With Bitcoin trading near $63,000 in mid-2026, more people than ever are holding meaningful balances on centralized exchanges, and the question “is this platform actually safe?” deserves a real answer rather than a marketing one. Bybit is a particularly interesting test case because it isn’t a theoretical safety question — in February 2025, it suffered the largest exchange hack in crypto history, losing roughly $1.5 billion in ETH from a single cold wallet transaction. What happened afterward, and what’s changed since, tells you more about the platform’s actual risk profile than any list of security badges on a landing page. This article walks through Bybit’s custody model, proof-of-reserves practices, KYC tiers, account protection tools, and the regulatory actions taken against it across multiple countries — then gives a direct verdict rather than a hedge. If you’re also tracking where Bitcoin might be headed next, the Free BTC AI Predictor is a useful reference point while you read.
Recommended exchange
Bybit
800+ coins on spot at 0.10%, USDT perps at 0.02% maker / 0.055% taker, free Grid/DCA/Combo bots, copy trading, TradFi CFDs (SpaceX xStocks, Apple, NVIDIA), and Unified Trading Account. Not available to US, Canada, UK, Singapore, Hong Kong, or Mainland China residents — EEA users use bybit.eu instead.
The 2025 Hack: What Actually Happened
On February 21, 2025, attackers compromised Bybit’s cold wallet transfer process during a routine multisig transaction and redirected approximately $1.5 billion worth of Ethereum to addresses under their control. Investigators, including the FBI and multiple blockchain forensics firms, attributed the attack to North Korean state-linked actors, consistent with a pattern of large-scale crypto thefts used to fund sanctioned programs. This wasn’t a simple password leak or phishing attack on individual users — it was a sophisticated compromise of the signing and verification process itself, which is precisely why it’s treated as one of the most technically significant incidents in exchange history rather than a routine breach.
The part of the story that gets less attention than the theft itself is the response. Bybit publicly disclosed the incident almost immediately, did not halt withdrawals, and within about 72 hours had closed the entire $1.5 billion gap using a combination of its own reserves, bridge loans, and loans from other institutions willing to extend credit on short notice. CEO Ben Zhou communicated directly and frequently during the crisis, a contrast to the silence or evasive statements that have characterized other exchange failures. No user lost funds as a direct result of the hack — the loss was absorbed entirely by the company itself. That’s a genuinely rare outcome in exchange-hack history, and it’s the single most important fact anyone evaluating Bybit’s safety in 2026 should understand clearly before forming an opinion either way.
It’s worth putting this in context against how other major exchange failures played out. When FTX collapsed in 2022, customer funds had been commingled and largely spent, leaving users waiting years for partial recovery through bankruptcy proceedings. When Mt. Gox was hacked in 2014, the exchange folded outright and clawback proceedings dragged on for the better part of a decade. Bybit’s situation was different in a structurally important way: the hack was an external attack on a specific transaction, not a case of internal fraud or missing reserves, and the company had — or was able to rapidly raise — enough capital and goodwill in the market to make users whole almost immediately rather than after years of litigation. That’s not an argument that the hack doesn’t matter; it’s an argument that the appropriate comparison set is other hacks, and against that comparison set, Bybit’s response was unusually fast and unusually complete.
The attack also prompted an unusual show of solidarity across the exchange industry, with several competitors publicly extending short-term liquidity support to help Bybit meet withdrawal demand during the most acute phase of the crisis. That’s a detail that rarely shows up in hack retrospectives but matters for assessing systemic risk: the broader industry treated a Bybit failure as a shared reputational risk worth preventing, which is a different dynamic than the isolated collapses of the past.
Proof-of-Reserves and Cold Storage Practices
Bybit publishes proof-of-reserves data intended to let users verify that customer assets are backed on a roughly 1:1 basis, using Merkle-tree verification methods that let individual users check their own balance is included in the audited snapshot without exposing other users’ data. This system existed before the 2025 hack, but the incident clearly increased scrutiny of it, and Bybit has since leaned harder into public reserve reporting as a trust-rebuilding tool. It’s worth being honest about the limits of proof-of-reserves as a concept industry-wide: it verifies assets exist at a point in time, not that liabilities are fully disclosed or that operational security is airtight — the 2025 hack itself happened to an exchange that already published reserve attestations. Proof-of-reserves is a necessary transparency measure, not a complete safety guarantee, and treating it as the latter is a mistake.
