Is Bybit Safe? What the 2025 Hack Actually Tells You
Bybit lost around 401,000 ETH to attackers on 21 February 2025, worth roughly $1.4bn to $1.5bn at the time. It was the largest theft in the history of crypto exchanges by value, and it is the first thing anyone should look at before opening an account. Any review that skips it, or buries it under a fee table, is not worth reading.
For bearings before any of that: Bybit launched in 2018, has been headquartered in Dubai since 2022, and has for years ranked among the largest crypto derivatives venues by turnover. That scale is not decoration, it is the reason the story below ended the way it did.
The useful question is not whether Bybit has ever been hacked. It has, spectacularly. The useful question is what happened next, what the company changed, and whether the account you would open today sits under a regulator that can do anything for you. Those answers differ a lot depending on where you live.
Bybit is a large, established exchange that survived the biggest exchange theft on record without passing a single cent of the loss to customers, kept withdrawals running throughout, and now holds a MiCA licence in Austria for its European entity. It is also an exchange that lost $1.4bn because human signers approved a transaction they could not properly verify, that carries no deposit insurance anywhere, and whose European arm no longer offers the derivatives and copy trading many people come to it for. Your money is not guaranteed on any crypto exchange, Bybit included.
What actually happened in February 2025
On 21 February 2025 Bybit was carrying out a routine internal transfer, moving Ethereum from a cold wallet into a warm wallet used for day to day operations. The transfer required several Bybit executives to sign it using Safe{Wallet}, a widely used third party multisignature smart contract wallet. The signers reviewed what looked like an ordinary transfer, approved it, and roughly 401,000 ETH left for addresses they did not control.
This is the part most coverage gets wrong, and it matters if you are judging how safe your own funds would be. The cold wallet's cryptography was not broken and Bybit's own servers were not breached. Two independent forensic investigations, by Sygnia and Verichains, found no evidence of compromise inside Bybit's infrastructure. The attackers had instead compromised a developer machine belonging to Safe{Wallet} and used that access to serve malicious JavaScript from the wallet interface at app.safe.global. The code was conditional, activating only for the specific target, so ordinary Safe users saw nothing unusual. It displayed one transaction to Bybit's signers and submitted a different one, then was removed minutes later to cover the attackers' tracks.
In other words, this was a blind signing failure. The signers approved what their screen told them they were approving, and their screen was lying. That is a real and serious weakness, and Bybit owned it as the party that signed. But it is a different weakness from sloppy key custody or an insider walking off with a private key, and it says different things about the exchange. It also implicated an entire industry practice rather than one company: at the time, plenty of large institutions signed high value transfers the same way.
The theft was publicly attributed by the FBI to North Korean state linked actors, the cluster usually described as the Lazarus Group. The funds were laundered quickly through mixers and cross chain bridges. Bybit launched a bounty program offering 10% of anything recovered, and later pursued civil litigation. Recovery has nonetheless been poor, and as of August 2026 most of the money is gone. Litigation can freeze assets that investigators manage to identify, but a freeze is not the same as funds coming back to the party that lost them. Assume, when you read about any large crypto theft, that the money does not come back.
How Bybit responded, and whether users were made whole
First, withdrawals never stopped. In the hours after the theft became public there was a bank run, which is exactly what you would expect. Bybit processed more than 350,000 withdrawal requests, and reported completing 99.9% of them within about ten hours. Cumulative outflows in the days that followed ran into the billions. A queue did build, and Bybit said so at the time rather than quietly throttling it. Chief executive Ben Zhou stated during the run that around 70% of requests had been cleared in the first couple of hours, that some users would be waiting a few hours, and that network congestion could still delay transfers. What did not happen is the part that matters: withdrawals were never suspended, no emergency maintenance window appeared, and the backlog was worked off within about twelve hours. Compare that with the standard failure pattern in this industry, where the withdrawal button goes dark first and the announcement comes days later.
