From $1.46B Loss to $700M Saved: How AI Changed Bybit’s Defense

Bybit, the crypto exchange that suffered a $1.46 billion hack linked to North Korea, says artificial intelligence has significantly improved its ability to identify and block security threats.

The exchange reported that AI-supported audits uncovered serious vulnerabilities at up to five times the rate of manual security checks. It also reduced the time needed to move from evaluating an asset to testing it from around two weeks to just two hours.

From Jan. 1 through June 15, Bybit said its AI systems intercepted more than 30,000 suspicious withdrawal requests. The company estimates those actions prevented potential losses of more than $700 million and protected nearly 20,000 customers. The average first review of a flagged withdrawal reportedly took only 4.7 minutes.

The figures come as Bybit seeks to strengthen its defenses after the February 2025 breach in which approximately $1.46 billion was stolen. The incident, considered the largest crypto theft to date, was attributed to North Korea’s Lazarus Group. Bybit has since initiated legal proceedings against the group and the North Korean government.

The exchange noted that the $700 million figure represents potential losses avoided, rather than confirmed thefts. Its AI tools also reportedly detected around $212 million in assets connected to suspected fraud and blacklisted more than 10,000 addresses. These figures have not been independently verified.

AI Gives Bybit Faster Security Checks

Bybit’s automated red-team platform reviewed 1,489 publicly accessible assets and uncovered more than 100 high-severity vulnerabilities during the period.

The system also brought the time between identifying an asset and testing it down to less than a day. In total, AI-assisted tools processed more than 100,000 security alerts.

The development comes as the crypto industry increasingly experiments with AI-driven cybersecurity. Smaller companies, developers and security researchers are using AI models to search for weaknesses before attackers can exploit them.

BTCPay Server, which recently suffered an attack affecting merchant Lightning nodes, has said AI is changing the cybersecurity landscape by allowing both sides to search code for vulnerabilities more quickly and cheaply. State-backed attackers could have an additional advantage because of their greater financial and technical resources.

Crypto Industry Wants Stronger AI Access

The push for AI-powered security has also led major crypto companies to demand better access to advanced artificial intelligence models.

More than 20 crypto-related companies, including Coinbase and Block, signed an open letter asking AI laboratories to provide security teams with early access to their most advanced models. The companies argued that defenders should not be forced to use weaker AI systems while attackers may have access to more sophisticated technology.

Separately, the volunteer Bitcoin Red Team has been using AI to inspect Bitcoin-related codebases and identify potential weaknesses. The group has produced thousands of findings across hundreds of projects, including research that helped BTCPay address a vulnerability.

While the Bitcoin Red Team has relied on donated computing power and sponsored accounts, Bybit has developed its own AI-based security infrastructure.

That makes Bybit’s latest figures an early indication of how effective AI can be when deployed at scale by a major crypto platform.

David Zong, Bybit’s head of group risk control and security, said the cybersecurity race has entered a stage where threats and defenses can evolve within minutes.

He said Bybit intends to continue using AI to strengthen security and risk management while protecting its own AI systems, with human oversight remaining central to critical security decisions.