Last Updated: July 19th, 2026|45 mins

Is Bybit Safe in 2026? Security, Proof of Reserves and User Risks

Analysis

Bybit has rebuilt its reserves, expanded its regulatory footprint and strengthened account controls since the 2025 hack. But that does not make the exchange risk-free.

This guide examines Bybit’s security systems, Proof of Reserves, regulation, withdrawal risks and product-level dangers to determine who should use it, and who should keep their distance.

Editor's Note (July 19, 2026): We fully updated this article in July 2026 to reflect Bybit's latest security controls, Proof of Reserves assessment, regulatory status, withdrawal policies and product risks. We also expanded our analysis of the 2025 hack, clarified the difference between recovered assets and replenished reserves, and added practical guidance for traders, long-term holders and users facing account restrictions.

Quick Verdict: Is Bybit Safe in 2026?

Yes, Bybit is a legitimate and regulated exchange, but it is not risk-free.

Its account-security toolkit is broad, with passkeys, Google Authenticator 2FA, a Fund Password, Secure Transaction Approval, trusted-device controls, withdrawal locks and anti-phishing codes. Bybit also publishes monthly Proof of Reserves with third-party verification for the assets and liabilities included within each assessment.

The 2025 custody theft remains the biggest weakness in its security record. Bybit restored reserve coverage without haircutting customer balances, but reserve replenishment is not the same as recovering every stolen asset. Bybit is best used for active trading in supported jurisdictions rather than permanent storage of long-term holdings.

Bybit Safety: Quick Answers

These answers summarize Bybit's legitimacy, reserve position, custody limits and suitability for different storage needs.

Question Quick Answer
Is Bybit legitimate? Yes, it is an established exchange with regulated regional entities.
Is Bybit hack-proof? No exchange is hack-proof.
Did Bybit restore reserves after the 2025 hack? Yes, but that does not mean all stolen assets were recovered.
Does Bybit have Proof of Reserves? Yes, with third-party verification for assets within scope.
Are deposits insured like a bank account? No.
Is Bybit suitable for long-term storage? Self-custody is generally safer for assets not being actively traded.

Bybit Safety by User Type

Bybit is easier to justify when its trading infrastructure serves a clear purpose and the user keeps only a controlled operating balance on the exchange.

User Type Safety Verdict Main Risk Safer Approach
Beginner buying BTC or ETH Usable Platform complexity and custody Use spot trading and avoid leverage
Active spot trader Strong Fit Account compromise and exchange custody Enable all account controls and limit balances
Derivatives trader High Product Risk Leverage, liquidation and funding Use isolated margin and strict position limits
P2P user Use Caution Fake receipts and banking disputes Confirm cleared funds before releasing crypto
Long-term holder Not Ideal Long-term custodial exposure Use Bybit as an on-ramp, then withdraw
Institution or treasury Requires Due Diligence Legal, custody and counterparty exposure Apply independent legal and financial controls

Safety assessments reflect Bybit's platform structure, reserve evidence, regulatory position, incident history and common product risks. They are not a guarantee against hacks, account restrictions, market losses, liquidation, compliance reviews or user-security failures.

Disclosure

Some links in this guide may be affiliate links. If you choose to use a service through these links, we may earn a commission at no additional cost to you.

bybit_inline

How We Assessed Bybit's Safety

A useful safety review has to separate platform security from financial transparency, regulation, account access and product risk. A secure trading engine can still offer highly risky derivatives, while a well-capitalized exchange can still restrict an account during a compliance review.

This assessment treats Bybit as a custodial trading platform rather than judging it by trading volume, market share or marketing claims.

Safety CategoryRatingWhat Is Being Assessed
Platform securityModerateWallet architecture, transaction approvals, incident response and post-attack controls
Solvency evidenceStrong within scopeProof of Reserves, included liabilities, wallet ownership and audit limitations
RegulationModerateLicenses, legal entities, regional rules and available complaints routes
Account protectionStrongPasskeys, 2FA, withdrawal locks, device approval and phishing controls
Access to fundsModerateWithdrawals, compliance checks, security holds and support escalation
Product riskModerate overallSpot, derivatives, P2P, Earn, copy trading, bots and Wallet risks

Bybit’s account-security toolkit is broad, but the exchange still controls customer assets. Its Proof of Reserves provides meaningful snapshot evidence, but it does not reveal the company’s complete financial position.

What Happened in the 2025 Bybit Hack?

The 2025 attack exposed a failure in the transaction-signing chain rather than a simple breach of a customer login or an online hot wallet.

What Happened in the 2025 Bybit Hack?Inside the 2025 Hack and Bybit’s Reserve Response

How the Bybit Hack Happened

On Feb. 21, 2025, attackers stole approximately $1.5 billion in virtual assets from an exchange-controlled Ethereum cold wallet while Bybit was conducting a routine transfer to a warm wallet.

The transaction appeared legitimate to Bybit’s signers through the interface they were using. The instructions behind that transaction were malicious and allowed the attacker to take control of the wallet before moving the assets across multiple addresses.

Safe’s forensic review found that a Safe Wallet developer machine had been compromised. That compromise allowed the attacker to prepare a disguised malicious transaction for Bybit’s signers.

The investigation did not identify Safe’s smart contracts or public frontend source code as the underlying vulnerability. The failure sat in the signing environment and the way the transaction was presented for approval.

Cold storage reduced routine online exposure, but it could not protect the wallet once authorized signers were shown misleading transaction information. A multisignature arrangement only works as intended when each signer can independently confirm the real destination, permissions and effects of the transaction.

The FBI attributed the theft to North Korean actors operating under the TraderTraitor designation. The activity is commonly associated with the Lazarus Group, although the FBI notice used TraderTraitor as the formal operation name.

Did Bybit Customers Lose Their Balances?

No, Bybit reported that customer balances were not haircut. The theft came from an exchange-controlled Ethereum wallet, leaving the company responsible for replacing the missing reserve assets rather than deducting the loss from individual accounts.

The exchange also kept withdrawals operational while processing an exceptional surge in withdrawal requests. That response offered practical evidence of available liquidity and crisis-management capacity under pressure.

