Is Bybit Safe? The 2026 Security Review No One Else Will Write
Last updated: April 2026 | Estimated reading time: 59 minutes
Introduction
Is Bybit safe? That single question is searched tens of thousands of times every month — and for good reason. In February 2025, Bybit suffered the largest cryptocurrency theft in history, losing $1.5 billion to North Korea’s Lazarus Group in a single attack. Anyone considering opening an account or depositing money on Bybit deserves a complete, honest answer to that question — not a promotional summary that buries the uncomfortable parts in fine print.
This review gives you that answer. We cover the hack in full technical detail, Bybit’s regulatory status across every major jurisdiction, its security architecture in plain language, its real user reviews including the complaints the exchange would rather you did not read, how it compares to its closest competitors on every safety dimension that actually matters, and the specific steps you need to take to protect yourself if you decide to use it.
The short answer is yes — Bybit is safe for active trading in 2026, with specific conditions. The long answer takes everything below to explain properly.
Before you read further: if you want to run an independent on-chain safety check on Bybit right now, use our free Trust Engine. It cross-references exchanges and tokens against six live layers of security data in under 60 seconds, free, with no sign-up required.
Disclosure: This review contains affiliate links to Bybit. Cryptosmap may earn a commission if you sign up through our referral code. This never affects our ratings, editorial conclusions, or which risks we choose to highlight. We are a crypto protection platform first. If we believed Bybit was unsafe, this article would say so plainly.
Who Is Bybit and Why Does Safety Matter More Here Than Anywhere Else?
Bybit was founded in 2018 by Ben Zhou, a former executive at XM Group, a global financial services company. It launched as a derivatives-first platform — specifically targeting perpetual contract traders who needed faster execution speeds and lower fees than the dominant exchanges of the time could offer. Its matching engine, built to handle 100,000 transactions per second, became its primary technical differentiator.
By April 2026, Bybit has grown into the world’s second-largest cryptocurrency exchange by trading volume, according to data from both CoinMarketCap and CoinGecko. It serves over 80 million registered users across 160 countries. It relocated its global headquarters from Singapore to Dubai in 2022 and established a European headquarters in Vienna, Austria, following the receipt of its MiCA licence in May 2025.
The reason safety matters more here than at almost any other major exchange is scale combined with history. Bybit is big enough that its failure would affect tens of millions of people. And its 2025 hack — the largest in crypto history — means that the question of whether it is safe is not theoretical. It has been tested under the most extreme real-world conditions imaginable. That test result is the most valuable data point in this entire review.
Section 1: The $1.5 Billion Hack — The Full Technical Story
There is no responsible way to answer “is Bybit safe?” without starting here. On 21 February 2025, approximately $1.5 billion worth of Ethereum was stolen from Bybit in what became the single largest cryptocurrency theft ever recorded, surpassing the previous record by more than double.
How the Attack Was Executed
The Bybit hack was not a conventional cyberattack on the exchange’s own systems. It was a sophisticated supply chain attack — meaning the attackers did not target Bybit directly but instead compromised a third-party platform that Bybit depended on, then used that access to manipulate Bybit’s internal processes.
Bybit used Safe{Wallet}, a third-party multi-signature wallet management platform, to conduct internal fund transfers between its cold wallet (offline, long-term storage) and its warm wallet (online, used for active operations). Multi-signature schemes require multiple authorised parties to jointly approve any transaction — a security measure designed specifically to prevent any single compromised key from enabling unauthorised transfers.
Weeks before the theft, the North Korean Lazarus Group — a state-sponsored hacking unit operating under the DPRK’s Reconnaissance General Bureau — had compromised a developer’s workstation at Safe{Wallet} using a social engineering attack. By gaining access to AWS session tokens, they infiltrated Safe{Wallet}’s cloud infrastructure without triggering multi-factor authentication alerts, because they were using stolen tokens rather than attempting to authenticate from scratch.
Once inside Safe{Wallet}’s systems, the attackers replaced the legitimate JavaScript code in the wallet’s user interface with malicious code designed to silently alter the destination address of any transaction while displaying the correct, expected address to the person approving it. This meant that when Bybit’s authorised signatories reviewed and approved what appeared to be a standard routine transfer, the transaction they were actually signing redirected funds to wallets controlled by Lazarus Group operatives.
The test run came at 14:15 UTC on 21 February 2025 — a transfer of 90 USDT used to confirm the injection was working correctly. Sixty seconds later, the full transfer of approximately 401,000 ETH — worth $1.5 billion at the time — began. It was complete in minutes.
The theft was attributed to Lazarus Group within 48 hours by blockchain analytics firms Chainalysis and Elliptic, and subsequently confirmed by the FBI. The stolen funds were dispersed across more than 50 different wallets and laundered through a complex web of decentralised exchanges, cross-chain bridges, and no-KYC instant swap services. German law enforcement seized approximately €34 million from eXch, a cryptocurrency swap service used to launder a portion of the stolen funds, in May 2025. As of early 2026, approximately $644 million of the stolen assets remains untraceable.
What Happened to User Funds — The Part That Matters Most
Every single Bybit user was made whole. No customer lost a penny. This is the most important sentence in this review, and it deserves to be stated without qualification before any other detail.
Within two hours of the theft, CEO Ben Zhou appeared on a live stream to confirm the breach publicly, explain what had happened, commit to covering all losses, and confirm that all other cold wallets were unaffected. He stated clearly that withdrawals would remain open. He delivered on every promise.
Within 72 hours, Bybit had fully replenished its reserves through a combination of emergency bridge loans and large institutional deposits from partners including Galaxy Digital, FalconX, and Wintermute — assembling approximately 447,000 ETH to replace what had been stolen. A proof-of-reserves audit conducted by cybersecurity firm Hacken on 24 February 2025 — just three days after the theft — confirmed that all major assets including Bitcoin, Ethereum, Solana, USDT, and USDC exceeded a 100% collateralisation ratio. Withdrawals were never suspended at any point.
Bybit additionally launched a 10% recovery bounty programme — offering up to $140 million for information leading to asset recovery. It paid out $2.3 million in bounties to 13 individuals and organisations who assisted in tracing and flagging stolen funds, including blockchain investigator ZachXBT and analytics firm BitJungle.
What the Hack Tells Us — and What It Does Not
The hack tells us that even an exchange with sophisticated security infrastructure can be compromised by a nation-state-level attacker who targets a third-party dependency rather than the exchange itself. Cold storage, multi-signature requirements, and offline key management are all meaningful protections — they cannot fully defend against an attacker who has compromised the software used to construct and display transactions for signing. This is a systemic risk across the entire crypto industry, not a flaw unique to Bybit.
What the hack also tells us — more powerfully — is how an exchange behaves when things go catastrophically wrong. The benchmarks that matter most in a crisis are: did the exchange communicate honestly and immediately? Did it keep withdrawals open? Did it have sufficient reserves to absorb the loss? Did it make users whole? On all four counts, Bybit’s answer in February 2025 was yes.
Compare this to FTX, which transferred user funds to a sister trading firm without disclosure and suspended withdrawals before collapsing. Or Celsius, which marketed itself as safe while secretly using user deposits for leveraged trading. Or Voyager, which froze accounts and filed for bankruptcy. Bybit absorbed a $1.5 billion theft and continued operating without interrupting a single user’s access to their funds. That track record is the most meaningful safety signal available for any centralised exchange.
Section 2: Bybit’s Security Architecture in 2026
Following the February 2025 incident, Bybit made significant enhancements to its security infrastructure. Here is a complete, plain-language breakdown of the protections in place today — both at the platform level and the account level.