On cold storage specifically, the industry standard — and the one Bybit aims for — is keeping the large majority of customer funds offline in cold wallets, with only a small operational float held in hot wallets for processing withdrawals. The 2025 hack specifically compromised a cold wallet transfer, which is an important nuance: cold storage reduces exposure to routine hacking but does not eliminate risk when the wallet is moved during a legitimate operational transaction, since that’s exactly the moment signing keys and approval processes come into play. Since the incident, Bybit has stated it tightened multisignature approval workflows and transaction verification steps specifically to close the gap that was exploited. There’s no independent third-party audit result publicly available that would let an outside observer fully verify these claims, which is a fair caveat for any user weighing how much trust to extend.
The attack vector itself is instructive for understanding what “cold storage” does and doesn’t protect against. Investigators concluded that attackers manipulated the user interface of the multisig wallet signing process, effectively tricking legitimate signers into approving a malicious transaction that looked identical to a routine transfer. This is sometimes called a blind-signing exploit, and it’s a known weak point across the industry, not a flaw unique to Bybit. The lesson for the exchange, and one it says it has acted on, is that cold storage security depends as much on the verification tooling used during the rare moments funds move as it does on where funds sit the rest of the time. Any exchange, custodian, or institutional wallet provider relying on multisig without independently verified transaction display tooling carries a similar exposure, which is why this incident triggered a broader industry conversation about signing infrastructure rather than being dismissed as a Bybit-specific failure.
Recommended exchange
Bybit
800+ coins on spot at 0.10%, USDT perps at 0.02% maker / 0.055% taker, free Grid/DCA/Combo bots, copy trading, TradFi CFDs (SpaceX xStocks, Apple, NVIDIA), and Unified Trading Account. Not available to US, Canada, UK, Singapore, Hong Kong, or Mainland China residents — EEA users use bybit.eu instead.
KYC Tiers, 2FA, and Withdrawal Whitelisting
Bybit uses a tiered KYC system: unverified or Level 0 accounts face tight withdrawal limits and restricted product access, while Level 1 and Level 2 verification (typically government ID plus proof of address, sometimes with a liveness check) grant access to higher limits and the full product suite including derivatives and TradFi CFDs. This tiered approach is standard across major exchanges and exists both for regulatory compliance and fraud prevention — the more identity information on file, the harder it is for a compromised account to be drained anonymously.
Two-factor authentication is available via authenticator apps and, in some regions, SMS, though app-based 2FA is materially more secure and should be the default choice — SMS-based 2FA is vulnerable to SIM-swap attacks that have drained accounts on other platforms in the past. Withdrawal address whitelisting is one of the more underused protections available: once enabled, withdrawals to new, non-whitelisted addresses are delayed or blocked, giving you a window to notice and stop an unauthorized withdrawal attempt even if your login credentials are compromised. Sub-account isolation is another meaningful safety feature for higher-volume users — funds and API keys in one sub-account are walled off from others, so a compromised API key tied to a trading bot on one sub-account doesn’t expose your entire balance. None of these tools protect you if you don’t turn them on, which is worth repeating because so many account compromises industry-wide trace back to skipped, not broken, security settings.
Worth calling out specifically: withdrawal limits scale with KYC level, and Bybit, like most large exchanges, applies additional friction to large or unusual withdrawal patterns as an anti-fraud measure. This can be mildly annoying if you’re a legitimate high-volume trader who trips a fraud flag, but it exists precisely to slow down attackers who’ve gained account access and are trying to move funds out quickly before the account owner notices. If you plan to move large balances regularly, it’s worth verifying to the highest KYC tier in advance rather than discovering a withdrawal limit mid-transaction, and it’s worth keeping your registered email and phone number current since most fraud-flag resolution flows route through those channels.
Insurance Funds and What They Actually Cover
Bybit maintains an insurance fund designed primarily to cover shortfalls from liquidation events in derivatives trading — specifically, situations where a liquidated trader’s position closes at a worse price than their remaining margin can cover, creating a deficit that would otherwise be socialized across profitable traders through auto-deleveraging. This is a different mechanism from deposit insurance in traditional banking, and it’s a distinction retail users frequently misunderstand. The insurance fund is not a blanket guarantee against exchange insolvency, hacking losses, or platform failure — the 2025 hack recovery was funded from Bybit’s broader corporate reserves and financing arrangements, not from the derivatives insurance fund specifically. If you’re mentally modeling Bybit’s safety net, separate “protection against a bad liquidation cascade” from “protection against exchange-level catastrophe,” because they’re covered by different mechanisms with very different scopes.