Keeping withdrawals open then also does not guarantee the same result after another incident.

Replenished Reserves Are Not Recovered Assets

Bybit restored reserve coverage by replacing the missing ETH through emergency liquidity, bridge loans, institutional support, OTC purchases and market acquisitions.

Its incident timeline reported that the ETH reserve gap was closed within roughly 72 hours. That restored the asset backing behind customer liabilities.

It did not mean the attackers returned all the stolen assets.

TermMeaning
Asset recoveryStolen assets are traced, frozen, seized or returned to the victim
Reserve replenishmentThe exchange replaces missing assets through its own liquidity, borrowing, purchases or external counterparties

Some stolen funds were later traced or frozen, but reserve coverage was restored before full asset recovery. In short, Bybit replenished its reserves and restored reserve coverage.

What Bybit Changed After the Attack

The post-attack response focused on reducing the chance that a deceptive signing interface could again push a high-value transaction through the approval chain.

The security-relevant changes and controls include:

  • Revised wallet-signing procedures: High-value transfers require a clearer separation between the party preparing the transaction and the people approving it. That reduces the chance that every signer relies on the same compromised view.
  • Independent transaction verification: The destination address, contract call, asset amount and resulting wallet permissions need to be checked through a separate channel before signing. A second screen or verification tool is only useful when it does not depend on the same compromised interface.
  • Stronger signer-device controls: Signer devices should be dedicated, tightly permissioned and isolated from ordinary browsing, messaging and development activity. Device isolation reduces the number of ways malware or stolen credentials can reach the approval process.
  • High-value transfer approvals: Large withdrawals and treasury transfers should face stricter thresholds than ordinary operational movements. More signers, longer review windows and out-of-band confirmation create friction where a mistake would be exceptionally costly.
  • Wallet-movement monitoring: Monitoring systems should flag unusual destinations, sudden permission changes, abnormal transaction sizes and activity that differs from the wallet’s normal behavior. Detection does not stop every attack, but it can shorten the time between execution and response.
  • Counterparty and infrastructure reviews: Wallet providers, signers, developers and other infrastructure partners become part of the exchange’s security perimeter. Reviewing their access, devices and incident procedures is as relevant as reviewing Bybit’s internal controls.
  • Reserve verification: Bybit continued publishing Proof of Reserves and engaged Hacken to assess included liabilities, wallet ownership and Merkle-tree integrity. This does not prevent another attack, but it improves visibility into whether covered liabilities remained backed at each snapshot.

Safe also reported rebuilding parts of its infrastructure and rotating credentials after identifying the compromised developer machine.

Read our full Bybit review.

Also Read

How Bybit Protects Its Platform and User Accounts

Bybit combines exchange-level wallet controls with security tools that users must activate themselves. The first layer protects platform infrastructure. The second reduces the chance that a stolen password, compromised email or unknown device can control an individual account.

How Bybit Protects Its Platform and User AccountsHow Bybit Secures Wallets, Accounts, Devices, and APIs

Exchange Wallet and Transaction Security

Bybit describes a wallet architecture built around cold storage, restricted hot-wallet exposure and distributed transaction approval.

The main controls serve different purposes:

  • Cold and hot wallet separation: Cold wallets keep larger reserves away from continuously connected systems, while hot wallets hold the liquidity needed for day-to-day withdrawals. This reduces the amount exposed through an ordinary online breach, but it cannot protect a cold wallet from a malicious transaction approved by authorized signers.
  • Multi-signature controls: A multisignature wallet requires several approvals before funds can move. It reduces dependence on one person or device, although every signer can still approve the same disguised instruction if they rely on a compromised interface.
  • Threshold Signature Schemes: TSS distributes the signing process so that no single participant holds the complete usable key. This can reduce key-theft risk, but the participants can still jointly authorize the wrong transaction.
  • Trusted Execution Environments: A TEE isolates sensitive signing operations from the wider device environment. Its protection depends on correct implementation, device security and the integrity of the information entering the secure environment.
  • Signer separation: The people or systems creating a transaction should not be the only ones validating it. Independent roles make it harder for one compromised account or device to control the full process.
  • Transaction simulation: Simulation shows what a proposed transaction will do before it is signed. It can reveal a hidden contract call, asset transfer or permission change, provided the simulation itself is independent and accurate.
  • High-value transfer approval: Large treasury movements should face additional signers, longer review and separate confirmation channels. The purpose is to slow down the transactions where one mistake could produce an existential loss.
  • Unusual-wallet monitoring: Monitoring can flag large transfers, unknown destinations, repeated failed approvals or abnormal contract interactions. Alerts are most useful when they trigger an immediate pause or manual review rather than simply recording the event.

Cold storage reduces online exposure. It does not prevent insider activity, compromised signing interfaces, incorrect transaction approval or failures inside third-party wallet infrastructure.

A safer setup combines distributed signing with independent simulation, destination verification, signer separation and stricter approval rules for unusually large transactions.

Account Security Features

Bybit's lists Google Authenticator 2FA, a Fund Password, passkeys, Secure Transaction Approval, anti-phishing codes, trusted-device management, the New Address Withdrawal Lock and account deactivation. The mobile app also provides App Lock through a pattern or biometric check.

