The $1.5 billion stolen from Bybit in February 2025 exposed a familiar weakness in crypto security: an attacker does not need to compromise a blockchain if there are easier targets around it.
The FBI attributed the theft to North Korea. The attackers targeted the infrastructure surrounding a wallet transfer, manipulating what signers believed they were approving rather than breaking Ethereum itself.
Eighteen months later, Bybit’s response points to a broader change in how crypto companies are approaching that problem.
The exchange says it intercepted more than 30,000 suspicious withdrawal requests involving nearly 20,000 users during the first half of 2026, representing more than $700 million in potential losses. Initial reviews took an average of 4.7 minutes, with 95% assessed in less than ten minutes.
Elsewhere in its security operation, AI-assisted tools are transforming performance:
- Higher Detection Rates: High-severity vulnerabilities are being identified at up to five times the rate of manual reviews;
- Compressed Testing Cycles: Specific testing routines previously taking roughly two weeks have been reduced to two hours;
- Scale of Monitoring: Systems analyzed nearly 1,500 digital assets and processed over 100,000 security alerts.
Those figures come from the company itself, and $700 million in flagged transactions should not be interpreted as $700 million that would otherwise certainly have been stolen.
The more important signal is the change in time: AI is making it possible to search for vulnerabilities, detect suspicious behavior, and process security alerts much faster. Attackers are gaining access to the same capabilities.
That is turning crypto security into a race in which being right may matter less if the other side gets there first.
Crypto Has a Speed Problem
Traditional security relies heavily on checkpoints. Code is reviewed before release, major updates are audited, vulnerabilities are disclosed, patches are developed, and systems are tested again.
That model works best when defenders have enough time between discovering a weakness and someone exploiting it. AI is beginning to compress that window.
Advanced models can inspect large codebases, identify suspicious patterns, and automate parts of vulnerability discovery at a scale that would require far more time from human researchers:
- For defenders: It offers broader code coverage and continuous monitoring;
- For attackers: It enables systematic, large-scale searches for exploitable flaws;
- For the market: The economics of vulnerability discovery shift when machines examine thousands of potential weaknesses simultaneously.
Crypto is particularly exposed to that shift. Smart contracts, exchanges, and custody systems often protect assets that can be moved almost instantly once an attacker succeeds. There is no fraud department capable of reversing the transaction the following morning.
A defense that identifies the attack after the money has moved may have identified it correctly and still failed.
AI Is Moving From the Lab Into the Security Stack
Bybit is not the only company responding to this shift. More than 40 organizations connected to digital assets, including Coinbase, Block, and BitGo, recently called for security researchers to receive controlled early access to the most capable AI models.
Their concern reveals how quickly the competitive dynamic is changing: if increasingly powerful models can help discover exploitable weaknesses, defenders cannot spend months working with less capable tools while attackers gain access elsewhere.
AI-assisted auditing is already demonstrating what greater search capacity can look like. One large-scale review of hundreds of projects across the Bitcoin ecosystem generated almost 5,000 security findings in little more than a day, including dozens initially classified as critical.
The headline number needs qualification. Automated findings are not the same as confirmed exploitable vulnerabilities. They require human review, and AI systems can generate false positives or misunderstand the context in which code operates.
But that is not necessarily the benchmark that matters. AI does not need to replace security researchers to transform their work—it only needs to let them search much more software, much more often.
The Audit Is Becoming Continuous
That distinction points toward a more significant change than simply making existing audits faster: security is moving closer to a continuous process.
A crypto company does not operate the same system indefinitely. New assets are listed, software changes, wallet infrastructure evolves, users interact with the platform, and new attack techniques appear. Every change alters the attack surface.
Periodic audits remain necessary, but the interval between them becomes a vulnerability of its own when attackers can continuously search for weaknesses.
AI gives defenders the ability to adapt to the same model:
- Continuous Code Scanning: Software is inspected iteratively rather than during fixed milestones.
- Real-time Transaction Analysis: Onchain and offchain operations are evaluated as they occur.
- Automated Alert Prioritization: Triage happens instantly, leaving human specialists to investigate edge cases requiring complex judgment.
That division of labor is essential because AI remains imperfect. Models can miss vulnerabilities, generate noise, or fail to comprehend complex attacks that rely on combinations of technical, operational, and human weaknesses.
The objective is therefore not autonomous security. It is shorter detection and response cycles.
Bybit Is Trying to Change Who Gets There First
The 2025 attack illustrates why that distinction matters. Bybit was not defeated because Ethereum stopped working; the attackers exploited infrastructure surrounding the movement of assets and the human process used to authorize it.
That kind of attack sits precisely at the intersection where crypto security is most difficult: code, interfaces, custody, and human behavior all have to work correctly at the same time.
AI cannot remove those dependencies. What it can do is watch more of them simultaneously.
That helps explain why the most consequential number in Bybit’s new security data may not be the $700 million in potential losses it intercepted. It may be 4.7 minutes.
The industry spent years improving audits, custody structures, and monitoring systems to make attacks harder. AI introduces a different objective: make the window available to the attacker smaller.
That also creates an uncomfortable symmetry. Every improvement in AI-assisted defense can eventually become an improvement in AI-assisted offense. Neither side has a permanent technological advantage.
The result is a security environment increasingly defined by response time.
Crypto’s largest theft demonstrated what happens when an attacker finds the weak point first. Bybit’s response suggests that the next phase of crypto security will be less about eliminating every vulnerability — an impossible goal — and more about continuously searching for them before someone else does.
In an industry where assets can disappear in minutes, security is becoming a competition over who can make those minutes count first.