Traders who rely heavily on high leverage should pay particular attention to how the insurance fund’s balance is disclosed and how auto-deleveraging ranks traders when the fund is insufficient to cover a shortfall. In practice, this matters most during extreme volatility events — a sudden 20% move in a major asset can trigger cascading liquidations across an entire exchange simultaneously, and the size of the insurance fund relative to open interest determines whether profitable traders get their full gains or face partial auto-deleveraging. This is a standard feature of the derivatives market structure industry-wide, not a Bybit-specific weakness, but it’s exactly the kind of mechanic that only becomes visible — and painful — during the tail-risk events it exists to manage.
Past Regulatory Actions Against Bybit
A safety assessment that ignores regulatory history is incomplete. Bybit has faced a series of jurisdiction-specific restrictions over the past two years: it was formally excluded from serving Japan as of December 2025, faced regulatory friction in France in January 2025, and encountered restrictive actions in Singapore stemming from unlicensed operation concerns. Thailand’s SEC moved against Bybit in June 2025, Malaysia’s Securities Commission took action in December 2024, and the Philippines’ SEC issued a restriction in August 2025. None of these actions allege that user funds were stolen or mishandled by Bybit directly — they generally center on operating without local licensing or registration, which is a compliance issue rather than a solvency or custody issue. That distinction matters, but it doesn’t make the pattern irrelevant: a growing list of regulators declining to license Bybit domestically is a signal that the exchange’s global-first, license-later approach carries real friction, and users in any of these markets should not assume continued access is guaranteed.
Who Should Trust Bybit — and Who Shouldn’t
If you live in a country where Bybit operates without restriction — much of Latin America, the Middle East, parts of Africa, and large parts of the Asia-Pacific region — the honest assessment is that Bybit is reasonably safe by industry standards: it demonstrated real financial resilience during a catastrophic hack, it maintains proof-of-reserves reporting, and it offers the standard suite of account protections if you actually enable them. It is not the safest possible choice in an absolute sense — no exchange with hot wallets and complex smart contract integrations can claim that — but it compares favorably to exchanges that have failed outright and left users with nothing.
If you’re in the United States, United Kingdom, or Canada, the safety question is moot because Bybit doesn’t serve you regardless of your risk tolerance. If you’re in the EEA, the relevant entity is bybit.eu under its Austrian MiCA license, which is a different regulatory wrapper with its own protections and is not the platform most reviews (including the affiliate links on this site) are actually discussing. If your country is one of the several that have taken direct regulatory action against Bybit — Japan, Thailand, Malaysia, the Philippines, or Singapore — you should weigh that local regulatory stance seriously rather than dismissing it, even if the platform remains technically accessible in some form.
For traders across Latin America, the Middle East, Africa, and much of the Asia-Pacific region where Bybit operates without formal restriction, the practical safety calculus comes down to two things: whether you personally enable the account protections available to you, and whether you size your exchange balance appropriately relative to your total portfolio. A trader keeping a working balance for active positions and moving profits to cold self-custody periodically is taking on meaningfully less custodial risk than someone treating Bybit as a long-term savings account. Neither approach is “wrong,” but they carry different risk profiles, and understanding which one you’re actually running is more useful than a binary safe-or-not-safe judgment.
Common Mistakes That Undermine Your Own Safety
The most common mistake isn’t a Bybit failure at all — it’s users skipping app-based 2FA, ignoring withdrawal whitelisting, and reusing passwords across exchanges, all of which shift risk from the platform to the individual account. A second mistake is confusing proof-of-reserves with a full financial audit; they answer different questions, and treating one as the other creates false confidence. A third is assuming the insurance fund covers everything — it specifically addresses derivatives liquidation shortfalls, not broader custodial risk. Finally, some users keep their entire portfolio on any single exchange, Bybit included, rather than splitting significant holdings between an exchange and self-custody. Given that even a well-capitalized, well-run exchange proved vulnerable to a $1.5 billion cold wallet compromise in 2025, treating any centralized platform as a long-term vault rather than a trading venue is a risk worth reconsidering regardless of which exchange you use.