Second, the hole was filled fast. Bybit closed the ETH gap within roughly 72 hours using a mix of open market purchases, bridge loans and large deposits from counterparties including Galaxy Digital, FalconX and Wintermute. The firm that runs its proof of reserves attestations, Hacken, subsequently reported that major assets including BTC, ETH, SOL, USDT and USDC were back above a 100% collateralisation ratio.
Third, customers took no haircut. There was no socialised loss, no ADL style clawback applied to spot balances, no conversion of user claims into a recovery token. The loss was absorbed on Bybit's own balance sheet, funded partly by borrowing. That is a meaningful data point, and it is the single strongest argument in Bybit's favour.
Now the honest caveat. Users were made whole because Bybit was large enough to eat a $1.4bn loss and because counterparties were willing to lend to it. That was a capacity outcome, not a legal guarantee. There is no deposit insurance scheme behind a crypto exchange anywhere in the world, and nothing in your account terms would have obliged anyone to cover you.
| When | What happened |
|---|---|
| 21 Feb 2025 | Around 401,000 ETH, roughly $1.4bn to $1.5bn at the time, redirected during a cold to warm wallet transfer |
| Same day | Bybit publicly confirms the incident; withdrawals continue processing, with a queue building but no suspension |
| Within ~10 hours | More than 350,000 withdrawal requests handled, reported 99.9% complete |
| Within ~72 hours | ETH gap closed via purchases, bridge loans and counterparty deposits |
| Days after | Sygnia and Verichains forensics point to a compromised Safe{Wallet} developer machine, not Bybit infrastructure |
| Late Feb 2025 | Hacken proof of reserves reports major assets back above 100% collateralisation |
| Ongoing | FBI attributes the theft to North Korean state linked actors; bounty program launched; most of the stolen value remains unrecovered as of August 2026 |
Who you actually contract with: Bybit EU or the offshore entity
Which entity you contract with changes the answer completely, depending on your address.
"Bybit" is not one company. If you are in the European Economic Area, the entity you contract with is Bybit EU GmbH, a company based in Vienna that holds a crypto asset service provider authorisation from the Austrian Financial Market Authority under MiCA, granted by a decision dated 28 May 2025 and passported into 29 EEA states. If you are outside the EEA, you are dealing with an offshore group entity instead, and the Austrian licence does you no good at all. Which entity that is has changed over the years, so read the name in your own account terms rather than trusting a list. Bybit Fintech Limited, the name that appears in the older regulatory actions against the group, is not a safe assumption. The British Virgin Islands Financial Services Commission stated publicly in 2023 that the company, incorporated there in August 2018, had been struck off the BVI register in December 2021, was dissolved in July 2023, and had never been licensed in the territory for financial services at all. The Dutch central bank still named that entity when it fined the group in October 2024, which is exactly why the entity written into your own account terms is worth reading. The February 2025 theft hit the group's global operation, not the Austrian entity.
The practical consequences of that split are large. MiCA's transitional period ended on 1 July 2026, and on 29 June 2026 Bybit announced that it would progressively restrict EEA residents from services on the global platform and move them onto Bybit EU, which is passported into 29 EEA states but not Malta. Bybit said affected users would get notice and timelines first, and would keep access to existing balances and positions so they could wind them down rather than have anything frozen. Bybit EU launched with spot trading, spot margin, Earn products and the Bybit Card. It did not launch with perpetual futures, options or the leveraged derivatives suite Bybit is best known for. Getting those into Europe is a separate application in a separate company: Bybit X GmbH, an Austrian entity distinct from Bybit EU GmbH, applied to the Austrian FMA on 5 September 2025 for an investment firm licence under the Austrian implementation of MiFID II, which is the rulebook crypto derivatives sit under. As of August 2026 that licence had not been granted, so European users do not get those products.