Security FeatureWhat It Protects AgainstMain Limitation
PasskeyPassword theft and many phishing attacksDevice recovery and backup still require planning
Google 2FAAccess using a stolen passwordCodes can still be phished or socially engineered
Fund PasswordUnauthorized withdrawals and sensitive changesWeak protection if reused, shared or stored insecurely
Secure Transaction ApprovalHigh-risk actions initiated from other devicesDepends on the security of the primary device
New Address Withdrawal LockImmediate withdrawals to newly added addressesExisting approved addresses still require review
Anti-Phishing CodeFake emails and text messagesDoes not identify a fake website opened directly
Trusted DevicesUnknown devices retaining account accessUsers must review the list regularly
App LockCasual or unauthorized access to the mobile appDoes not protect a fully compromised phone
Account DeactivationContinued activity after suspected compromiseTemporarily removes the user’s own access as well
  • A passkey uses FIDO-based credentials tied to a trusted device and can resist many password-phishing attacks. Recovery is the weak point. Losing the only authorized device without a prepared backup route can turn strong security into an access problem.
  • Google Authenticator 2FA adds a second credential beyond the login password. The same protection should be enabled on the email account linked to Bybit because control of that inbox can help an attacker reset other account controls.
  • The Fund Password is separate from the login password and is used for withdrawals and sensitive security changes. Reusing the same password defeats that separation.
  • Secure Transaction Approval lets the user designate a primary phone for high-risk approvals. A withdrawal or sensitive action initiated elsewhere must then be reviewed on that primary device.
  • The New Address Withdrawal Lock creates a waiting period before recently added addresses can receive funds. It reduces the value of an attacker quickly adding a new destination, but it does not protect against an old address that is already approved and no longer trustworthy.
  • An anti-phishing code appears in official Bybit emails and messages. Its absence or an incorrect code can expose an impersonation attempt. It cannot protect users who reach a fake login page through search results, malicious advertising or a direct message.
  • Trusted-device management shows which devices retain account access. Removing old phones, browsers and computers closes sessions that may otherwise remain valid longer than the user expects.
  • Account deactivation gives the user an emergency stop when compromise is suspected. It can prevent continued activity, although the legitimate owner must then complete recovery steps before regaining access.
  • App Lock adds another barrier when someone has physical access to the phone. It helps against casual access, but not against malware or a fully compromised operating system.

API and Device Security

A compromised API key can place unwanted trades even when the attacker cannot log in normally. Derivatives permissions make the damage worse because the attacker may open leveraged positions, move the account into manipulated markets or leave exposure unmanaged.

Users should:

  • Disable withdrawal permissions: Most trading tools need to read data and place orders, not remove assets. Transfer access creates a direct route to fund loss.
  • Use IP restrictions where supported: Limiting requests to approved server addresses makes a stolen key less useful from another location. It does not help when the approved server itself is compromised.
  • Create one API key per service: Separate keys make it easier to identify which integration caused a problem and revoke only the affected connection.
  • Use subaccounts for bots: A dedicated subaccount limits the balance and positions one automated strategy can reach. It also separates manual trading from bot activity.
  • Review derivatives permissions: A portfolio tracker does not need futures access. Granting unnecessary leverage permissions expands the possible damage from a compromised key.
  • Delete inactive keys: An abandoned integration remains an attack path even when the user has forgotten it exists.
  • Revoke old devices and sessions: Previous phones, browsers and computers may retain access long after they stop being used.
  • Secure the email account: Password resets, withdrawal notices and support communication often pass through email. A weak inbox can undermine stronger exchange settings.
  • Avoid unknown browser extensions: Extensions can read pages, capture credentials or alter what appears on screen. Trading accounts should not share a browser profile with untrusted extensions.
  • Remove unnecessary remote-access software: Remote desktop tools give an attacker the same visibility and control as the user if those tools are compromised.

Bybit’s API-key setup supports API trading through standard subaccounts while keeping deposits and withdrawals under the main account. This separation can reduce the capital and functions exposed to one service.

For a broader account-security framework, our crypto safety guide covers phishing, malware, remote-access attacks and recovery-seed risks beyond Bybit itself.

Bybit Security Checklist

Complete these steps before depositing a meaningful balance:

  1. Create a unique password. Do not reuse an email, banking or exchange password.
  2. Secure the email account with separate 2FA. The connected inbox is part of the exchange-security perimeter.
  3. Add a passkey. Prepare a recovery route before relying on a single device.
  4. Enable Google Authenticator 2FA. Keep recovery information offline.
  5. Create a Fund Password. Make it different from the login password.
  6. Activate Secure Transaction Approval. Use the most secure phone as the primary approval device.
  7. Add an anti-phishing code. Treat any message without the correct code as suspicious.
  8. Review trusted devices. Remove anything old, unknown or unnecessary.
  9. Enable withdrawal-address controls. Review existing approved addresses before relying on the lock.
  10. Audit API permissions. Remove transfer access and derivatives access when they are not needed.
  11. Make a small test withdrawal. Confirm the network, address and approval workflow before moving a larger balance.
  12. Keep backup authentication methods offline. Do not store every recovery method in the same device or cloud account.

Does Bybit Have Proof of Reserves?

Yes. Bybit publishes monthly proof of reserves, and its June 24, 2026 snapshot, the most recent one available as of July 19, 2026, shows reserve ratios well above 100%

Does Bybit Have Proof of Reserves?What Bybit’s Latest Proof of Reserves Actually Establishes

Latest Bybit Proof of Reserves Assessment

Hacken completed a Proof of Reserves assessment using an June 24, 2026 snapshot.

The assessment found full 1:1 coverage for customer liabilities linked to every asset within scope. It examined:

  • Proof of Liabilities: The report reviewed the customer-balance data used to calculate the liabilities Bybit owed for the included assets.
  • Wallet ownership: Hacken assessed whether Bybit controlled the on-chain wallets presented as reserves.
  • Reserve calculations: The auditors compared the value and quantity of included reserves with the corresponding customer liabilities.
  • Merkle-tree generation: The review examined how customer balances were converted into the Merkle structure used for individual verification.
  • Merkle-proof validation: The report tested whether users could verify inclusion without exposing every account balance publicly.
  • Included loan liabilities: The calculation considered the loan obligations included within the assessment scope rather than looking only at simple spot balances.

The scope covered more than 65 million liability holders and a specified group of crypto assets and networks. Every included collateral ratio exceeded 100% in the report.

What the Assessment Helps Prove

The report helps establish that:

  • Bybit controlled the audited wallet addresses: Wallet-ownership tests supported the claim that the exchange had control of the on-chain reserves shown in the report.
  • Included reserves covered included liabilities: The assets within scope exceeded the corresponding customer obligations at the snapshot time.
  • The liability calculation was reviewed: Hacken examined the relationship between the liability data and the Merkle-tree output rather than relying only on a list of wallets.
  • The Merkle process was tested: The generation, root calculation and verification process underwent code and data checks.
  • Users can check balance inclusion: An account holder can verify whether their covered balance appeared in the liability tree used for that snapshot.