Platform-Level Security
Cold wallet storage with enhanced transfer verification
The majority of user assets are held in offline cold wallets — storage physically disconnected from the internet and inaccessible to remote attackers. Following the 2025 hack, Bybit significantly upgraded its internal transfer verification protocols. Any movement of funds between cold and warm wallets now requires additional layers of independent transaction verification, going beyond the standard multi-signature process that was exploited through Safe{Wallet}’s compromised interface.
Trusted Execution Environment (TEE)
Bybit employs a Trusted Execution Environment — a secure, isolated processing enclave built directly into the processor chip. Sensitive operations such as key management and transaction signing occur inside this enclave, which is hardware-separated from the rest of the operating system. Even if the operating system itself is compromised, operations inside the TEE remain isolated and protected. This is the same class of technology used in secure payment processing and government identity systems.
Threshold Signature Schemes (TSS)
Bybit uses Threshold Signature Schemes for its custody infrastructure, splitting private wallet keys across multiple independent parties. A minimum number — the threshold — of those parties must cooperate before any transaction can be authorised. No single party, system, or compromised key can unilaterally move funds. This eliminates the single-point-of-failure risk inherent in traditional private key management and significantly raises the bar for any attacker attempting to authorise unauthorised transfers.
Real-time monitoring and AI-powered fraud detection
Bybit’s risk monitoring systems operate continuously, analysing patterns in logins, trades, and withdrawal requests in real time. Unusual behaviour — a new device logging in from an unrecognised location, a withdrawal request that deviates significantly from a user’s typical pattern, an account performing trades inconsistent with its history — triggers additional verification requirements before the action proceeds. In 2026, this system incorporates AI-powered anomaly detection that flags sophisticated attack patterns that rule-based systems alone would miss.
Monthly Proof of Reserves audited by Hacken
Since June 2024, Bybit has published monthly Merkle-tree proof-of-reserves reports, independently verified by Hacken. The Merkle-tree methodology is important because it allows any individual user to independently verify that their own specific account balance is included in the published reserve total — not just trust a headline number from the exchange. Users can perform this verification directly inside their Bybit account under Account → Proof of Reserves, using the Merkle inclusion checker, and the process takes approximately two minutes.
As of the most recently published report in April 2026, all major assets are held above 100% collateralisation. Bitcoin reserves are held at over 100% of user liabilities. Ethereum, USDT, USDC, Solana, and XRP all exceed 100% coverage. This means Bybit holds more of each asset than the total amount owed to users — providing a buffer against market volatility and liquidity pressure.
The fact that this audit system was in place before the 2025 hack — and that the post-hack audit on 24 February 2025 confirmed reserves remained above 100% — is significant. It was not implemented as damage control. It reflects a pre-existing commitment to transparency that proved critical in maintaining user confidence during the crisis.
Bug bounty programme
Bybit maintains an active bug bounty programme that pays ethical security researchers to find and responsibly disclose vulnerabilities. This is standard practice among mature exchanges and contributes to ongoing security improvement by engaging a global community of researchers looking for problems that internal teams might miss.
Insurance fund for leveraged trading
Bybit maintains a dedicated insurance fund used specifically to cover losses during leveraged trading liquidations — situations where a trader’s position moves against them faster than the liquidation engine can close it, leaving a shortfall. This fund is not a comprehensive insurance policy covering all user losses against all possible scenarios. It provides a targeted buffer for the most common category of platform-side trading loss on derivatives exchanges.
Account-Level Security: The Settings You Must Enable
Platform-level protections are Bybit’s job. What follows is your job — the account security features available to every user that, when enabled, protect against the most common real-world attacks targeting individual exchange accounts.
Two-factor authentication (2FA)
Enable 2FA before depositing anything. Without it, a compromised email account or password is sufficient to access and drain your exchange account. Bybit supports three 2FA methods, listed here from most to least secure:
Hardware security keys (FIDO/passkeys): The most secure option. Authentication is tied to a physical device using biometrics and cannot be phished, because the key never leaves your device and the cryptographic response is bound to the specific website’s domain. Even if an attacker tricks you into visiting a fake Bybit site, a hardware key authentication will fail there. This option is free and available to all Bybit users.
Authenticator apps (Google Authenticator, Authy): Strongly recommended. Generates a 6-digit code that rotates every 30 seconds. Significantly more secure than SMS because it requires physical access to the device the app is installed on, and is not vulnerable to SIM-swap attacks.
SMS (text message): The least secure option. SIM-swap attacks — where an attacker convinces your mobile carrier to transfer your number to a SIM card they control — are common in the crypto space and can be executed without physical access to your phone. If SMS is your only option, it is still better than nothing, but upgrade to an authenticator app as soon as possible.
To enable: Profile icon → Account & Security → Two-Factor Authentication → select your preferred method.
Anti-phishing code
Set a personal anti-phishing code — a short unique string of your own choosing that appears in every genuine email Bybit sends to you. If you receive an email claiming to be from Bybit that does not contain your personal code, it is a phishing attempt. Full stop.
This single feature neutralises the vast majority of email-based social engineering attacks targeting Bybit users. Active phishing campaigns impersonating Bybit — including fake “security alert” emails, fake “withdrawal confirmation” emails, and fake “KYC update required” emails — are tracked in real time on our Scam & Rug Pull Alerts page.
To enable: Profile icon → Account & Security → Anti-Phishing Code → Create.
Withdrawal address whitelisting
This is the single most powerful account-security feature available on Bybit, and it is significantly underused. Enabling the withdrawal whitelist restricts your account so that funds can only be withdrawn to wallet addresses you have pre-approved. Any attempt to add a new withdrawal address triggers a mandatory 24-hour security delay plus multi-factor confirmation before the address becomes active.
The practical implication: even if an attacker gains complete access to your account — your login credentials, your 2FA code, your email — they cannot withdraw your funds to their own wallet without waiting 24 hours, during which Bybit alerts you and you can revoke the attempt. This single feature prevents the most common form of exchange account compromise that results in user losses.
To enable: Profile icon → Account & Security → Withdrawal Address Whitelist → Enable.
Fund password
A separate password used exclusively for withdrawals and high-risk trading actions — completely distinct from your login password. Even if your main account password is compromised, the fund password provides an independent barrier to asset movement.
To enable: Profile icon → Account & Security → Fund Password → Create.
Passkeys (FIDO2)
Bybit supports modern FIDO2-based passkeys that tie authentication to a physical device using your device’s built-in biometrics (fingerprint or face recognition). Passkeys are phishing-resistant by design — the cryptographic handshake is bound to the exact domain of the site you are authenticating with, so a fake Bybit site cannot capture or replay your authentication. Most modern smartphones and laptops support this natively, and it is free to enable.
To enable: Profile icon → Account & Security → Passkey Management → Add Passkey.
Secure Transaction Approval
Bybit allows you to designate a primary device — typically your phone — that must explicitly confirm any high-risk action (large withdrawals, new device logins, significant trades) before it can proceed. This creates a physical device requirement for your most sensitive account actions, even if your credentials are otherwise compromised.
To enable: Profile icon → Account & Security → Secure Transaction Approval → Enable.
Device and session management
Review your active sessions regularly. Profile icon → Account & Security → Session Management shows every device currently logged into your account, its approximate location, and its last activity. Any session you do not recognise should be revoked immediately. If you find an unrecognised session, change your password, review your withdrawal whitelist, and check for any pending withdrawal requests before anything else.
