Advertisement

Bybit Credits AI for Saving $700M After Record $1.46B Hit

Bybit, the crypto exchange that lost $1.46 billion in a North Korea-linked attack, has released figures showing how artificial intelligence is being used to strengthen its security systems.

The exchange said AI-assisted audits detected high-severity vulnerabilities at as much as five times the rate of traditional manual reviews. The technology also shortened the gap between identifying a system and putting it through security testing, reducing the process from roughly two weeks to about two hours.

Between Jan. 1 and June 15, Bybit said its AI-powered systems blocked more than 30,000 suspicious withdrawal attempts. The exchange estimates that the intervention helped protect nearly 20,000 users from more than $700 million in potential losses. Bybit said the initial assessment of a flagged withdrawal took an average of 4.7 minutes.

The company’s decision to disclose these numbers comes after its massive security breach in February 2025. Around $1.46 billion was stolen in what became the largest crypto heist on record, with investigators attributing the attack to North Korea’s Lazarus Group. Bybit is now pursuing legal action against the group and the North Korean state.

Bybit stressed that its $700 million figure refers to potential losses prevented through blocked withdrawals, not confirmed theft attempts. The exchange also said its AI tools identified approximately $212 million worth of funds associated with fraudulent activity and blacklisted more than 10,000 wallet addresses. Those figures have not been independently confirmed.

Bybit Expands AI-Based Security Testing

During the period, Bybit’s automated red-team system examined 1,489 assets accessible from the public internet and identified more than 100 high-severity vulnerabilities.

The company also reduced the time between discovering an asset and testing it to less than 24 hours. More than 100,000 security alerts were additionally analyzed with the help of AI.

Bybit’s results arrive as other crypto companies and independent developers increasingly turn to AI to identify vulnerabilities before malicious actors can exploit them.

BTCPay Server, which recently experienced an attack involving merchant Lightning nodes, said AI is altering the balance between cybersecurity attackers and defenders. AI models can examine extensive codebases more quickly and cheaply, while sophisticated attackers, particularly state-sponsored groups, may have access to larger financial resources.

Crypto Firms Seek Access to Advanced AI

The growing use of AI in cybersecurity has also prompted crypto companies to call for better access to advanced models.

Dozens of crypto-focused firms, including Coinbase and Block, recently signed an open letter urging AI developers to provide defenders with early access to their most capable systems. The companies argued that security teams should not have to rely on weaker tools while attackers potentially gain access to more powerful technology.

Meanwhile, the volunteer Bitcoin Red Team has been using AI models to examine Bitcoin-related software and identify vulnerabilities. The group has reported thousands of findings across hundreds of projects, including research that contributed to a vulnerability fix at BTCPay.

The initiative operates largely through donated computing resources and sponsored accounts, while the companies behind the open letter are seeking access to AI models that may otherwise be too expensive.

Bybit’s figures offer an early example of what can be achieved when a major crypto company builds dedicated AI security tools and deploys them at scale.

David Zong, Bybit’s head of group risk control and security, said the cybersecurity race is increasingly being measured in minutes rather than days.

He added that Bybit’s priority is to use AI to improve security and risk controls while also protecting the AI systems themselves, with human judgment remaining essential for important security decisions.