This provides stronger evidence than a simple public wallet list. Wallet balances show assets. They do not show how much the exchange owes customers unless liabilities are also included.

What Proof of Reserves Does Not Prove

The report does not provide complete assurance about:

  • Every corporate asset: The assessment covers specified reserve wallets rather than every asset owned by every Bybit entity.
  • Every corporate liability: Corporate borrowing, trade payables and other off-chain obligations may sit outside the Proof of Reserves scope.
  • Off-chain borrowing: Loans or financing arrangements that do not appear on-chain are not automatically visible through wallet verification.
  • Asset encumbrances: A wallet can contain assets that are pledged, borrowed against or subject to another legal claim.
  • Future reserve positions: The report reflects one snapshot. Assets can move after the measurement time.
  • Every listed cryptocurrency: Only the assets and networks named in the report receive that particular assessment.
  • Company profitability: Reserve coverage does not show whether the business is profitable, cash-flow positive or operationally sustainable.
  • Legal segregation of user assets: Proof of Reserves does not determine how customer assets would be treated in bankruptcy.
  • Deposit-insurance protection: A reserve ratio above 100% does not create government-backed compensation.
  • Overall insolvency risk: Solvency depends on the full set of assets, liabilities, legal claims and liquidity demands, not one reserve snapshot.

Hacken describes the report as a point-in-time attestation rather than a comprehensive audit of Bybit’s complete financial position.

To summarize, Bybit's specified on-chain reserves covered specified liabilities as of June 24, 2026.

Can Users Verify Their Own Balance?

Users can check whether their balance was included in the relevant snapshot:

  1. Open Bybit’s Proof of Reserves area.
  2. Select the relevant snapshot date.
  3. Locate the Merkle leaf, verification ID or balance record attached to the account.
  4. Run the verification process.
  5. Confirm that the covered balances appear in the liability tree.
  6. Check which assets and networks were included.
  7. Compare the result with the corresponding third-party report.

A successful verification shows that the balance was included in that snapshot’s liability calculation. It does not prove that the same reserve position exists today.

What Bybit's Insurance Fund Covers

Bybit’s derivatives insurance fund is designed to absorb certain deficits created when a liquidated position closes beyond its bankruptcy price.

When a trader’s remaining margin cannot cover the full loss, the insurance fund may absorb the shortfall. This reduces the frequency with which Auto-Deleveraging must reduce profitable positions held by other traders.

The insurance fund:

  • Supports the derivatives liquidation system
  • Covers specified liquidation deficits
  • Can reduce reliance on Auto-Deleveraging
  • Is funded through platform contributions and surplus liquidation margin

It does not:

  • Insure ordinary spot balances
  • Guarantee reimbursement after an exchange hack
  • Protect every Earn product
  • Cover every insolvency scenario
  • Operate like a government deposit-guarantee scheme
  • Promise that every derivatives loss will be absorbed

Is Bybit Regulated?

Yes, Bybit has regulated regional entities, including an Austrian MiCAR-authorized company and a UAE-licensed virtual-asset operator. The user’s protection depends on which legal entity holds the account and which products that entity is authorized to provide.

Is Bybit Regulated.pngBybit’s Regulatory Status Depends on the Serving Entity

Bybit EU and MiCAR

Bybit EU GmbH is based in Austria. The Austrian Financial Market Authority granted it authorization as a crypto-asset service provider under MiCAR on May 28, 2025.

The authorization covers:

  • Custody and administration: Bybit EU may safeguard and administer crypto-assets on behalf of customers.
  • Crypto-to-fiat exchange: The entity may exchange supported crypto-assets for fiat currency.
  • Crypto-to-crypto exchange: It may execute exchanges between supported crypto-assets.
  • Placing crypto-assets: The license covers specified activities involving the placement of crypto-assets.
  • Crypto transfer services: Bybit EU may transfer crypto-assets on behalf of customers.

The license applies to Bybit EU GmbH and its authorized activities. It does not automatically place every Bybit product, global entity or derivatives service under the same Austrian framework.

European users should check the legal entity named in their account agreement. A Bybit EU account creates a different legal relationship from an account served by another company in the group.

Bybit EU’s own disclosures state that it is not a bank and its balances are not covered by Austrian deposit-guarantee or investor-compensation schemes.

MiCAR supervision can strengthen governance, custody procedures, disclosure and complaints handling. It does not turn an exchange balance into an insured deposit.

Bybit's UAE License

The UAE Capital Market Authority’s licensed-company database lists a Bybit entity as a Virtual Asset Platform Operator.

The licensed activities include specified forms of virtual-asset trading, custody and dealing. This is more advanced than the earlier in-principle approval stage and gives the relevant entity a formal regulatory basis for covered services.

UAE users should still confirm:

  • Which Bybit company appears in their account agreement
  • Whether their emirate and location are supported
  • Whether the selected product falls within the licensed scope
  • Whether a feature is provided directly by Bybit or an external partner
  • Which complaints process applies to that entity

A group-level license does not mean every feature under the Bybit brand receives identical legal treatment.

Bybit Global and Regional Entities

Bybit is a brand covering more than one legal relationship.

Before funding an account, identify:

QuestionWhere to Check
Which company serves the account?Terms of Service, account agreement and privacy notice
Which country is the user registered in?KYC profile and proof-of-address details
Which regulator oversees the entity?Regulator database and legal disclosures
Which services are authorized?License scope and product terms
How are complaints handled?Entity-specific complaints policy
Which law governs the agreement?Governing-law section of the terms
Where would a dispute be heard?Jurisdiction or arbitration clause

Two users may see the same logo and interface while receiving services through different companies. That difference can affect product access, complaints, asset treatment and regulatory remedies.

Restricted Countries and VPN Risk

Availability changes by country, legal entity and product. As of July 19, 2026, Bybit's restricted-jurisdiction list includes the United States, Canada, mainland China, Hong Kong, Singapore, Iran and several other territories.

The official list should be checked:

  • Before registration
  • Before depositing
  • Before using a new product
  • After changing residence
  • Before travelling internationally with open positions

Bybit’s terms allow it to terminate accounts or liquidate positions when a user provides false residency information or bypasses restrictions.