Section 3: Bybit’s Regulatory Status — The Complete 2026 Picture
Regulation is the most frequently misrepresented aspect of Bybit’s safety profile. Some reviewers overstate it, presenting Bybit as broadly regulated when it lacks licences in major markets. Others understate it, dismissing Bybit as “unregulated” when it holds meaningful licences in several jurisdictions. Here is the accurate, complete picture.
Where Bybit Holds Active Regulation
European Union and EEA — MiCA Licence (Austria’s FMA)
This is Bybit’s most significant regulatory achievement of 2025. Bybit EU GmbH received a full Markets in Crypto-Assets Regulation (MiCAR) licence from Austria’s Financial Market Authority (FMA) in May 2025. The licence was confirmed on the FMA’s public register and reported by CoinDesk and Cointelegraph. It allows Bybit EU to offer regulated crypto-asset services across all 29 European Economic Area countries through MiCA’s passporting mechanism — meaning a single licence in Austria covers the entire bloc.
MiCA is one of the most comprehensive crypto regulatory frameworks in the world. For a licence to be granted, an exchange must demonstrate client asset segregation from company funds, robust AML/KYC programmes, cybersecurity standards, reserve adequacy, and consumer protection procedures. EU users now have access to formal legal recourse through Austrian courts and can file complaints with Austria’s FMA — protections that are simply absent when using unlicensed exchanges.
Bybit has established its European headquarters in Vienna, Austria, with plans to hire over 100 professionals there to support its EU operations and compliance obligations. It was among the first major global exchanges to receive MiCA authorisation, positioning itself ahead of many competitors who are still seeking EU regulatory approval.
United Arab Emirates — UAE Securities and Commodities Authority (SCA)
Bybit holds a Virtual Asset Platform Operator licence from the UAE’s federal Securities and Commodities Authority, covering its primary global operations from its Dubai headquarters. Bybit is also pursuing full operational authorisation from Dubai’s VARA (Virtual Assets Regulatory Authority) at the emirate level, with provisional approvals already achieved.
Kazakhstan — Astana Financial Services Authority (AFSA)
Bybit Kazakhstan operates under AFSA regulation within Kazakhstan’s Astana International Financial Centre, under licence AFSA-A-LA-2024-0027 covering regulated digital asset trading and custody activities.
Georgia — National Bank of Georgia
Bybit obtained VASP (Virtual Asset Service Provider) registration from the National Bank of Georgia in November 2024.
Cyprus — CySEC / EEA CASP Register
UAB Onlychain Fintech Limited, operating under the Bybit trade name, is listed on the EEA’s CASP register under CySEC oversight, providing an additional layer of EU-level regulatory standing.
Where Bybit Is Not Regulated — And Why That Matters
United Kingdom
Bybit does not hold Financial Conduct Authority (FCA) registration and is not available to UK residents. The UK’s crypto regulatory regime operates independently from the EU’s MiCA framework and requires its own separate registration process. Bybit has not pursued FCA registration. UK residents looking for a regulated alternative should consider Kraken, which holds FCA registration, or Coinbase, which operates a UK entity.
United States
Bybit does not operate in the US market. US residents are blocked at the KYC stage. To legally serve US users, a crypto exchange must register with FinCEN as a Money Services Business and obtain money transmitter licences in most states — a complex and expensive process that Bybit has chosen not to pursue. US residents should use Coinbase, Kraken, or Gemini, all of which are fully licensed for US operations.
Canada
Bybit has exited major Canadian provinces including Ontario and Quebec due to regulatory requirements from the Ontario Securities Commission and Canadian securities regulators.
France
Although Bybit was removed from the French AMF’s blacklist in February 2025 after a remediation process, it suspended services to French users in January 2025 and had not resumed operations as of the time of writing. French users within the EEA can theoretically access Bybit EU under the MiCA passporting mechanism, but should verify current availability directly.
What Regulatory Status Means Practically for You
If you are in the EU/EEA and using bybit.eu, you have formal regulatory protections: asset segregation requirements, dispute resolution access, and the ability to complain to Austria’s FMA. If you are in the UAE or Kazakhstan, you have jurisdiction-specific regulatory protections.
If you are in most of the 160 countries where Bybit operates outside these regulated jurisdictions — including large parts of Africa, Asia, Latin America, and the Middle East — you are using Bybit without local regulatory protection. In practice, this means your contractual relationship is governed by Bybit’s terms of service, interpreted under British Virgin Islands law (where the parent company is incorporated). This does not make Bybit unsafe in those regions, but it does mean your legal recourse in a dispute is limited. This is the most significant regulatory limitation of using Bybit and should be weighed realistically.
Section 4: Real User Reviews — What Bybit’s Customers Actually Say
Most exchange reviews quote the platform’s own statistics and positive testimonials. This section does something different: it examines what Bybit’s real users report in 2026, including the negative experiences the exchange would prefer not to highlight. Understanding both the strengths and the failure modes helps you make an informed decision.
App Store Ratings — Where Bybit Scores Well
Bybit’s mobile app performance tells a notably different story from its web platform reviews. On Google Play, the Bybit app holds a 4.5 out of 5 rating based on over 1.3 million reviews. On Apple’s App Store, it scores 4.7 out of 5 from over 41,000 reviews. These are strong numbers for a financial app. Users consistently praise the speed and responsiveness of the interface, the quality of TradingView charting integration, the copy trading module, and the overall range of features available on mobile.
The mobile experience is genuinely well-executed. Navigation is intuitive, the bottom menu bar provides familiar app-style navigation, features load quickly, and the order execution interface is clean. For active traders who primarily use their phone, Bybit’s mobile app is among the best in the industry.
Trustpilot Reviews — Where Bybit Struggles
The picture changes significantly on Trustpilot, where Bybit averages approximately 3.4 out of 5 from over 7,000 reviews. The divergence from its app store ratings is not accidental — people who have a trading experience tend to rate apps; people who have a compliance or support problem tend to go to Trustpilot.
The most common complaint categories, drawn from current Trustpilot reviews, are:
Account and withdrawal freezes due to compliance reviews
This is by far the most frequently reported problem in 2026. A significant number of users report having their accounts restricted or their withdrawals blocked following transactions that Bybit’s compliance system flags as requiring review. Some of these are resolved relatively quickly. Others drag on for weeks or months, with users reporting that they submitted the requested documents repeatedly, received automated responses, were given multiple extension deadlines, and ultimately had no access to their funds for extended periods.
One user reported having 2.427 ETH held in a compliance review since October 2025, with no substantive response after escalation requests. Another reported $25,102 USDT frozen for over 30 days with no clear explanation. A third reported being asked to wait until May 2026 for resolution of a review that began in March — without any legal justification provided.
It is important to provide context for these complaints. Compliance reviews on crypto exchanges are required by law in most jurisdictions. The MiCA framework Bybit operates under in the EU specifically mandates enhanced due diligence for transactions that trigger AML (anti-money laundering) risk thresholds. Some of the reviewed transactions likely involve funds that have touched mixing services, flagged addresses, or other on-chain patterns that compliance systems are required to scrutinise. Not every account restriction is arbitrary — many are regulatory obligations that Bybit cannot legally bypass regardless of user frustration.
That said, the recurring pattern of users reporting that identical documents were requested multiple times, automated responses replaced substantive engagement, and resolution timelines were repeatedly extended without clear communication, suggests that Bybit’s compliance support infrastructure is not scaling well with its user base. This is a genuine weakness and one that users with significant funds on the platform should factor into their decision.
Customer support response quality for complex issues
Bybit’s live chat handles routine queries reasonably quickly — response times of 5 minutes or less are commonly reported for standard questions. The problem arises with complex cases: account restrictions, compliance reviews, P2P disputes, and withdrawal failures that cannot be resolved in a standard live chat session are escalated to email tickets, where response times can stretch to 5–7 days or longer. Users in active compliance reviews describe receiving identical automated responses for weeks without substantive human engagement.
