Bybit became the most-Googled exchange-safety question of 2025 after the February 2025 hack — at $1.5B, the largest single theft in cryptocurrency history. The question "is Bybit safe" is reasonable and the honest answer is more nuanced than either the official press releases or the hostile Twitter takes suggest.
What happened in the February 2025 hack
On 21 February 2025, attackers compromised a multi-signature signing flow used by Bybit's cold-storage operations and drained approximately 401,000 ETH (~$1.5B at the time). The attack was attributed to the Lazarus Group / DPRK by multiple independent blockchain-intelligence firms (Elliptic, TRM Labs, Chainalysis) within 48 hours. The attack vector was a UI-spoofing exploit against the Safe{Wallet} multi-sig interface used by Bybit's custody team — not a wallet-key compromise and not a smart-contract bug in Bybit's own systems.
The critical fact for users: every user account was made whole. Bybit covered the loss from corporate reserves and an emergency 30-day credit facility from major industry partners. No user lost a single satoshi to the hack. Withdrawals were paused for less than 12 hours and re-opened to full processing the next morning.
This is the highest possible test of an exchange's operational resilience — and Bybit passed it. By any reasonable standard, an exchange that absorbs a $1.5B loss without passing it to users has demonstrated more capacity to protect customer funds than one that has simply never been tested.
The regulatory picture in 2026
Bybit's regulatory status is uneven across jurisdictions — this is the most important thing for a new user to understand.
Where Bybit operates with full licensing: - UAE — fully licensed by Dubai's VARA (Virtual Assets Regulatory Authority); Bybit's MENA HQ. - Hong Kong — operates under Hong Kong SFC licensing structures via its VATP entity. - Cyprus / EU — MiCA registration is in progress; some EU services operate under transitional arrangements. - Turkey, Brazil, Argentina, Kazakhstan — various national-level registrations.
Where Bybit is restricted, banned, or has been forced to exit: - United States — Bybit does not serve U.S. customers and has not since 2023. U.S. residents using VPN workarounds violate the TOS and forfeit account access. - United Kingdom — FCA non-permissioned; Bybit was removed from FCA's permitted list in 2023. - France — AMF added Bybit to its blacklist for unauthorised provision of services to French residents; later partially regularised under new structure but coverage is limited. - Japan — JFSA warning, not licensed. - Canada (Ontario) — OSC settlement in 2022; Ontario residents not served. - Singapore — DPT licence pending; service restricted for SG retail.
Verdict: Bybit is fundamentally a non-U.S., non-UK exchange. If you live in either, regulated alternatives (Coinbase, Kraken, Gemini in the US; Coinbase UK, Kraken UK, Bitstamp UK) are the safer default.
Day-to-day safety for users
Setting aside the regulatory question, the operational risks for a Bybit user in 2026 look like this:
- Custody risk: Materially the same as any major centralized exchange. Use self-custody for anything not actively trading.
- 2FA / account takeover risk: Comparable to peers. Hardware 2FA (YubiKey via the API security flow) is supported and strongly recommended over SMS.
- Withdrawal-blocking / sudden freezes: Bybit's complaint volume on this is in line with peers — there are some, the cause is usually a sanctions/AML flag on the destination address rather than the exchange acting in bad faith.
- Liquidation engine quality: Derivatives execution is among the best in the industry. This is what most experienced users actually pay for.
- Customer support: Improved meaningfully in 2024–2025; still uneven for non-VIP retail. Be patient and use the in-app ticket flow rather than Telegram (which is the primary fake-support attack vector — see below).
The biggest real risk: clone sites and fake "support"
For most Bybit users in 2026, the largest real risk is not the exchange itself but the ecosystem of clone domains (bybit-login.app, bybit-pro.net, bybit-support.help) and fake support accounts on Telegram and X. These have stolen more from individual Bybit users than the February 2025 hack did from the company.
Three rules that close 95% of this risk:
- The only legitimate domain is bybit.com. Anything else is a clone.
- Bybit support never DMs users on Telegram. Any DM offering "account recovery" is the scam.
- Bybit never asks for your seed phrase, your 2FA backup codes, or remote-control access to your device.
Verdict
For an experienced trader in a jurisdiction Bybit serves with a licence (UAE, HK, Turkey, parts of Asia): safe enough to use, particularly for derivatives. The post-hack response was the strongest test of operational integrity in exchange history and Bybit passed it.
For a U.S. or UK resident: use a domestically regulated alternative. The legal exposure of trading on a non-permissioned exchange (account freezes, no recourse to your regulator, banking-side flags) outweighs any feature advantage.
For everyone: bookmark the real URL, never search the brand name, and treat any "support agent" who DMs you as a scammer until proven otherwise. Before logging in to any exchange, paste the URL into the GACS Safe Scanner — four seconds, free, no signup, cross-checked against the real exchange registry and our 250k-entity blacklist.
