
Bybit says its use of artificial intelligence has helped strengthen its cybersecurity defenses, less than two years after the exchange suffered a $1.46 billion hack attributed to North Korea.
The exchange said AI-powered audits identified high-severity vulnerabilities at up to five times the rate of conventional manual reviews. The technology also cut the time required to move from assessing an asset to testing it from roughly two weeks to just two hours.
Between Jan. 1 and June 15, Bybit reported that its AI systems blocked more than 30,000 suspicious withdrawal attempts. According to the company, those interventions helped shield nearly 20,000 users from more than $700 million in potential losses. The initial assessment of a flagged transaction took an average of 4.7 minutes.
The results come after Bybit’s February 2025 security breach, when approximately $1.46 billion worth of crypto was stolen in what was described as the largest crypto theft on record. The attack was attributed to North Korea’s Lazarus Group, and Bybit is pursuing legal action against both the group and the North Korean state.
Bybit clarified that the $700 million represents losses it believes were prevented, rather than confirmed thefts. The exchange also said its AI systems identified roughly $212 million in funds associated with fraudulent activity and blacklisted more than 10,000 addresses. The company’s figures have not been independently verified.
AI Speeds Up Vulnerability Detection
Bybit’s automated red-team system examined 1,489 public-facing assets during the period and uncovered more than 100 high-severity vulnerabilities.
The company said the time between discovering an asset and conducting a security test fell to less than 24 hours. AI-assisted systems also helped process more than 100,000 security alerts.
The increased use of AI comes as crypto companies and independent developers look for faster ways to discover vulnerabilities before attackers can exploit them.
BTCPay Server, which recently faced an attack that drained merchant Lightning nodes, said AI is shifting the balance between cyber attackers and defenders. AI models can scan large codebases rapidly and at lower cost, although sophisticated attackers—particularly state-backed groups—may have access to greater financial and computing resources.
Crypto Firms Call for Better AI Tools
The crypto industry is also pushing AI companies to give cybersecurity teams greater access to advanced models.
Dozens of crypto-focused businesses, including Coinbase and Block, signed an open letter urging AI labs to provide defenders with early access to their most powerful models. They argued that security teams should not be forced to operate with less capable technology than potential attackers.
Meanwhile, the volunteer Bitcoin Red Team has been using AI models to examine Bitcoin-related software and identify security weaknesses. The group has reported thousands of potential issues across hundreds of projects, including findings that helped BTCPay fix a vulnerability.
Unlike the volunteer effort, which relies on donated computing resources and sponsored accounts, Bybit has built dedicated AI security tools internally.
The company’s results provide an early look at how AI can improve cybersecurity when deployed across a large crypto platform.
David Zong, Bybit’s head of group risk control and security, said the cybersecurity battle is increasingly being fought on a timescale of minutes.
He added that Bybit’s priority is to use AI to improve security and risk management while ensuring its own AI systems remain secure, with human judgment continuing to guide critical security decisions.