Bybit EU’s Trustpilot profile shows similar patterns, with additional complexity arising from the transition of European users from bybit.com accounts to the new bybit.eu entity, which some users have reported created new friction and unresolved cases.
Bybit Card issues
Multiple users report problems with the Bybit Card — the exchange’s crypto debit card available in supported regions. Issues include cashback calculation disputes (one EU user documented a systematic 14–16% discrepancy between EUR cashback amounts confirmed by email and USDC amounts actually credited), card transaction failures despite funded balances, and difficulty resolving card-related support cases. These are product-specific rather than security issues, but they represent a customer experience failure that damages trust.
P2P trading disputes
P2P trading complaints are common across all major exchanges that offer the feature. On Bybit, users report cases where payments were made but coins were not released, disputes were not resolved within stated timeframes, and support in P2P dispute cases was slow to engage substantively.
Balancing the Picture
It would be misleading to present these complaints as representative of the average Bybit user experience. Over 80 million registered users means that even a small percentage of problematic experiences represents a large absolute number of complaints. The majority of Bybit users — those who trade actively without triggering compliance flags, who do not have complex support needs, and who use the platform’s security features correctly — report positive experiences.
The complaints matter because they reveal specific risk categories: if you deposit large amounts and your transaction history includes on-chain patterns that could trigger AML flags (transactions touching decentralised mixers, cross-chain bridges, or flagged addresses), you face a real risk of extended compliance review that may delay access to your funds. If you rely on Bybit Card cashback as part of your financial planning, the product has documented inconsistencies that have not been fully resolved. If you encounter a P2P dispute, resolution can be slow.
These are not security risks in the traditional sense — your funds are not at risk of being stolen by Bybit. But they are real operational risks that a comprehensive safety review must address honestly.
Section 5: Bybit vs Competitors — A Safety Comparison
Evaluating whether Bybit is safe requires comparing it against the realistic alternatives. Here is how Bybit compares to its main competitors across the dimensions that matter most for safety.
The Core Safety Comparison
| Safety dimension | Bybit | Binance | Coinbase | Kraken | Gate.io |
|---|---|---|---|---|---|
| Proof of Reserves | Monthly, Hacken-audited | Monthly | Public company | Monthly | Monthly |
| Cold storage | Yes, majority of assets | Yes | Yes | Yes | Yes |
| TEE / TSS custody tech | Yes | Partial | No (disclosed) | No (disclosed) | No |
| MiCA licence (EU) | Yes — Austria FMA | In progress | No | Yes — Ireland | No |
| FCA regulated (UK) | No | No (suspended) | No | Yes | No |
| FinCEN / US licensed | No | Binance.US only | Yes | Yes | No |
| Hack history | $1.5B (2025) — users protected | Multiple incidents | Data breach (2021) | None major | $234M (2018) |
| Withdrawal suspension history | Never | Multiple incidents | Never | Never | Never |
| Hardware key 2FA | Yes — FIDO2 | No | Yes | Yes | No |
| Withdrawal whitelisting | Yes | Yes | Yes | Yes | Yes |
| Anti-phishing code | Yes | Yes | No | No | Yes |
| Trustpilot rating (approx.) | 3.4 / 5 | 2.1 / 5 | 1.9 / 5 | 3.6 / 5 | 2.8 / 5 |
Several observations from this table deserve specific comment.
On withdrawal suspensions: This is the single most important row. FTX, Celsius, Voyager, and BlockFi all suspended withdrawals before their collapses, and users lost funds in every case. Bybit has never suspended withdrawals — including during a $1.5 billion theft. Binance has had multiple withdrawal suspension incidents on specific assets during periods of high volatility. Coinbase and Kraken, like Bybit, have never suspended general withdrawals. Gate.io suspended some asset withdrawals during its 2018 security incident.
On Trustpilot ratings: Every major crypto exchange has a poor Trustpilot score because the platform disproportionately captures complaints. Kraken’s 3.6 is the highest among major exchanges. Bybit’s 3.4 is reasonable in context. Binance and Coinbase score far worse — Coinbase’s 1.9 rating reflects the enormous scale of user complaints about account lockouts, support responsiveness, and KYC disputes that are characteristic of US-regulated entities operating under stricter compliance regimes.
On regulation: Coinbase is the most regulated exchange in this comparison, as a publicly listed US company subject to SEC oversight, FINRA rules, and state money transmitter licences. This regulatory clarity is its most significant safety advantage. Kraken holds both FCA (UK) and FinCEN (US) registration alongside MiCA in Ireland, making it the most broadly regulated of the non-US-specific exchanges. Bybit’s MiCA licence is meaningful but narrower in geographic coverage than Kraken’s regulatory profile.
On custody technology: Bybit’s TEE and TSS implementation is more advanced than what most competitors publicly disclose. Most major exchanges use some form of multi-signature cold storage but do not specify whether they employ TEE-protected signing or threshold signature schemes. This does not mean Bybit is necessarily more secure in practice — implementation matters as much as technology choices — but it suggests a more sophisticated approach to custody architecture than the industry default.
Bybit vs Gate.io
Gate.io is the other exchange in Cryptosmap’s current affiliate portfolio, and readers comparing the two deserve an honest assessment. Gate.io offers a significantly larger asset selection — over 3,800 cryptocurrencies versus Bybit’s 700+ — making it the superior choice for users specifically seeking small-cap altcoin exposure or early access to newly listed tokens. Gate.io holds a security rating of AA (88/100) from CER.live, an independent security rating agency, and publishes monthly proof of reserves.
Gate.io suffered a $234 million hack in 2018 — before the current management team significantly upgraded its security infrastructure. Since then, it has not suffered a comparable incident. Its spot trading fees are slightly higher than Bybit’s (0.20% versus 0.10% at the base level). It lacks the FCA, FinCEN, and MiCA regulatory coverage that Bybit has achieved, operating without major Western regulatory licences.
For users who want deep altcoin access, Gate.io is a reasonable choice alongside appropriate security practices. For users who prioritise low fees, derivatives depth, copy trading, and regulatory coverage, Bybit is the stronger option. Our Market Insights section includes detailed head-to-head comparisons of both exchanges.
Section 6: The Hardware Wallet Question — How Much Should You Keep on Bybit?
One of the most important safety questions for any exchange user is not whether the exchange itself is safe — it is how much of your crypto should live there at all.
The fundamental principle of crypto security can be summarised in a sentence that has remained true since Bitcoin’s creation: not your keys, not your coins. Any cryptocurrency held on a centralised exchange is custodied by that exchange. You do not hold the private keys. In the event of an exchange failure, hack, or regulatory action, your access to those funds depends entirely on the exchange’s solvency, integrity, and legal compliance.
This does not mean exchanges are never appropriate for holding crypto. For active traders who need to move funds quickly between pairs, hold collateral for leveraged positions, or use copy trading features, keeping a working balance on an exchange is both necessary and reasonable. But long-term holdings — funds you are not actively trading with and do not need immediate access to — belong in a self-custody wallet where you control the private keys.
The 80/20 Approach
The approach used by professional crypto security practitioners in 2026 is a version of the following framework:
Keep 80–90% of total holdings in cold storage — a hardware wallet like a Ledger or Trezor — where the private keys never touch an internet-connected device. These are your savings. You do not need to access them frequently, and the small inconvenience of retrieving funds from cold storage is trivial compared to the security benefit.