If you arrived on this page because you want Bybit for derivatives or copy trading, and you live in the EEA, that is the fact that decides your answer. The safety question becomes moot, because the product you wanted is not available to you through the licensed entity. Some competitors have already solved this: Kraken, for example, holds a MiCA authorisation through the Central Bank of Ireland alongside a separate MiFID authorisation via CySEC, which is what allows a European venue to offer derivatives lawfully. That is a genuine advantage over Bybit in Europe as of August 2026. Bitvavo is another established European option, though it is a spot venue and not a derivatives one.
Non EEA users get the full product range and, in exchange, weaker protections. Check your account terms to see which entity is named.
| Bybit EU (EEA residents) | Global platform (non EEA) | |
|---|---|---|
| Legal entity | Bybit EU GmbH, Vienna | An offshore group entity, named in your account terms rather than assumed from a list |
| Regulator | Austrian FMA, MiCA CASP authorisation, passported across 29 EEA states | Depends on entity; the group holds Dubai VARA and UAE SCA licences, which do not automatically cover whichever entity your terms name |
| Perpetual futures and options | Not offered; a separate entity, Bybit X GmbH, has a MiFID II application pending since 5 September 2025 | Offered, up to 100x on the deepest pairs, except where local rules exclude them, as in the UK |
| Copy trading | Derivatives copy trading not available; check the Bybit EU product list for spot copy trading | Available, including on derivatives |
| Spot and spot margin | Yes, margin capped well below derivatives leverage | Yes |
| Complaint escalation | Austrian FMA and MiCA complaint handling rules | Limited; depends on entity and jurisdiction |
| Deposit insurance | None | None |
Where Bybit is regulated, and where that word is doing less work than it looks
Offshore exchanges are fond of listing licences, and most of those licences are narrower than the word suggests. It is worth separating the meaningful ones from the decorative ones.
The Austrian MiCA authorisation is the real one. MiCA imposes requirements on client asset segregation, governance, complaint handling, custody liability and disclosure, and a European authority can act against the firm. Bybit EU is authorised for a subset of MiCA's crypto asset services rather than all of them, and it does not cover derivatives, which are financial instruments and sit under MiFID rather than MiCA. Bybit's payments arm, Bybit Payments GmbH, was granted an electronic money institution licence by the Austrian FMA under the E-Money Act 2010, announced on 4 August 2026, which is relevant to card and payment services rather than to trading.
In the UAE, Bybit moved its headquarters to Dubai in 2022, holds licensing from Dubai's Virtual Assets Regulatory Authority, and in October 2025 obtained a Virtual Asset Platform Operator licence from the UAE Securities and Commodities Authority. These are genuine authorisations in a jurisdiction with a real virtual asset regime, but they create no compensation scheme and will not help a user in Brazil or Vietnam.
The regulatory record is not spotless, and you should weigh it. On 22 October 2024 the Dutch central bank, De Nederlandsche Bank, fined Bybit Fintech Limited €2,250,000 for offering crypto services in the Netherlands without the legally required registration, covering a period running until September 2023. In January 2025 India's Financial Intelligence Unit imposed a penalty of about ₹9.27 crore, roughly $1m, for operating without registration under Indian anti money laundering law; Bybit paid, registered, and resumed service there later in 2025. France's markets regulator had previously listed Bybit as an unauthorised provider, and it was removed from that list in early 2025.
The pattern is consistent and worth naming plainly: Bybit has repeatedly operated in markets first and regularised afterwards, paying fines when caught. Since 2024 it has moved decisively towards licensing. Both halves of that sentence are true, and how much weight you give each is a judgement call, not a fact.
Proof of reserves: useful, and narrower than it sounds
Bybit publishes proof of reserves attestations, verified by a third party, on a regular cadence, using a Merkle tree so individual users can check that their own balance was included in the snapshot. After the hack, Hacken's attestation confirmed major assets were back above 100% collateralisation. That is more transparency than most exchanges offered before 2022, and it is worth checking before you deposit.
