIT H1 2026 SECURITY REPORT
PILLAR 03 · AI-NATIVE SECURITY
Attackers are moving faster with AI. So is defense.
10x
faster alert response, with missed-detection rates down by an order of magnitude versus manual-only review.
100,000+
security alerts triaged with full AI-assisted coverage
3–5x
AI deep audit achieved higher high-severity vulnerability discovery rate vs. manual audit
100+
confirmed high-severity vulnerabilities found by automated red-teaming
1,489 assets
public-facing infrastructure under continuous automated pen-testing
<24 hrs
average time from asset discovery to first penetration test — 90%+ faster than manual scheduling
07
BYBIT H1 2026 SECURITY REPORT
CLOSING
Three pillars, one direction: move the defense line earlier — identify threats before they reach scale, intercept attacks before they reach users.
Risk has no finish line, and neither does the defense that answers it. Every capability built today is both a response to known threats and a foundation for the next wave. On the risk and security front, Bybit will continue into the AI-native direction — freeing human intelligence from repetitive tasks so our people can focus on the nuanced and tough decisions, while systems handle the rest.
All figures reflect Bybit internal security, risk, and engineering operations data for the period Jan 1–Jun 15, 2026, unless otherwise noted. Not financial or investment advice.
08
BYBIT H1 2026 SECURITY REPORT