Keep 10–20% on exchanges like Bybit for active trading purposes. This is your working capital. It should represent an amount whose temporary loss or restriction — through a compliance review, technical problem, or in the worst case, an exchange failure — would not constitute a financial catastrophe for you.
Test your hardware wallet setup before trusting it with significant funds. Send a small amount, verify it arrived, and verify you can recover it using your seed phrase backup before moving larger amounts. Our guide to hardware wallets and self-custody walks through this process step by step for complete beginners.
The Seed Phrase — The One Thing You Cannot Get Wrong
Whether you are using a hardware wallet or any other form of self-custody, the security of your funds ultimately comes down to your seed phrase — a 12 or 24 word recovery sequence generated when you first set up the wallet. The seed phrase is the master key to your funds. Anyone who has it can restore your wallet on any device and access everything in it.
The seed phrase must be written on paper (or stamped into metal for fire and water resistance) and stored in a physically secure location — never photographed, never typed into any device, never stored in cloud storage or email, and never shared with anyone under any circumstances. If you lose your seed phrase and your hardware wallet is damaged or lost, your funds are permanently inaccessible to everyone including you. If someone else obtains your seed phrase, your funds are immediately theirs to take.
This is the trade-off of self-custody: you take on the responsibility that the exchange currently carries for you. Most people who understand crypto security consider this a worthwhile trade for holdings above a threshold that would genuinely hurt them to lose.
Section 7: The Cryptosmap Safety Verdict
Overall safety rating: 7.5 / 10
The Positive Case
Bybit has passed the most important safety test available to a centralised exchange — a real, catastrophic loss event. In February 2025, $1.5 billion was stolen from its infrastructure by the most sophisticated state-sponsored hacking group in the world. Every user was made whole. Withdrawals were never suspended. Reserves were independently verified within 72 hours. The CEO communicated publicly within two hours of the breach. That record of behaviour under extreme adversity is the most meaningful evidence of trustworthiness available.
Beyond the crisis response, Bybit’s security architecture in 2026 is genuinely advanced. Monthly proof of reserves verified by Hacken, TEE and TSS custody technology, FIDO2 passkey support, withdrawal address whitelisting, anti-phishing codes, and real-time AI-powered monitoring represent a comprehensive multi-layer approach. Its MiCA licence gives EU users formal regulatory protections. Its fee structure is competitive and transparent.
The Concerns
The compliance-driven account restriction problem is real and affects a meaningful number of users. If your transaction history includes on-chain patterns that trigger AML systems — interactions with decentralised exchanges, cross-chain bridges, or peer-to-peer platforms — you face a material risk of extended compliance reviews that may delay access to funds for weeks or months. This is not theft, but it is an operational risk that anyone holding significant balances on Bybit needs to understand.
Customer support quality for complex cases falls below what a platform serving 80 million users should be able to deliver. The pattern of automated responses replacing substantive engagement on compliance review cases is documented extensively in current user reviews and represents a service quality problem that does not match the platform’s technical sophistication.
Bybit’s absence of FCA and FinCEN regulation means that UK and US users either cannot use the platform or must accept operating outside locally regulated frameworks. The parent company’s British Virgin Islands incorporation means that non-EU users outside Bybit’s regulated jurisdictions have limited formal legal recourse in disputes.
The third-party supply chain risk that enabled the 2025 hack has not been fully eliminated — it has been mitigated through enhanced verification protocols, but any exchange that depends on third-party infrastructure for any part of its custody process carries some version of this risk. No exchange can claim complete immunity.
Who Bybit Is Appropriate For
Bybit is appropriate for active traders outside restricted jurisdictions who want low fees, deep derivatives liquidity, copy trading, and a platform that has demonstrated it will protect user funds during a crisis. EU/EEA users who use bybit.eu benefit from MiCA regulatory protections that make Bybit a genuinely regulated option for the European market.
Bybit is not appropriate for US or UK residents, for users who plan to hold large long-term positions on the exchange rather than in self-custody, or for users whose on-chain transaction history may trigger compliance reviews and who cannot afford restricted access to funds.
Section 8: How to Maximise Your Safety if You Use Bybit
Everything in this section applies whether you use Bybit or any other major exchange. These practices eliminate the majority of real-world risk to individual exchange users.
The Pre-Deposit Checklist
Before depositing any meaningful amount on Bybit, work through this checklist completely. Every item takes between two and ten minutes.
Enable two-factor authentication using an authenticator app or hardware key. Do not use SMS if you can avoid it. Do this before you deposit anything.
Create your anti-phishing code. Go to Account & Security → Anti-Phishing Code. Choose a unique word or phrase that you will remember and that is not used anywhere else in your online life.
Enable withdrawal address whitelisting. Add your personal hardware wallet address to the whitelist immediately. This ensures that if your account is ever compromised, funds cannot be withdrawn to an attacker’s address without a 24-hour delay that alerts you.
Set a fund password. This is your withdrawal-specific password — separate from your login password, known only to you.
Do a small test withdrawal. Before depositing significant funds, send a small amount to your personal wallet, confirm it arrives on the correct network, and confirm the withdrawal process works as expected. This takes ten minutes and confirms the entire chain works before it matters.
Check your proof-of-reserves inclusion. Navigate to Account → Proof of Reserves and verify your balance appears in Bybit’s published Merkle tree. This confirms your funds are actually backed by the reserves Bybit claims to hold.
During Your Time on Bybit
Check your active sessions monthly. Any device you do not recognise in your session list should be revoked immediately.
Verify the Bybit domain every time you log in. The correct addresses are bybit.com for global users and bybit.eu for EU users. Bookmark them and use the bookmark — do not type the address each time.
Keep only your active trading capital on the exchange. Move funds to your hardware wallet when you are not actively trading them.
Check our Scam & Rug Pull Alerts before acting on any unexpected communication from Bybit. We track active phishing campaigns targeting Bybit users in real time, including fake security alert emails, fake withdrawal confirmation messages, and fake KYC update requests.
Do not store seed phrases digitally. If you are using a hardware wallet alongside Bybit, your seed phrase must be on paper or metal, stored physically in a secure location, and never photographed or typed anywhere.
Section 9: The Biggest Crypto Exchange Hacks in History — And What They Reveal About Keeping Your Money Safe
The Bybit hack of February 2025 did not happen in a vacuum. It is the most recent chapter in a history of exchange breaches stretching back to Bitcoin’s earliest days — a history that reveals consistent patterns, repeated vulnerabilities, and in some cases, repeated failures to learn from what came before.
Understanding this history is not morbid curiosity. It is the most practical thing any crypto investor can do. The patterns that caused every major hack on this list are still present in the industry today. Recognising them tells you what to look for when choosing an exchange, what questions to ask, and which red flags no amount of marketing language should be allowed to override.
From 2011 through mid-2025, the crypto industry suffered $22.7 billion in losses to hacks and scams across 785 incidents, according to a longitudinal study by Crystal Intelligence. ChainPlay Here are the hacks that defined that history — and what each one actually means for you.
Mt. Gox — $460 Million (2014): The Original Warning
Mt. Gox was once the largest Bitcoin exchange in the world, handling over 70% of all global Bitcoin transactions at its peak. Between 2011 and 2014, hackers gradually drained approximately 850,000 BTC from the exchange — worth around $460 million at the time, and over $60 billion at 2026 prices. The breach was not discovered for years because the exchange’s accounting systems were so poorly maintained that the missing funds went undetected.
The hack worked through a combination of hot wallet theft and internal accounting manipulation. Mt. Gox’s CEO Mark Karpeles did not use any version control software for the site’s source code Scam Help — a technical failing that is almost incomprehensible for a platform handling billions of dollars in user funds. The exchange eventually suspended trading, filed for bankruptcy, and collapsed. Users waited over a decade for partial repayments, which are still being processed through bankruptcy proceedings in 2026.