It is also routinely oversold, so here is what it does not tell you.
A report showing coverage a few points above 100% for BTC is a claim about one asset at one moment, verified by one firm using data the exchange supplied. It is a useful smoke detector, not a guarantee and not insurance.
- It is a snapshot at a single moment. Assets present on the day of the attestation can move the next day.
- It covers only the assets included in that assessment. Anything outside the listed tokens is unverified.
- It does not show off balance sheet liabilities: borrowings, bridge loans, litigation exposure or obligations to counterparties. An exchange can be over collateralised on tokens and still be in trouble.
- It says nothing about derivatives exposure, unrealised losses on the platform's own positions, or operational risk.
The insurance fund does not insure you
This is the most consistently misunderstood item on any derivatives exchange, and the name is entirely to blame. Bybit maintains an insurance fund for its futures contracts. Many people read that as protection for their money. It is not.
The fund exists to absorb negative equity. When a leveraged position is liquidated at a price worse than its bankruptcy price, the loss exceeds the trader's posted margin and someone has to cover the shortfall so the winning counterparty is paid in full. That is the fund's job. It is financed by Bybit contributions plus the surplus from liquidations that close better than bankruptcy price, and Bybit has added segmented pools for newly listed contracts and correlated portfolios to increase loss absorption capacity.
Read that mechanism again from your own point of view. By the time the insurance fund becomes relevant to your position, your margin is already gone. The fund protects the platform's settlement integrity and the trader on the other side of you. It does not refund you, it does not cap your losses, and it has no relationship whatsoever to your spot balance or to a security incident like the February 2025 theft.
Behind the insurance fund sits auto deleveraging. If liquidation losses in extreme conditions exceed what the fund can cover, Bybit's ADL system force closes profitable positions on the opposite side, starting with the most highly leveraged. If you are on the right side of a violent move, ADL can end your winning trade at the system's price rather than yours. Bybit's segmented pools are designed to make that rarer, and it remains a live risk in a fast market.
The plain summary: no crypto exchange insurance fund, at Bybit or anywhere else, is deposit insurance. There is no equivalent of the EU's €100,000 bank deposit guarantee or the UK's FSCS for crypto held on an exchange.
Leverage and liquidation, stated plainly
On the global platform Bybit offers up to 100x leverage on its deepest perpetual contracts such as BTC and ETH, with the maximum stepping down on smaller pairs and shrinking further as your position size climbs through the risk limit tiers. Positions are held in a Unified Trading Account which can run isolated, cross or portfolio margin, and liquidation triggers on the mark price rather than the last traded price, which prevents a single thin print from closing you out.
None of that engineering changes the arithmetic. At 100x leverage a 1% move against you wipes out the margin behind the position. Which margin mode you are in then decides how much else is exposed. Under isolated margin the loss is capped at the margin you assigned to that position. Under cross or portfolio margin it is not, and a single bad trade can take the rest of the balance in that account with it, so these products can lose you more than the amount you consciously decided to risk. Liquidation is not a warning, it is the position being closed, and in fast markets slippage between the trigger and the actual fill means you can lose the whole margin on a trade that would have recovered minutes later. Funding rates on perpetuals charge you continuously for simply holding a position.
High leverage does not by itself make an exchange unsafe, and it is not a hidden trap. It is simply the most common way people lose money on venues like this, far more common than being hacked. Any honest answer to "is Bybit safe" has to put that in proportion: statistically, the leverage products are a much larger threat to your balance than the security of the exchange holding it. Trading crypto derivatives puts your capital at risk. This page is not investment advice and cannot tell you whether any product is suitable for you.
Withdrawals, compliance holds and frozen accounts
Bybit's withdrawal record during its worst week was excellent, and that deserves weight. Day to day, withdrawals are generally fast, with on chain processing typically within the hour once security checks clear.