A fifth mistake, more subtle than the others, is assuming that because an exchange has a large user base and high trading volume, it must have passed some equivalent of a banking-grade safety review. Trading volume reflects liquidity and market trust, not a regulatory safety certification, and the two are often conflated by users comparing exchanges purely on size. A sixth mistake is ignoring official communication channels during a security event and instead relying on social media speculation, which spread significant misinformation during the 2025 hack before Bybit’s own statements caught up. Bookmarking the exchange’s official status and announcement pages before you need them, rather than during a crisis, is a small step that pays off disproportionately when it matters.
Verdict: Safe for Supported Jurisdictions, With Real Caveats
Bybit is safe in the sense that matters most to a prospective user: it has demonstrated it can absorb a worst-case security event without transferring losses to customers, it maintains reserve transparency tools, and it offers a standard set of account-level protections. It is not safe in the sense of being risk-free — the 2025 hack happened to a platform that already had reserve attestations and multisig controls in place, which is a sober reminder that no amount of published security marketing eliminates operational risk entirely. It’s also not universally available or universally welcomed by regulators, with real restrictions in the US, UK, Canada, several EU-adjacent contexts requiring the separate bybit.eu entity, and formal regulatory actions in Japan, Thailand, Malaysia, the Philippines, and Singapore. For users in supported regions who enable the available protections and don’t treat any single exchange as a permanent vault, Bybit’s 2026 safety profile is reasonable — better in some ways than several competitors, meaningfully behind a hypothetical ideal, and worth continued attention as regulatory and security developments unfold.
Recommended exchange
Bybit
800+ coins on spot at 0.10%, USDT perps at 0.02% maker / 0.055% taker, free Grid/DCA/Combo bots, copy trading, TradFi CFDs (SpaceX xStocks, Apple, NVIDIA), and Unified Trading Account. Not available to US, Canada, UK, Singapore, Hong Kong, or Mainland China residents — EEA users use bybit.eu instead.
FAQ
Did Bybit lose customer funds in the 2025 hack?
No customer directly lost funds. Bybit absorbed the roughly $1.5 billion shortfall using its own reserves and short-term financing within about 72 hours, and withdrawals remained operational throughout the incident.
What is proof-of-reserves and does Bybit have it?
Proof-of-reserves is a Merkle-tree-based system letting users verify their balance is included in an audited snapshot of exchange assets. Bybit publishes this data, though it verifies assets at a point in time rather than guaranteeing operational security.
Is Bybit regulated?
Bybit operates under a patchwork of regional licenses rather than a single global regulator. Its EU-facing entity, bybit.eu, holds an Austrian MiCA license. It has also faced exclusion or restriction in Japan, France, Singapore, Thailand, Malaysia, and the Philippines.
Does Bybit have deposit insurance like a bank?
No. Bybit’s insurance fund covers shortfalls from derivatives liquidation events, not broad custodial insolvency or hacking losses. The 2025 hack recovery came from corporate reserves and financing, not this fund.
Can US, UK, or EU residents use Bybit safely?
US, UK, and Canadian residents cannot open accounts at all. EEA residents must use the separate bybit.eu entity, which operates under different terms and is not the platform typically referenced by affiliate reviews of Bybit.
What security settings should every Bybit user enable?
App-based two-factor authentication, withdrawal address whitelisting, and sub-account isolation for API keys tied to bots. These are optional but meaningfully reduce the risk of account-level compromise.
Why was Bybit excluded from Japan in December 2025?
Japan’s regulators moved to exclude Bybit from serving the market as part of broader licensing enforcement against exchanges operating without full local registration, a pattern seen in several other jurisdictions around the same period.
Is it safe to keep large crypto balances on Bybit long term?
Any centralized exchange carries custodial risk, as the 2025 hack demonstrated even at a well-resourced platform. Most security-conscious users treat exchanges as trading venues and move significant long-term holdings to self-custody.
Related on NeuralMindMastery
For a full breakdown of fees and products, see our complete Bybit review for 2026. If you’re weighing US-compliant alternatives with strong security track records, our Coinbase Advanced API trading guide is a solid next read, alongside our Stoic AI review for automated strategy considerations. To estimate how your positions might respond to security-driven volatility, try our AI ROI calculator.