Using a VPN can therefore create more than a login problem. It may produce a mismatch between KYC records, IP location and product eligibility, exposing the account to termination or forced position closure.

A temporary visit to a restricted country can also create access complications. Users with open positions should contact support rather than pretending to be in another jurisdiction.

What Regulation Does and Does Not Protect

Regulation can improve:

  • Governance: Regulators can impose standards for management, policies and internal controls.
  • Asset safeguarding: Licensed entities may face clearer rules around custody and the treatment of client assets.
  • Compliance processes: KYC, AML and transaction-monitoring procedures become subject to supervisory expectations.
  • Complaints routes: Users may receive a defined escalation path beyond ordinary platform support.
  • Disclosure requirements: Regulated entities may have to provide clearer information about risks, products and legal relationships.
  • Supervisory oversight: Regulators can inspect, investigate and sanction the licensed company.

Regulation does not eliminate:

  • Market losses
  • Exchange hacks
  • Account reviews
  • Withdrawal delays
  • Counterparty exposure
  • Product complexity
  • Stablecoin risk
  • Liquidation risk
  • Self-custody mistakes

A license defines who supervises the entity and which services it may offer. It cannot make leverage, weak passwords or malicious wallet approvals safe.

Can Bybit Freeze Accounts or Delay Withdrawals?

Yes. Bybit can temporarily restrict withdrawals or other account functions for security, technical and compliance reasons. These situations should be separated because they have different causes and different solutions.

Can Bybit Freeze Accounts or Delay Withdrawals?Why Bybit May Restrict Withdrawals or Freeze Accounts

Certain account-security changes trigger a 24-hour withdrawal restriction.

These include:

  • Resetting the password: A short lock prevents an attacker from changing the password and immediately removing funds.
  • Changing the registered phone number or email: Contact-detail changes can signal account takeover, so withdrawals are paused while the new details settle.
  • Resetting Google Authenticator: Removing or replacing 2FA weakens a major access control, making a temporary lock a reasonable defense.
  • Changing the Fund Password: Because the Fund Password protects withdrawals and sensitive actions, replacing it can trigger the same waiting period.
  • Removing passkeys: Removing a phishing-resistant credential lowers the account’s security posture and may pause withdrawals.
  • Changing address-lock settings: Enabling or disabling certain withdrawal-address controls can affect where funds may be sent, so Bybit applies a delay.
  • Reactivating an account: A recently restored account may face a waiting period before sensitive financial activity resumes.

Bybit states that these restrictions can also affect internal transfers, fiat withdrawals, Card transactions and P2P activity.

The lock is both a defense and an inconvenience. It can stop an attacker from changing credentials and immediately withdrawing funds. It can also prevent the legitimate owner from moving assets during an emergency.

Users should plan large withdrawals before changing authentication settings unless compromise is suspected. In a real compromise, securing the account takes priority over immediate access.

KYC, Enhanced Due Diligence and Source of Funds

Standard KYC confirms identity. Additional withdrawal verification confirms a specific transaction. Enhanced due diligence examines the wider source and behavior of the funds.

Bybit may ask for:

  • Identity documents: Government-issued identification confirms that the person controlling the account matches the verified customer.
  • Source-of-funds records: Bank statements, payslips, sale agreements or exchange records help explain where a specific deposit came from.
  • Source-of-wealth information: Employment, business ownership or investment history may be used to assess how the user accumulated their wider assets.
  • Wallet ownership evidence: Screenshots, signed messages or transaction records may connect an external wallet to the account holder.
  • Transaction hashes: On-chain records allow compliance teams to trace the path of deposited or withdrawn assets.
  • Exchange withdrawal records: Statements from another platform can show where the funds originated before reaching Bybit.
  • Employment or business documents: Income information helps explain whether the account activity matches the customer’s financial profile.

Bybit provides a dedicated enhanced due diligence workflow for higher-risk or unusual cases.

Review TypeMain Purpose
Standard KYCConfirm the user’s identity and address
Withdrawal verificationConfirm that a specific withdrawal is legitimate
Enhanced Due DiligenceUnderstand source of funds, wealth and transaction behavior
Sanctions or monitoring reviewInvestigate legal, geographic or transaction-risk indicators

A separate withdrawal-verification process may require the user to provide documents within a specified window. Failure to submit complete evidence can cause the withdrawal to be rejected.

A rejection does not always mean the account has been permanently frozen. It can mean that the particular withdrawal failed the required verification and must be resubmitted after the documentation issue is resolved.

Why a Withdrawal May Be Pending or Rejected

A delayed withdrawal does not automatically indicate insolvency. It also should not be dismissed without checking the reason.

Common causes include:

  • Blockchain congestion: The withdrawal may leave Bybit successfully but wait longer for network confirmation.
  • Unsupported networks: Sending an asset through a chain the destination does not support can cause rejection or permanent loss.
  • Incorrect tags or memos: Assets such as XRP may require an additional identifier. The wallet address alone may not be enough.
  • Wallet maintenance: Bybit may temporarily suspend withdrawals during upgrades, forks or network instability.
  • Minimum withdrawal requirements: Requests below the minimum amount may be rejected before broadcast.
  • Insufficient available balance: Funds may be locked in open orders, collateral, Earn products or pending transactions.
  • Security-change locks: Recent password, 2FA or address-control changes may trigger the 24-hour restriction.
  • Additional verification: The platform may request proof of identity, wallet ownership or transaction source.
  • Risk-control reviews: Unusual amounts, destinations or transaction patterns may require manual assessment.
  • Travel Rule information: Certain transfers require sender and recipient details under jurisdiction-specific rules.
  • Country or payment-provider restrictions: A withdrawal method may be unavailable because of the user’s location or the external provider’s policy.

A technical delay usually has a network or maintenance explanation. A security lock normally has a defined waiting period. A compliance review requires documents and may not have a fixed completion time.

Our guide to unfreezing crypto explains how to separate blockchain, platform and compliance restrictions before escalating through the wrong channel.

Fiat Withdrawal Holds

Fiat withdrawals operate through different payment rails and risk systems from on-chain crypto transfers.