The recurring complaint against Bybit is not slow payouts but compliance freezes. Search any review platform and you will find users describing accounts restricted without warning, funds inaccessible during a compliance review, no stated reason, no stated end date, and support tickets that move slowly. Some of these follow deposits traced to sanctioned or high risk sources. The UK designated the exchange HTX under sanctions on 26 May 2026, and users have since reported holds on transfers connected to it, including users who had done nothing knowingly wrong.
Two things should be said about that evidence honestly. Complaint samples are self selecting, because nobody writes a review to report that their withdrawal worked. And compliance holds happen at every KYC'd venue on earth, since they are a legal obligation rather than a business preference. What is fair to criticise is the opacity.
Be careful, too, about who you take advice from here. A cottage industry of "fund recovery" firms markets itself on exactly these complaints, and it has a commercial interest in making exchange freezes sound both universal and reversible for a fee. Treat those sources as advertising.
- Keep on the exchange only what you are actively using, and move long term holdings to a wallet you control. Nothing you hold on an exchange is insured, which is the lesson of February 2025 restated.
- Enable two factor authentication with an authenticator app rather than SMS, set a withdrawal address whitelist, and use an anti phishing code so you can recognise genuine emails.
- Complete verification fully before you deposit anything meaningful, so a KYC gap cannot strand funds later.
- Avoid receiving deposits from unknown counterparties, peer to peer trades with strangers or funds of unclear origin, which is the most common trigger for a compliance hold.
KYC and country restrictions
Bybit's no verification era is over. Identity verification of at least standard level is now mandatory across Bybit products and services, and an unverified account cannot meaningfully trade, deposit or withdraw. Standard verification typically means government ID plus a liveness check and clears within a day for straightforward cases. Higher verification tiers raise withdrawal limits and, for the EEA entity, are simply a legal requirement.
Country coverage changes often, so check on the signup page rather than trusting any list you read online, including this one. As a general picture in 2026: Bybit does not serve the United States, and it is unavailable or restricted in mainland China, Singapore and Canada among others. The United Kingdom is a different case and often reported out of date. Bybit returned to the UK on 19 December 2025, after a two year absence, through an arrangement with Archax, an FCA authorised firm that approves and supervises its financial promotions. That is not an FCA registration for Bybit itself. UK users get spot trading across more than 100 pairs plus peer to peer trading, and no derivatives or leveraged products. EEA residents are served by Bybit EU rather than the global platform. Using a VPN to get around a country restriction is a good way to have an account frozen at the moment you try to withdraw, and the terms allow exactly that.
Signing up through a referral link or code changes none of the above. A sign up reward is a marketing cost, not a safety feature, and it does not offset custody risk, liquidation risk or the possibility of an account restriction. Bybit's standard reward is a small amount of Bitcoin for both sides once qualifying conditions are met, and those conditions change regularly. Judge the exchange first.
So, is Bybit safe? A calibrated answer
The genuinely interesting question is whether an exchange that was breached and made its users whole is safer or riskier than one that has never been tested. There is no clean answer, but there is a defensible one.
What the incident proved, and it did prove it, is that Bybit had the capital, the credit lines and the operational discipline to absorb the largest theft in exchange history without touching customer balances or ever suspending withdrawals. Very few exchanges could have done that, and most of the ones that failed in 2022 stopped withdrawals long before losses of that scale.
What the incident also proved is that a $1.4bn transfer was authorised by humans looking at a screen a third party's compromised laptop could manipulate, and that the money is essentially gone. Surviving a loss is not the same as being unlikely to suffer one. The sector's response, moving away from blind signing towards independent transaction verification, hardware confirmation of transfer details, MPC based custody and off exchange settlement, is genuine progress, but it is progress the whole industry is making rather than a moat any one exchange has built.
So the calibrated position is this: Bybit today is a reasonable choice among large offshore exchanges, with better than average transparency, a proven willingness to eat a loss rather than pass it on, and a real European licence for EEA users. It is not a safe place to store savings, because no exchange is, and custody, counterparty and compliance freeze risk are all live and none of them insured.