What it tells you: Cold wallet storage, proof of reserves, and independent auditing are not optional features. They are the baseline. Any exchange that cannot prove its reserves are intact through a verifiable, third-party-audited mechanism should be avoided entirely.
Coincheck — $530 Million (2018): The Hot Wallet Catastrophe
Japan-based Coincheck suffered the largest single theft since Mt. Gox when hackers stole approximately $530 million worth of NEM tokens from its hot wallet in January 2018. The attack was relatively straightforward by the standards of what came later: the exchange held nearly all of its NEM holdings in a single online (hot) wallet without multi-signature protection, despite industry guidance at the time being clear that large holdings should never be kept in hot storage.
The exchange was subsequently acquired by Monex Group, a Japanese financial services company, and rebuilt under significantly stronger security standards. The Japanese Financial Services Agency (FSA) used the incident to push through stricter crypto exchange regulation that became a model for other jurisdictions.
What it tells you: Hot wallets — exchange wallets connected to the internet for operational convenience — are consistently the weakest link in exchange security. The majority of major exchange hacks target hot wallets. Any exchange that cannot clearly explain what percentage of user funds are held in cold storage, and that cannot demonstrate multi-signature protection on those cold wallets, carries elevated custodial risk.
KuCoin — $281 Million (2020): The Recovery That Worked
KuCoin suffered a $281 million hack in September 2020 when attackers stole private keys to its hot wallets and drained funds across Bitcoin, Ethereum, and multiple ERC-20 tokens. What makes the KuCoin case notable is not the theft itself — it is the response.
KuCoin recovered $204 million through a rapid response Scam Help — working with blockchain analytics firms, engaging with token project teams who froze stolen assets at the smart contract level, and cooperating with law enforcement. The exchange covered remaining user losses from its insurance fund and continued operations without suspending withdrawals. It subsequently upgraded to a more robust multi-signature cold storage system and real-time on-chain monitoring.
What it tells you: Exchange response matters as much as prevention. An exchange that communicates immediately, keeps withdrawals open, and uses every available tool to recover stolen funds demonstrates the kind of operational integrity that should inform your choice of platform. KuCoin’s 2020 response and Bybit’s 2025 response share important similarities — both kept users made whole without suspension.
Ronin Network / Axie Infinity — $624 Million (2022): The Bridge Vulnerability
The Ronin Network hack of March 2022 set the previous record for the largest crypto theft in history at $624 million. The Ronin Network was a blockchain bridge supporting Axie Infinity, a play-to-earn gaming platform. Attackers — again the Lazarus Group — compromised five of the nine validator nodes required to authorise transactions on the bridge, giving them the ability to forge withdrawals and drain the network.
The attack exploited a combination of social engineering (a fake job offer PDF sent to a Sky Mavis engineer contained malware) and an insufficiently decentralised validator set. Cross-chain bridges have been the single most exploited piece of infrastructure in crypto since 2021, with over $2.8 billion drained from them — roughly 40% of every dollar stolen in Web3. NFT Evening
What it tells you: Bridge infrastructure — the technology that moves assets between different blockchains — is disproportionately targeted because it combines high value concentration with complex, difficult-to-audit code. If you use cross-chain bridges as part of your crypto activity, understand that this is one of the highest-risk operations you can perform. Use only well-audited, battle-tested bridges and keep bridge transactions small relative to your total holdings.
FTX — $8 Billion+ (2022): Not a Hack, Something Worse
FTX’s November 2022 collapse is not a hack in the conventional sense — it was fraud. Founder Sam Bankman-Fried directed the transfer of billions in customer deposits from FTX to Alameda Research, his sister trading firm, without customer knowledge or consent. When Binance announced it would liquidate its FTX token holdings, a bank run exposed the missing funds and FTX filed for bankruptcy within days.
SBF received a 25-year prison sentence in March 2024, and must forfeit $11 billion to compensate victims of the scam. Scam Help Customer repayments — at dollar values, not crypto prices — began in 2024 but do not fully compensate users who held assets that appreciated significantly after FTX’s collapse.
What it tells you: The most dangerous threat to your exchange funds is not always a hacker. Sometimes it is the exchange itself. Proof of reserves that are independently audited by a reputable third party using a Merkle-tree methodology — where you can individually verify your own account balance is included — is the only meaningful protection against this category of risk. FTX’s “proof of reserves” were later revealed to be fabricated. Bybit’s are verified monthly by Hacken and individually checkable by every user.
OneCoin — $4 Billion (2014–2019): The Biggest Crypto Fraud in History
OneCoin does not appear on most “biggest crypto exchange hacks” lists because it was not a hack. It was something far more dangerous: a fraud that never involved a real cryptocurrency at all. It belongs on this list because it is the single largest theft of money from crypto investors ever recorded — dwarfing every exchange hack on this page — and because the tactics it used are still being replicated by scammers today at smaller scales across the globe.
Between 2014 and 2019, Ruja Ignatova — a Bulgarian-German entrepreneur with a doctorate in private international law from the University of Konstanz and a brief career at McKinsey — co-founded OneCoin with Karl Sebastian Greenwood and built what the US Department of Justice has called one of the largest fraud schemes in history. OneCoin defrauded as many as 3.4 million investors worldwide through a fake cryptocurrency that never operated on a blockchain. ResearchGate
The scheme was elegant in its simplicity. Ignatova presented OneCoin as a Bitcoin competitor — simpler, safer, and destined to be the world’s dominant digital currency. She sold “educational packages” that came bundled with OneCoin tokens. Investors were promised that the coin’s value was rising and would continue to rise. They were shown charts, shown figures, shown a ledger — but none of it was real. OneCoin was not a real cryptocurrency, and the claims she made about the coin’s increasing value were lies. NFT Plazas There was no blockchain. The coin existed only as entries in a private internal database that Ignatova’s team controlled and manipulated at will.
The operation was structured as a multi-level-marketing pyramid. Existing investors earned commissions by recruiting new investors. This created a self-sustaining recruitment engine that spread OneCoin across 175 countries, from London’s Wembley Arena — where Ignatova performed to thousands of cheering investors — to rural Uganda, where families sold livestock and property to buy in. Wealthy investors lost millions of dollars and investors in rural Uganda lost their homes. Ventureburn The vast majority of investment came from China, but funds flowed from Brazil, Pakistan, Norway, Canada, Yemen, Palestine, and dozens of other countries.
At its peak, Ignatova was among the most recognisable figures in the crypto world. She styled herself the “Cryptoqueen.” She spoke at packed arenas. She appeared on international television. She had an Oxford education, a McKinsey background, and a confident, authoritative stage presence that made scepticism feel like ignorance. In June 2016, she told a Wembley Arena crowd that within two years, nobody would speak about Bitcoin anymore. People believed her.
Throughout the scheme, OneCoin is believed to have defrauded victims out of more than $4 billion. Ventureburn Some investigators and victims contend the true figure is considerably higher — estimates cited by insiders reach $15 billion when accounting for funds moved through shell companies and criminal networks across multiple jurisdictions.
The Disappearance
On 25 October 2017, Ignatova was scheduled to address a room full of investors in Lisbon, Portugal. Instead, she boarded a Ryanair flight from Sofia to Athens. She did not appear in Lisbon. She has not been seen publicly since. In June 2024, the FBI increased the reward for information leading to her arrest to $5,000,000. NFT Plazas She is currently on the FBI’s Ten Most Wanted Fugitives list — only the 11th woman ever to appear there in the list’s 72-year history, and currently the only woman on it.
