Bybit's AI System Prevents $300 Million in Fraudulent Withdrawals

John NadaBy John Nada·Mar 3, 2026·6 min read
Bybit's AI System Prevents $300 Million in Fraudulent Withdrawals

Bybit's new AI-assisted system successfully blocked over $300 million in fraudulent withdrawals, highlighting the need for enhanced security measures in crypto exchanges.

Bybit announced it blocked or disrupted over $300 million in suspected scam-related withdrawals in Q4 2025, thanks to a newly implemented AI-assisted risk monitoring system. This system is designed to flag potentially malicious transactions before they can leave the exchange, showcasing an evolving approach to security in the cryptocurrency sector.

In a detailed blog post, Bybit explained that its advanced risk monitoring system flagged approximately $500 million in withdrawal requests during the quarter. This proactive measure has not only led to significant financial protection for users but also demonstrated Bybit's commitment to cultivating a secure trading environment. More than 4,000 users received real-time risk alerts or had their transactions completely blocked, indicating a robust user protection mechanism that operates effectively in real-time.

David Zong, Bybit’s head of group risk control, emphasized the system's efficiency. He noted that a considerable portion of the $300 million figure consists of withdrawals that users voluntarily canceled after receiving alerts. This insight illustrates the system's effectiveness in preventing potential losses, ensuring that funds remained in user accounts rather than necessitating recovery or reimbursement processes. "Because the withdrawals were stopped prior to completion, the funds did not require recovery or reimbursement. They remained in users’ accounts at all times," Zong stated, highlighting a user-centric approach to transaction security.

In addition to thwarting withdrawals, Bybit's AI system played a crucial role in identifying 350 high-risk investment fraud addresses, successfully protecting approximately 8,000 users from potential losses linked to these fraudulent schemes during the previous quarter. The ability to proactively identify and shield users from high-risk scenarios is a testament to the growing sophistication of Bybit’s security framework, which is becoming increasingly essential in a landscape marked by digital fraud.

Furthermore, Bybit reported blocking over three million credential stuffing attacks throughout 2025. Credential stuffing, a common cyber threat where attackers use stolen credentials to gain unauthorized access to user accounts, poses a significant challenge to cryptocurrency exchanges. The fact that Bybit successfully thwarted millions of such attacks demonstrates not only the platform's commitment to user security but also reflects the escalating sophistication of cyber threats targeting the cryptocurrency industry. As cryptocurrency hacks resulted in staggering losses of $3.4 billion in 2025, the urgency for enhanced security measures becomes increasingly clear.

Bybit’s risk detection framework aims to intercept fraudulent withdrawal attempts before they occur, relying on exchange data to identify unusual patterns, such as mass withdrawals. This data-driven approach is particularly vital in a market where the risk of cyberattacks is ever-present. High-risk withdrawals receive either warning prompts or complete transaction blocks based on their severity, allowing users to make informed decisions about their transactions and significantly reducing the likelihood of fraud.

This innovative theft prevention framework is built on a triple-tied system that enables Bybit’s operations team to preemptively blacklist dangerous destination addresses. By employing advanced analytics and AI technologies, Bybit is at the forefront of a new wave of security measures designed to protect its users from the pervasive threats that loom over the cryptocurrency landscape.

Cybersecurity experts have consistently called for the cryptocurrency sector to adopt real-time, AI-powered threat monitoring systems to fend off cybercrime effectively. Deddy Lavid, CEO of the blockchain cybersecurity firm Cyvers, has underscored the importance of implementing AI-based anomaly detection, which could significantly bolster defenses against hackers aiming to infiltrate exchanges and steal funds or sensitive data. This sentiment resonates with the broader industry, which is increasingly recognizing the necessity of advanced security measures to maintain user trust and safeguard digital assets.

The cryptocurrency landscape is fraught with risks, as highlighted by the Coinbase data breach in May 2025. This incident exposed wallet balances and physical locations of about 1% of the exchange's users, leading to reimbursement costs that soared up to $400 million. Such breaches serve as stark reminders of the vulnerabilities that exist even among established platforms, reinforcing the need for exchanges to invest heavily in security technologies and protocols.

Bybit's efforts to innovate in fraud prevention could set a new standard in the industry. As exchanges face mounting pressure to protect users against cyber threats, the adoption of advanced technologies like AI for real-time monitoring may soon transition from a luxury to a necessity. The proactive measures taken by Bybit could influence competitors to enhance their security protocols, potentially reshaping industry standards and prompting a collective response to the evolving threat landscape.

In the broader context, the success of Bybit's system may encourage other exchanges to consider similar strategies, emphasizing the importance of a unified approach to security challenges in the cryptocurrency sector. As the industry continues to mature, the integration of advanced security measures will likely play a crucial role in maintaining user trust and safeguarding assets.

By prioritizing security and user protection, Bybit is not only mitigating risks but also positioning itself as a leader in the cryptocurrency space. The implications of this approach extend beyond individual exchanges, as it sets a precedent for the entire industry to follow in the fight against fraud and cyber threats. By establishing a framework that protects users in real-time, Bybit is paving the way for a more secure cryptocurrency environment—one where users can trade with confidence, knowing their assets are safeguarded against malicious actors.

The evolution of Bybit’s security measures reflects a broader trend in the cryptocurrency industry, where exchanges are increasingly recognizing the importance of investing in robust cybersecurity frameworks. As digital currencies continue to gain traction, the expectation for exchanges to provide secure trading environments will only grow stronger. Users are becoming more informed about the risks, and they are likely to demand greater transparency and security from the platforms they choose to engage with.

In light of the persistent threats facing the cryptocurrency sector, Bybit’s strategic focus on AI-driven security solutions could inspire a wave of innovation among its competitors. As the industry grapples with the challenges posed by cybercriminals, the adoption of AI and machine learning technologies may become critical components of an effective security strategy. Bybit’s commitment to protecting its users not only strengthens its standing in the market but also contributes to the overall health and sustainability of the cryptocurrency ecosystem.

With the rapid advancement of technology and the increasing complexity of cyber threats, Bybit's initiative to implement AI-assisted risk monitoring stands as a significant milestone in the ongoing battle against fraud. The proactive stance taken by Bybit serves as a model for other exchanges, highlighting the necessity for ongoing innovation in security practices. The future of cryptocurrency trading may very well depend on the industry’s ability to adapt to these evolving threats, ensuring that user safety remains a top priority as the market continues to grow and evolve.

Scroll to load more articles