Bybit’s fiat-withdrawal guidance says fiat assets may be temporarily locked for one to seven days depending on account-security and risk conditions.

A fiat withdrawal may also be held because:

  • The bank-account name does not match the verified Bybit identity
  • The selected payment method is unavailable in the user’s country
  • A recent funding method created a temporary risk lock
  • The bank or payment provider requires additional checks
  • The account underwent a recent security change
  • Bybit requests EDD or source-of-funds evidence

Fiat and crypto withdrawal timelines should not be treated as interchangeable. A crypto transfer may depend mainly on blockchain conditions, while fiat access also depends on banking partners and payment processors.

What to Do When an Account Is Restricted

Use one clear evidence trail:

  1. Save the support case number. This creates a single reference for every later message.
  2. Record transaction hashes and withdrawal IDs. These allow support to trace the exact transfer rather than search the entire account.
  3. Capture account-history screenshots. Save the status, timestamp, asset, amount and any error message.
  4. Confirm whether the restriction is time-based. A 24-hour security lock needs a different response from an open-ended compliance review.
  5. Upload complete and unedited documents. Cropped, inconsistent or altered records can create more questions.
  6. Explain the source and destination of funds clearly. A short factual timeline is more useful than a long defensive message.
  7. Keep communication inside official support channels. Telegram, WhatsApp and social media impersonators often target users with frozen accounts.
  8. Avoid duplicate cases unless instructed. Multiple tickets can fragment the evidence and slow escalation.
  9. Identify the legal entity serving the account. The correct company determines the relevant complaints process and regulator.
  10. Use the formal complaints route when necessary. Normal support and formal complaints are separate escalation stages.
  11. Contact the relevant regulator where appropriate. Regulatory escalation usually makes more sense after the platform’s internal complaint route has been completed.

Do not pay a third party that promises to unlock the account. A legitimate support or compliance review does not require a private recovery fee.

Is Every Bybit Product Equally Safe?

No. Bybit’s platform-level security does not make every product equally suitable. Each service introduces a different dominant risk.

Is Every Bybit Product Equally Safe?Bybit Products Carry Different Custody and Market Risks
Bybit ProductMain RiskSafety Interpretation
Spot tradingExchange custody and market volatilitySuitable for active trading balances, though not automatically ideal for long-term storage
Perpetual futuresLeverage, liquidation, funding and ADLA secure platform cannot make leveraged trading safe
OptionsExpiry, volatility and strategy complexityBetter suited to experienced users
Copy tradingTrader selection and strategy changesCopying another trader does not transfer responsibility
Trading botsAPI permissions and strategy failureUse restricted keys and separate subaccounts
P2P tradingFake receipts, chargebacks and third-party paymentsEscrow reduces some risks but cannot control later banking disputes
Bybit EarnLock-up, counterparty, market and smart-contract riskRisk depends on the specific product
Bybit CardFraud, account access and issuer riskProtection and availability differ by issuing region
Bybit WalletSeed phrase, approval, bridge and DApp riskSelf-custody shifts responsibility from Bybit to the user

Spot, Derivatives and Options

Spot trading avoids liquidation caused by leverage, but users still face market volatility and exchange custody. A token can lose most of its value without any platform failure.

Perpetual futures add several risks:

  • Leverage: A small price move can create a much larger account loss.
  • Liquidation: The platform may close the position automatically when margin falls below the required level.
  • Funding Rates: Recurring payments between long and short traders can erode returns over time.
  • Auto-Deleveraging: Profitable positions may be reduced when liquidation losses exceed the available insurance mechanisms.
  • Execution risk: Fast markets can produce slippage, partial fills and delayed stop execution.

A secure derivatives engine cannot make leverage safe. It can only execute the product rules reliably.

Options add expiry, implied volatility, time decay and nonlinear exposure. The user can lose money even when the underlying asset moves in the expected direction because the option price also depends on timing and volatility.

Copy Trading and Trading Bots

Copy trading automates another trader’s decisions. It does not guarantee that the trader will maintain the same strategy, leverage, risk tolerance or performance.

Past returns may hide:

  • High drawdowns
  • A short measurement period
  • Open losing positions
  • Strategy changes
  • Survivorship bias
  • Excessive leverage

Trading bots add strategy and API risk. A bot may execute its rules correctly while the strategy loses money. A compromised key may also place unauthorised orders even when withdrawal access is disabled. Restricted permissions reduce direct theft risk. Separate subaccounts reduce the amount one bot can affect. Neither control makes a bad strategy profitable.

Bybit P2P

Bybit P2P uses escrow to hold the crypto while the buyer and seller complete payment. Escrow can reduce the risk of one side disappearing before the trade finishes.

It cannot control everything that happens through the banking system.

Users should:

  • Never release crypto based only on a screenshot
  • Confirm that cleared funds reached the correct bank account
  • Reject third-party payments
  • Keep communication inside Bybit
  • Save payment and order evidence
  • Check the counterparty’s completion history
  • Open an appeal when payment information does not match
  • Avoid moving the dispute to Telegram or WhatsApp

Bybit’s P2P scam guidance warns against fake receipts and third-party payments.

A later bank freeze or chargeback can still occur after the platform releases the crypto. Escrow protects the immediate exchange of assets. It does not settle every banking dispute that follows.

Bybit Earn

Bybit Earn covers several product types rather than one uniform deposit account.

Risk may come from:

  • Lock-up periods: Funds may not be available immediately when the market moves or the user needs liquidity.
  • Redemption delays: Even flexible products may have processing times or temporary limits.
  • Counterparty lending: Some yields may depend on another party repaying borrowed assets.
  • Market exposure: Structured products can lose principal when the market moves beyond specified conditions.
  • Validator performance: Staking products may depend on validator uptime, reward rates and slashing conditions.
  • Smart contracts: DeFi-linked products can inherit contract, oracle and protocol risk.
  • Stablecoin issuers: A stablecoin yield still depends on the token maintaining its value and redemption function.
  • Promotional rates: A headline APY may apply only for a short period, a small deposit or a specific user group.