What happened to her remains unknown. Bulgarian investigative reporting found that a police informant had overheard someone claiming that Ignatova was murdered in November 2018 on a Bulgarian drug lord’s orders, aboard a yacht in the Ionian Sea, and her body disposed of at sea. NFT Plazas However, investigators and journalists who have spent years tracking her whereabouts are divided. German documentary filmmaker Johan von Mirbach, who directed a 2022 investigative documentary on the case, says he is convinced she is still alive, pointing to what he describes as too many failed efforts to lay false tracks about her whereabouts. LiquidityFinder As of 2026, searches have focused on Cape Town, South Africa, and there is speculation about connections to individuals linked to the Russian government.
Her co-founder Karl Sebastian Greenwood was arrested and admitted to federal wire fraud and money laundering charges in 2022. ResearchGate He received a 20-year prison sentence. Ignatova’s brother Konstantin Ignatov was arrested at Los Angeles International Airport in March 2019 and pleaded guilty to wire fraud conspiracy and money laundering charges, cooperating with prosecutors and providing extensive information about the scheme’s inner workings.
Where the Legal Process Stands in 2026
Despite the scheme collapsing in 2017, the legal proceedings continue. In August 2024, a UK court ordered a global asset freeze on assets belonging to Ignatova and her associates NFT Evening following an ICIJ investigation that revealed OneCoin promoters had purchased luxury properties in Dubai, including a $2.7 million penthouse. In late 2025, Guernsey courts ordered the seizure of properties held in Ignatova’s name through shell companies on the island.
Most significantly for victims: in April 2026, the US Department of Justice opened a $40 million victim compensation claims process for OneCoin victims ResearchGate — the first formal restitution mechanism available to the scheme’s 3.4 million victims globally. The $40 million represents seized assets recovered through prosecutions to date. It is a fraction of the estimated $4 billion stolen, but it represents the first concrete step toward any financial remedy for victims who in many cases lost their entire savings. The claims process is administered through the Southern District of New York and is open to victims worldwide.
What OneCoin Tells You
OneCoin is the most important case study for any crypto investor because it demonstrates the most dangerous attack vector of all: not a technical hack, but a social one. Ignatova did not exploit a smart contract vulnerability or compromise a private key. She exploited trust, authority, and the human tendency to believe in a compelling story told by a credible-seeming person.
The warning signs were present throughout OneCoin’s run — and they are present in every similar scheme operating today. OneCoin had no verifiable blockchain. The coin could not be independently audited or tracked on any public ledger. Its value was determined entirely by the company that sold it, with no external market price discovery. It was marketed primarily through a multi-level-marketing structure that rewarded recruitment over investment returns. Investor events resembled religious revivals more than financial product presentations. And when sceptics asked technical questions, they were dismissed as people who “don’t understand the vision.”
Every one of those characteristics is a documented red flag. Every one of them is still used by fraudulent crypto projects in 2026 — scaled down to thousands of dollars rather than billions, but structurally identical.
Before investing in any cryptocurrency project — not just major exchanges — verify the following: does the blockchain exist and can you independently examine it on a public explorer? Is there an independent technical audit from a reputable security firm? Can you find the token’s contract address and verify it on-chain? Do the founders have verifiable, real-world identities with a public track record? Does the investment opportunity rely on recruiting others rather than the underlying asset’s value?
You can run any token or project through our free Cryptosmap Trust Engine before committing a single dollar. It checks for blockchain existence, contract audit status, honeypot characteristics, and community-verified threat intelligence — the exact due diligence that OneCoin’s victims never had access to in 2014. Our Scam & Rug Pull Alerts page also tracks active OneCoin-style schemes currently operating globally, updated in real time.
Ruja Ignatova promised people financial freedom and delivered financial ruin. The only protection against the next person who makes the same promise is knowing exactly what to look for before you hand over a single dollar.
DMM Bitcoin — $308 Million (2024): Regulation Does Not Guarantee Safety
The $305 million hack of Japanese exchange DMM Bitcoin in May 2024 Media Search Group demonstrated something important: being regulated does not make an exchange immune to catastrophic security failures. DMM Bitcoin operated under Japan’s FSA — one of the most stringent crypto regulatory regimes in the world. Despite this, investigations led to the North Korean Lazarus Group becoming suspects Scam Help in what appeared to be a private key compromise of its hot wallet.
In December 2025, DMM Bitcoin announced it would discontinue its operations Scam Help after sustained withdrawal restrictions and transfer its client accounts to SBI VC Trade. Unlike Bybit, DMM Bitcoin did not have the reserves or institutional backing to absorb the loss and continue operating at scale.
What it tells you: Regulatory licensing is a meaningful signal of compliance standards, but it is not a guarantee of financial resilience. An exchange can be fully licensed and still fail to protect user funds if it lacks sufficient reserves or insurance to cover a major loss event. Proof of reserves — independently verified, regularly published, and individually checkable — matters more than regulatory status alone.
WazirX — $230 Million (2024): The Multi-Sig Failure
India’s largest domestic crypto exchange lost approximately $230 million in July 2024 when hackers compromised one of its multi-signature wallets. Both the DMM Bitcoin and WazirX incidents involved compromised private keys targeting centralised finance (CeFi) infrastructure Media Search Group — and together they accounted for over a third of all crypto losses in 2024.
The WazirX case is particularly instructive because it involved multi-signature wallet infrastructure — security technology specifically designed to prevent single-point failures. The attackers compromised the signing infrastructure sufficiently to manipulate the transaction approval process in a manner disturbingly similar to the Bybit hack seven months later.
What it tells you: Multi-signature wallet schemes are meaningful security improvements over single-key custody, but they are not impenetrable. The attack surface shifts from the private key itself to the software used to construct, display, and approve transactions for signing. This is precisely the vulnerability that Lazarus Group exploited at Bybit through Safe{Wallet}.
Bybit — $1.5 Billion (2025): The Record Broken
The Bybit hack of February 2025 is covered in full in the main body of this article. In the context of this historical overview, two things are worth highlighting.
First: crypto losses in 2025 totalled $3.4 billion — the highest annual figure since 2022 — with North Korean hackers netting $2.02 billion, up $681 million from 2024, via advanced infiltration methods. The Serp Wizards The Bybit hack drove the majority of that figure. North Korean hackers executed fewer but far more damaging attacks in 2025, which Chainalysis attributes to an increase in sophistication and patience as they focus more on high-yield targets. DataWallet
Second: only about $334.9 million of stolen funds were recovered or frozen in 2025 — down sharply from $488.5 million in 2024 — as more funds moved quickly through bridges, mixers, and cross-chain routes, reducing recovery chances. DataWallet
What it tells you: Recovery of stolen crypto is becoming less likely over time as laundering techniques become more sophisticated. The practical implication: prevention and exchange resilience matter more than recovery potential. Choose exchanges that have demonstrated they can absorb losses without harming users — not just exchanges that have not been hacked yet.
The Pattern Every User Needs to Understand
Reviewing the eight cases above, four recurring vulnerability categories stand out — and all four remain active threats in 2026.
Hot wallet exposure. Exchanges that hold a significant proportion of user funds in online wallets for operational convenience create a high-value target with a large attack surface. Every major exchange that has suffered catastrophic losses held too much in hot storage.
Third-party supply chain compromise. Both the Bybit and WazirX hacks exploited not the exchange’s own code, but the third-party software used to construct and approve transactions. North Korean operatives embedded themselves as IT workers within Web3 firms and exploited third-party vendors The Serp Wizards — a pattern that has become their primary attack vector.