The practical answer depends on who you are. If you are an EEA resident who wants spot trading, Bybit EU is a legitimate regulated option under the same MiCA rules as its licensed competitors, so compare fees and asset coverage rather than agonising over the hack. If you came for perpetuals or copy trading and live in the EEA, Bybit currently cannot serve you, and a venue holding both MiCA and MiFID permissions is the more useful place to look. If you are outside the EEA and want leveraged derivatives, Bybit is one of the deepest and most liquid venues available, and you are accepting offshore counterparty risk with no regulator behind you. In every case, hold on the exchange only the balance your trading actually requires.
Get the Bybit bonus
9Q49BO- €10 credited on a first card top-up of €100+
- Up to €110 in 10% cashback on select merchant categories during your first 30 active days
- 100% cashback (up to €50) on eligible subscriptions like ChatGPT, Netflix and Spotify
If you sign up through this page, this site may receive the referrer's side of the reward. This never costs you anything extra.
Browse referral codes
Pages Bybit
Categories Crypto Exchange
Frequently asked questions
Did Bybit users lose money in the 2025 hack?
No. Bybit absorbed the loss on its own balance sheet and no customer balance was reduced. Withdrawals were never suspended, with more than 350,000 requests handled in around ten hours. A queue did build during the bank run, which Bybit acknowledged publicly at the time, and it cleared within about twelve hours. The ETH gap was closed within roughly 72 hours using purchases, bridge loans and counterparty deposits. That was possible because Bybit was large enough and could borrow, not because any insurance or legal guarantee required it.
How was Bybit hacked if the funds were in a cold wallet?
The cold wallet itself was not broken. Attackers compromised a developer machine at Safe{Wallet}, the third party multisignature tool Bybit used to sign transfers, and served malicious code from its interface. Bybit's signers saw a legitimate looking transaction on screen while a different one was submitted. Forensic investigations by Sygnia and Verichains found no evidence that Bybit's own infrastructure was compromised.
Is Bybit regulated in Europe?
Yes, in a specific and limited sense. Bybit EU GmbH holds a MiCA crypto asset service provider authorisation from the Austrian Financial Market Authority, granted by a decision dated 28 May 2025, which passports into 29 EEA states. That authorisation covers custody, exchanging crypto for funds or for other crypto, placing and transfers. It does not cover derivatives, which fall under MiFID rather than MiCA. Non EEA users deal with a different, offshore entity that the Austrian licence does not cover.
Can I trade futures on Bybit in the EU?
Not as of August 2026. From 1 July 2026, when MiCA's transitional period ended, EEA residents were progressively restricted on the global platform and moved to Bybit EU, which launched with spot trading, spot margin, Earn products and the Bybit Card but without perpetual futures or options. A separate Austrian entity, Bybit X GmbH, applied for a MiFID II investment firm licence on 5 September 2025 in order to offer regulated derivatives across the EEA, and that application has not been granted. Until it is, European users who specifically want leveraged derivatives need a venue that already holds both MiCA and MiFID permissions.
Does Bybit's insurance fund protect my money?
No, despite the name. The insurance fund covers negative equity when a leveraged position is liquidated at a price worse than its bankruptcy price, so that the trader on the other side is paid in full. By the time it matters to your position, your margin is already lost. It has nothing to do with your spot balance and nothing to do with security incidents. No crypto exchange offers deposit insurance comparable to a bank guarantee scheme.
Why do people report frozen Bybit accounts?
Most reported freezes are compliance reviews rather than withdrawal failures, commonly triggered by deposits traced to sanctioned or high risk sources, unusual activity, incomplete verification, or transfers linked to platforms under sanctions such as HTX since May 2026. Every KYC'd exchange does this because it is a legal requirement. The fair criticism of Bybit is opacity: users report little explanation and no stated timeline. Complaint samples also skew negative, because satisfied users do not post.