The advertised yield does not explain where the return comes from. Users should identify the source of yield, principal-loss conditions, lock-up terms and redemption process for each product.

Bybit Card

Bybit Card risk differs by issuing region and payment partner.

The main risks include:

  • Fraudulent card transactions
  • Compromise of the underlying Bybit account
  • Regional differences in chargeback or dispute rights
  • Payment-provider outages
  • Merchant restrictions
  • Temporary account or card freezes
  • Exchange-rate and conversion costs

Card protections should be assessed through the terms of the specific issuing entity rather than assumed from the much larger Bybit brand.

Bybit Wallet

Bybit Wallet operates differently from the centralized exchange account. With a seed-phrase wallet, the user controls the recovery credentials and carries direct responsibility for transactions.

Risks include:

  • Seed phrase loss: Losing the only recovery copy can permanently remove access.
  • Seed phrase exposure: Entering it into a fake site gives an attacker complete wallet control.
  • Malicious token approvals: A contract permission can allow assets to be transferred later without another obvious warning.
  • Disguised transactions: A signature may approve more than the interface appears to show.
  • Bridge risk: Cross-chain transfers depend on bridge contracts, validators and liquidity.
  • DApp risk: A compromised or malicious application can request dangerous permissions.
  • Wrong-network transfers: Sending assets through an unsupported network can make recovery difficult or impossible.
  • MEV and slippage: On-chain execution can receive a worse price because of transaction ordering and visible pending trades.

Smart contract risk becomes relevant as soon as the wallet interacts with DeFi protocols, bridges or token approvals.

Self-custody removes exchange-custody risk, then replaces it with key-management and transaction-approval risk.

How Does Bybit Compare With Other Exchanges on Safety?

Bybit’s strongest evidence comes from its tested crisis response and current account controls. Kraken has the cleaner breach history, while Binance has a broader public emergency fund. OKX and Bitget combine reserve disclosures with their own protection structures and regional licences.

How Does Bybit Compare With Other Exchanges on Safety?Bybit’s Safety Record Against Binance, Kraken, and Rivals
CriterionBybitBinanceKrakenOKXBitget
Major exchange-security incidentYes, 2025 custody theftYes, 2019 hot-wallet theftNo reported breach resulting in client-fund lossNo comparable exchange-wide custody theft publicly reportedNo comparable exchange-wide custody theft publicly reported
Current reserve transparencyMonthly public PoR with user verificationPublic user-verifiable PoRIndependently reviewed, user-verifiable PoRMonthly PoR reviewed by HackenMonthly public PoR with user verification
Public protection structureDerivatives insurance fundSAFU emergency fundNo direct blanket equivalentPlatform risk and insurance structures, scope variesPublic Protection Fund
Main regulatory strengthEU and UAE entitiesBroad regional licensingStrong presence across regulated marketsMultiple regulated regional entitiesRegional licences and registrations
Primary safety advantageCrisis response and account controlsScale, liquidity and SAFULong security recordReserve transparency and wallet controlsPublic Protection Fund and reserve reporting
Primary weakness2025 custody incidentRegulatory and entity complexityNo blanket customer deposit insuranceJurisdiction and entity complexityShorter operating and regulatory track record
  • Binance publishes a user-verifiable proof of reserves system and maintains the Secure Asset Fund for Users. SAFU is an exchange-controlled emergency mechanism rather than government insurance.
  • Kraken publishes regular, user-verifiable proof of reserves and has the cleaner security history for readers who prioritise the absence of a comparable exchange-wide theft over product breadth.
  • OKX publishes regular reserve reports and combines them with wallet and account controls. Its legal-entity and jurisdiction structure still requires the same user-level review discussed for Bybit.
  • Bitget publishes reserve data and maintains a separate protection fund. That adds a visible protection layer, although the fund does not replace full solvency analysis or user-side security.

Is Bybit Safe for Long-Term Crypto Storage?

Bybit can hold crypto for active trading, collateral and near-term transactions. It should not be treated as a permanent replacement for self-custody when assets have no reason to remain on an exchange.

Is Bybit Safe for Long-Term Crypto Storage?Why Long-Term Holdings Need a Different Custody Plan

Exchange balances can be divided by purpose:

  • Active trading capital: Funds needed for planned spot trades and short-term strategies.
  • Open-position collateral: Margin supporting current derivatives exposure.
  • Near-term purchases: Funds expected to be deployed shortly.
  • Emergency trading buffer: A limited amount kept for margin adjustments or sudden opportunities.
  • Long-term holdings: Assets intended to remain untouched across market cycles.

The first four categories may justify exchange custody. Long-term holdings usually receive little additional utility from remaining on Bybit while continuing to face counterparty exposure.

There is no sensible universal percentage or dollar limit. A professional trader and a passive Bitcoin holder use an exchange for different reasons. The principle is to retain only what is needed for planned activity, plus a controlled operating buffer.

Risks of Leaving Crypto on Bybit

Long-term exchange storage creates several overlapping risks:

  • Exchange custody: Bybit controls the wallets and transaction process. The user holds an account claim rather than direct control of the private keys.
  • Account compromise: A stolen email, device or authentication method can expose the balance even when the exchange itself remains secure.
  • Withdrawal restrictions: Security and compliance reviews can delay access at the exact moment the user wants to move funds.
  • Regulatory changes: A product, payment rail or entire account relationship may become unavailable in the user’s jurisdiction.
  • Insolvency risk: Proof of Reserves reduces uncertainty without revealing every corporate liability or legal claim.
  • Stablecoin exposure: Holdings may depend on the issuer, reserve quality and redemption mechanics of the selected stablecoin.
  • Product-specific lock-ups: Earn, staking or structured products may prevent immediate withdrawal or expose principal to additional conditions.
  • No bank-style insurance: Exchange balances do not receive ordinary government-backed deposit protection.

The key difference between an exchange and a wallet is control.