Insufficient reserve buffers. The difference between Bybit and DMM Bitcoin in their respective hack responses came down largely to reserve depth. Bybit had the institutional relationships and financial position to replenish $1.5 billion within 72 hours. DMM Bitcoin did not, and ultimately could not continue operating.
Social engineering over technical exploitation. As Immunefi founder Mitchell Amador put it, with code becoming harder to exploit, the main target for hackers in 2026 is people. NFT Evening The Lazarus Group’s attacks on Bybit, Ronin, and DMM Bitcoin all involved a social engineering component — tricking a human into either downloading malware, approving a malicious transaction, or granting access they should not have granted.
What This History Means for Choosing an Exchange Today
Before depositing on any exchange, run through this checklist informed by the historical record above:
Does the exchange publish independently audited proof of reserves on a regular basis — monthly is now the standard — using a Merkle-tree methodology that allows you to individually verify your balance? If not, you have no way to confirm that your funds actually exist on the platform.
Has the exchange ever suspended withdrawals? Any exchange that has done so — for any reason — has demonstrated that it prioritises its own operational needs over your access to your funds.
Does the exchange clearly disclose what percentage of user assets are held in cold storage versus hot wallets? Hot wallet exposure is the most common cause of catastrophic exchange losses.
Has the exchange ever faced a major loss event, and if so, how did it respond? An exchange that has absorbed a loss and made users whole is in some ways more trustworthy than one that has never been tested — because you know how it behaves under pressure.
Does the exchange have independent third-party security audits of its infrastructure? Bug bounty programmes, regular penetration testing, and published audit reports from reputable security firms are meaningful signals of a security-first culture.
You can run any exchange through the Cryptosmap Trust Engine for a real-time on-chain safety assessment that cross-references against six layers of live security data in under 60 seconds. For the full guide on how to evaluate whether any crypto platform is legitimate before depositing, see our Educational Guides.
The history of crypto exchange hacks is not a reason to avoid crypto. It is a manual for how to participate in it safely.
Frequently Asked Questions
Q: Is Bybit safe after the $1.5 billion hack?
Yes. The February 2025 hack resulted in zero user losses. Bybit replenished all stolen funds within 72 hours through institutional emergency loans, maintained open withdrawals throughout the crisis, and passed an independent proof-of-reserves audit three days after the theft. Its security infrastructure has been significantly upgraded since the incident, including enhanced internal transfer verification, TEE and TSS deployment in its custody system, and new multi-layer authorisation requirements for any fund movement between wallets.
Q: Has Bybit ever frozen withdrawals?
No — and this matters more than almost any other single data point. Bybit has never suspended general withdrawals at any point in its history, including during the February 2025 hack when $1.5 billion was stolen from its infrastructure. Every exchange that has ultimately harmed users — FTX, Celsius, Voyager, BlockFi — did so by restricting withdrawal access before the extent of their problems became public.
Q: Is Bybit regulated?
Partially, depending on your location. Bybit holds a MiCA licence from Austria’s FMA covering all 29 EEA countries (through bybit.eu), a UAE SCA Virtual Asset Platform Operator licence, and registrations in Kazakhstan and Georgia. It does not hold FCA (UK) or FinCEN (US) registration and is not available to UK or US residents.
Q: Why do some users have their accounts frozen on Bybit?
Account and withdrawal restrictions on Bybit are typically triggered by Bybit’s AML compliance systems when a transaction or account pattern matches risk indicators that the platform is legally required to review. These reviews are mandatory under MiCA, UAE SCA requirements, and most other regulatory frameworks Bybit operates under. The problem is not that the reviews occur — they are legally required — but that Bybit’s support capacity for resolving them at scale appears insufficient, leading to extended delays and poor communication for affected users.
Q: Is it safe to leave large amounts on Bybit long-term?
No exchange is appropriate for holding large long-term crypto positions. Even the safest, most well-regulated exchange is a custodial arrangement — they hold your keys, not you. Long-term holdings above an amount you could comfortably afford to lose temporarily (due to compliance review, technical issue, or in an extreme scenario, platform insolvency) should be stored in a hardware wallet under your own control. Our guide to self-custody and hardware wallets covers the setup process in detail.
Q: How does Bybit’s proof of reserves work and can I verify mine?
Bybit uses a Merkle-tree proof of reserves methodology, independently audited monthly by Hacken. This allows each individual user to verify that their specific account balance is included in the published reserve total — not just trust a headline figure. To verify your inclusion: log in to Bybit → Account → Proof of Reserves → use the Merkle inclusion checker. The process takes about two minutes and gives you cryptographic proof that your balance is backed.
Q: What are the biggest risks of using Bybit in 2026?
The most significant risks for individual users are: AML-triggered compliance reviews that may restrict account access for extended periods (particularly if your on-chain transaction history includes interactions with flagged addresses or services); the residual supply chain risk from third-party platform dependencies (mitigated but not eliminated since the 2025 hack); the absence of FCA or FinCEN regulation limiting legal recourse for UK and most non-EU users; and the general counterparty risk inherent in any centralised exchange custody arrangement.
Q: What should I do if I think a Bybit communication is a scam?
Do not click any links. Check the email against your personal anti-phishing code — if the code is absent or wrong, it is a phishing attempt. Verify current Bybit-related phishing campaigns on our Scam & Rug Pull Alerts page. Report suspicious communications directly through Bybit’s official support centre. If you are unsure whether an exchange or token is legitimate, run it through our free Trust Engine.
Q: What is the safest way to use Bybit?
Enable all security features before depositing: authenticator-app or hardware-key 2FA, anti-phishing code, withdrawal address whitelist, fund password, and passkeys. Keep only your active trading capital on the platform — move long-term holdings to a hardware wallet. Verify your proof-of-reserves inclusion monthly. Check your active sessions monthly. Use the Cryptosmap Trust Engine and Scam Alerts page before acting on any unexpected communication. Test withdrawals with a small amount before depositing significant funds.
Q: Where can I find the most up-to-date safety information about Bybit and other exchanges?
Cryptosmap’s Trust Engine provides real-time on-chain safety data. Our Scam & Rug Pull Alerts page tracks active threats including phishing campaigns. Our Educational Guides cover how to read proof-of-reserves reports, evaluate exchange safety, and set up hardware wallets. Our Market Insights section covers exchange comparisons and regulatory developments as they happen.
Further Reading on Cryptosmap
- Cryptosmap Trust Engine — run any exchange or token through our six-layer on-chain safety check, free, in under 60 seconds
- Scam & Rug Pull Alerts — live intelligence on active phishing campaigns, rug pulls, and exchange impersonation threats
- Educational Guides — how to spot a crypto scam, how to choose a safe exchange, how to set up hardware wallet self-custody, and more
- Market Insights — exchange comparisons, regulatory updates, and data-driven analysis to help you make informed decisions
- Bybit Referral Code 2026: The Honest Guide — if you have decided Bybit is right for you, our companion article walks through exactly how to sign up, claim your bonus, and set up your account securely
Disclaimer
The content in this article is for educational and informational purposes only. It does not constitute financial, investment, or legal advice. Cryptocurrency trading is highly volatile and carries significant risk of loss. Never invest more than you can afford to lose. Always conduct your own research before depositing on any exchange.
This article contains affiliate links to Bybit. Cryptosmap may earn a commission if you sign up using our referral code. This never affects our ratings, editorial independence, or which risks we choose to cover. Our Trust Engine scores are never for sale.
Bybit is not available to residents of the United States, United Kingdom (without FCA registration), mainland China, Singapore, or other restricted jurisdictions. Always verify your eligibility before registering.



