Crypto exchange Bybit reported that its AI-assisted security systems helped prevent more than $700 million in potential losses between January and mid-June, roughly one year after suffering a record-breaking $1.46 billion hack attributed to North Korea's state-sponsored Lazarus Group. The company shared metrics showing its automated systems scanned nearly 1,500 public-facing assets, processed over 100,000 security alerts, and blocked more than 30,000 suspicious withdrawal requests during the period.

Market Context

The disclosure comes amid heightened scrutiny of cybersecurity practices across centralized crypto platforms following a wave of high-profile exploits. Bybit's February 2025 hack remains the largest single theft in cryptocurrency history, surpassing previous records by a significant margin and raising questions about security protocols at major exchanges. The incident triggered broader industry discussions about defensive capabilities and prompted calls from dozens of firms for greater access to advanced AI security tools.

Analysis

Bybit's report represents the first detailed quantitative assessment from a major centralized exchange detailing specific returns on AI security investments following a catastrophic breach. According to the company, its AI systems identified high-severity vulnerabilities at rates up to five times higher than manual review processes. The time between discovering an asset and initiating testing fell from approximately two weeks to under 24 hours, with critical reviews of flagged withdrawals averaging 4.7 minutes per incident.

The exchange also reported flagging approximately $212 million in funds linked to fraudulent activity and blacklisting more than 10,000 addresses associated with suspicious transactions. David Zong, Bybit's head of group risk control and security, framed the metrics as evidence of a broader shift in defensive capabilities: 'The cybersecurity arms race has entered an era of minutes,' he said in a statement. 'Using AI to strengthen our security and risk-control capabilities, while securing the AI systems themselves, is our top priority, with human judgment remaining at the center of critical security decisions.'

The company noted it is pursuing legal action against North Korea and the Lazarus Group over the 2025 theft. The claims regarding AI effectiveness cannot be independently verified by outside parties.

Key Numbers

- $700 million in potential losses prevented between January 1 and June 15, 2026

- 30,000+ suspicious withdrawal requests blocked during the period

- Nearly 20,000 users protected from fraudulent attempts

- 1,489 public-facing assets scanned by automated systems

- 100+ high-severity vulnerabilities identified with AI assistance

- $212 million in funds flagged as linked to fraud

- Average review time of 4.7 minutes per flagged withdrawal

- Testing timeline reduced from two weeks to under two hours for initial assessment

What to Watch

Market participants should monitor whether other major exchanges publish similar metrics on AI security effectiveness, which could establish industry benchmarks for post-breach recovery investments. The ongoing legal proceedings against the Lazarus Group and North Korea will be closely watched for any asset recovery progress. Additionally, upcoming regulatory discussions around mandatory cybersecurity disclosures at crypto platforms could be influenced by Bybit's willingness to share operational data.

The broader industry response to calls from firms like Coinbase and Block requesting early access to frontier AI models from major labs may reshape competitive dynamics in the security arms race between defenders and state-sponsored attackers.