When Self-Custody Is the Better Choice

Self-custody is more appropriate when:

  • The assets are not actively traded: Exchange custody provides little practical benefit when the holdings are intended to sit untouched.
  • The user can secure a recovery phrase properly: Self-custody becomes dangerous when backups are exposed, lost or stored carelessly.
  • The balance justifies dedicated security: Larger holdings may justify a hardware wallet, separate devices and a more formal backup process.
  • The user understands networks and withdrawal testing: Selecting the wrong chain or address can cause irreversible loss.
  • A recovery plan exists: The user needs a clear route for device loss, authentication failure and wallet restoration.
  • An inheritance plan exists: Long-term holdings should remain accessible to trusted heirs without exposing the recovery phrase during the user’s lifetime.

A hardware wallet keeps private keys in a dedicated signing environment and can reduce exposure to exchange failure and general-purpose device malware.

It also removes customer support as a recovery route. A lost or exposed recovery phrase can cause permanent loss.

Self-custody works best when backup, inheritance and transaction verification form an ongoing process rather than a one-time setup.

A Safer Withdrawal Routine

Use the same process for every substantial withdrawal:

  1. Whitelist the destination wallet where supported.
  2. Confirm the asset and blockchain network.
  3. Check the full address rather than only the first and last characters.
  4. Confirm whether a tag or memo is required.
  5. Send a small test transaction.
  6. Wait for the test transfer to arrive.
  7. Verify the received asset and network.
  8. Send the remaining amount.
  9. Save the transaction hashes and account records.
  10. Revoke unused API keys.
  11. Review trusted devices after a major withdrawal.
  12. Confirm the final balance in both the exchange and wallet.

A test transaction adds cost and time. Those are cheap compared with sending a long-term holding to an incompatible network or malicious address.

Who Should Use Bybit?

Bybit is best suited to active traders who need advanced markets and are willing to manage custody, security and jurisdictional risk directly.

Who Should Use Bybit?Matching Bybit’s Trading Tools to the Right Users

Bybit Is Best Suited To

  • Active spot traders: The platform provides deep order books, advanced order types and regular access to crypto markets.
  • Experienced derivatives traders: Perpetual futures, options and margin tools support more complex strategies, although the products remain highly risky.
  • Copy traders who understand strategy risk: The marketplace can automate another trader’s positions without removing drawdown, leverage or selection risk.
  • Users who need advanced trading tools: APIs, subaccounts, bots and order controls support systematic or high-frequency activity.
  • Residents of supported jurisdictions: A clear legal entity and compliant registration path reduce the risk of sudden access problems.
  • Users prepared to activate security controls: Passkeys, 2FA, Secure Transaction Approval and withdrawal locks materially improve the account’s defense.

The platform becomes more defensible when its features solve a real trading need. Users paying the custody cost without using the trading infrastructure receive a weaker bargain.

Bybit Is Not the Best Choice For

  • Residents of restricted jurisdictions: Misrepresenting location can lead to account termination or forced position closure.
  • Users seeking insured custody: Bybit does not provide bank-style deposit protection.
  • Complete beginners drawn to leverage: Easy access to derivatives does not make liquidation and funding easy to manage.
  • Long-term holders without trading needs: Self-custody may provide better control when assets do not need to remain on an exchange.
  • Users unwilling to complete KYC or source-of-funds checks: Compliance reviews are part of using a regulated custodial platform.
  • Users who cannot manage account security: Weak email, device or API practices can undermine the platform’s controls.
  • People seeking a simple buy-and-hold experience: Bybit’s product range can add complexity for users who only want occasional purchases.
  • Anyone uncomfortable with possible withdrawal reviews: Centralized custody means access can depend on security and compliance processes.

Bybit Safety by User Type

User TypeVerdict
Beginner buying BTC or ETHUsable, although a simpler platform may be easier
Active spot traderStrong fit with proper account security
Derivatives traderStrong platform for an extremely risky product category
P2P userUsable with strict payment verification
Long-term holderBetter used as an on-ramp than permanent storage
Institution or treasuryRequires independent legal, custody and counterparty due diligence

An institution or treasury needs more than retail security settings. It may require legal review of asset ownership, withdrawal controls, subaccount permissions, counterparty limits, financial disclosures and insolvency treatment.

Newsletter_inline

Is Bybit Safe? Final Verdict

Bybit is a legitimate and increasingly regulated cryptocurrency exchange. Its current account controls are stronger than a basic password-and-2FA setup. Passkeys, a Fund Password, Secure Transaction Approval, trusted-device management, address locks and anti-phishing codes give users several ways to reduce account-takeover risk.

The remaining weaknesses are structural. Regulation and customer protections vary by legal entity. Withdrawals may be delayed by security locks, technical problems or compliance reviews. Derivatives, P2P, Earn and Bybit Wallet each add risks beyond the security of the central exchange.

Bybit is a defensible choice for active traders in supported jurisdictions who keep permissions tight and limit their exchange balance to planned activity. It is a poor substitute for insured savings or carefully managed self-custody.

Editorial Standards
Why You Can Trust The Coin Bureau

We do the digging, the testing, and the updating, so readers get crypto education that is clear, grounded, and built on real editorial work, not fluff wrapped in buzzwords.

50+ Years
Combined editorial experience

Combined experience in journalism across our writers and editors, covering finance, technology, and global markets long before crypto went mainstream.

25+ Hours / Week
Active testing and updates

Dedicated to hands-on testing, research, and content updates so pages do not gather digital dust.

90K
Monthly readers

Monthly readers who rely on The Coin Bureau for clear, unbiased crypto education and analysis.

Expert-Led Editorial Team

Our content is written and reviewed by specialists, not anonymous freelancers or AI-only pipelines.

Frequently Asked Questions

Devansh Juneja

Devansh Juneja

Adept at leading editorial teams and executing SEO-driven content strategies, Devansh Juneja is an accomplished content writer with over three years of experience in Web3 journalism and technical writing. 

His expertise spans blockchain concepts, including Zero-Knowledge Proofs and Bitcoin Ordinals. Along with his strong finance and accounting background from ACCA affiliation, he has honed the art of storytelling and industry knowledge at the intersection of fintech.

Join the Coin Bureau Club

Get exclusive access to premium content, member-only tools, and the inside track on everything crypto.

Stay Ahead with Our Newsletter

Weekly crypto insights, expert guides, and in-depth research—delivered straight to your inbox. Stay informed, for free.