HostDeFi › Is Bybit legit
Is Bybit legit? The exchange that survived crypto's largest theft
Bybit has the most dramatic legitimacy file in crypto: a real, Dubai-licensed exchange since 2018 — that suffered the largest theft in industry history (~$1.46 billion) in February 2025 and absorbed it completely, processing 350,000 withdrawals in ten hours without a single user losing a dollar. The theft is the proof.
“Is Bybit legit” is asked with unusual urgency because it is the exchange that suffered the worst security event in crypto history — and the answer is that the event is precisely what makes the legitimacy file legible. A fake venue doesn't survive a $1.5 billion hole; Bybit did, in public, in real time. The post-theft disclosures are on the record in a way no fake venue could manufacture: bridge-loan partners named, a live audit confirming reserves exceeded liabilities, and a founder who went on camera within hours rather than going silent.
Every claim below names its source and date.
The company is real and licensed
Bybit was founded in 2018 by Ben Zhou — a named, public founder — and is headquartered in Dubai, where it holds a real VARA license. It is one of the top three exchanges globally by volume — a real company with real offices, real regulatory standing in the UAE and EU, and a product surface spanning spot, derivatives, Earn, and the Bybit Web3 wallet.
The growth record is real: it built to top-three status over seven years, through every market cycle, with an operating history that is public and a founder who is publicly identifiable.
The largest theft in crypto history — and the survival file
The file's defining entry: on February 21, 2025, Lazarus Group stole approximately $1.46–1.5 billion in ETH from a Bybit cold wallet — the largest theft in crypto history, by a wide margin. The mechanism is documented in forensic detail: a Safe{Wallet} developer machine was compromised, a poisoned signing UI was served from S3, and the multisig signers — including Zhou — approved what looked like a routine transaction. The cold-wallet signature was real; what it signed was not.
What makes this a legitimacy file rather than a collapse file is the aftermath, which is the best-documented part: Bybit processed roughly 350,000 withdrawal requests in ~10 hours — a bank-run-scale exit wave, cleared at full speed, — a bank-run-scale exit wave, cleared at full speed, — a bank-run-scale exit wave, cleared at full speed, as users rushed the exit, covered the hole with bridge loans from partners (including a public pledge of 1:1 backing), got reserves-versus-liabilities confirmed live by Hacken, and kept operating. Zhou did a live stream within hours. The company's books held under the worst stress test any crypto venue has ever faced.
What the theft proved — and what it didn't
The honest read of the theft is asymmetric: it proved Bybit’s solvency and operational resilience conclusively — no fake or thin venue absorbs $1.5 billion and pays out in full — while simultaneously exposing the signing-UI dependency that made the theft possible. The cold wallets held; the humans and the interface they read did not — a distinction that applies to every venue using the same signing pattern. The cold wallets held; the humans and the interface they read did not — a distinction that applies to every venue using the same signing pattern. The cold wallets held; the humans and the interface they read did not — a distinction that applies to every venue using the same signing pattern. Both are true, and the second is why the file is honest about the residual: the attack wasn't a smart-contract bug or an inside job; it was a supply-chain compromise of the signing layer the venue trusted. That is the honest row: the same signing-UI dependency sits in every venue that approves cold-wallet transactions through third-party interfaces — the difference is that Bybit’s was exploited and survived, not that others were immune.
The post-incident posture is documented: Bybit commissioned multiple independent reviews, rotated its signing infrastructure, and has continued to publish proof-of-reserves attestations with an unbroken record since. The company also ran the kind of remediation a real institution runs — external reviews, infrastructure rotation, named commitments — rather than the quiet disappearance a fraudulent one would.
The other file entries
The legitimacy file is not theft-only — Bybit carries the ordinary major-exchange regulatory texture: a UK FCA exit in 2023 (products withdrawn rather than fight the perimeter), a €2.25M Dutch fine (2024) for unlicensed operation, an Ontario OSC settlement — the ordinary penalties of a global venue finding its regulatory perimeter, not fraud entries. Each is a jurisdiction-by-jurisdiction perimeter fight; none is a solvency or honesty event. Each is a jurisdiction-by-jurisdiction perimeter fight; none is a solvency or honesty event. Each is a jurisdiction-by-jurisdiction perimeter fight; none is a solvency or honesty event.
None of it is the shape of a scam; it is the shape of a real multinational exchange absorbing the standard regulatory friction of being one. Fines for operating without local licenses are what real global exchanges accumulate as they scale into each jurisdiction — categorically different from a fraud charge.
The verdict, precisely
Is Bybit legit? Yes — with the most operationally-verified legitimacy claim in the industry: it is a real, licensed, seven-year-old company that absorbed the largest theft in crypto history without a single customer losing funds. The honest caveat is the theft itself — the largest security failure ever documented at a major venue — which proves solvency while documenting a real signing-layer dependency. “Legit” is settled; “was it well-defended” is a different, now-answered, question. The legitimacy file closed on February 21; what remains open is how every other venue’s signing layer would fare under the same attack. The legitimacy file closed on February 21; what remains open is how every other venue’s signing layer would fare under the same attack. The legitimacy file closed on February 21; what remains open is how every other venue’s signing layer would fare under the same attack.
The operating record underneath the incident
Beneath the incident file is an operating record that has held for seven years: Bybit built to top-three global status through the 2022 collapses that killed FTX, Celsius, and BlockFi, publishes regular proof-of-reserves attestations, and runs a product surface — spot, derivatives, Earn, a Web3 wallet — that has only grown. The most meaningful fact may be the boring one: the February 2025 theft happened in year seven of a continuous operating history, and the company treated a $1.5 billion hole as a balance-sheet event rather than an existential one.
The regulatory posture is the real-company kind as well: a Dubai VARA license, an expanding UAE footprint — including a full Virtual Asset Platform Operator license announced in October 2025 — and the standard multinational penalty trail. None of it is the shape of a scam; all of it is the shape of an institution being real in public.
The growth file matters to legitimacy too: Bybit didn't buy its way to top-three with a token or a celebrity blitz — it grew through derivatives-market share, a trading product professionals actually use, and an international expansion that kept operating through every cycle. That’s the texture of a real company, and it’s what made the February file survivable. A thin or fraudulent venue doesn’t have the counterparties, the reserves, or the nerve to hold the door open through a $1.5 billion exit wave — that combination is earned, not staged. A thin or fraudulent venue doesn’t have the counterparties, the reserves, or the nerve to hold the door open through a $1.5 billion exit wave — that combination is earned, not staged. A thin or fraudulent venue doesn’t have the counterparties, the reserves, or the nerve to hold the door open through a $1.5 billion exit wave — that combination is earned, not staged.
Frequently asked
Is Bybit a real company?
Yes — founded 2018 by Ben Zhou, Dubai HQ with a VARA license; a top-three global exchange by volume.
Did Bybit really get hacked for $1.5B?
Yes — Feb-21-2025, Lazarus Group, ~$1.46B ETH from a cold wallet via a compromised Safe signing UI; the largest crypto theft ever.
Did users lose money?
No — Bybit absorbed the loss via bridge loans and reserves, processed ~350K withdrawals in ~10h, and no customer lost funds.
Is Bybit a scam?
No — it is a licensed, operating, solvent venue that survived the worst attack in the industry's history with 1:1 backing intact.
Was the Bybit hack an inside job?
The forensic record says no — Lazarus Group, via a Safe{Wallet} developer-machine compromise that poisoned the signing interface.
Is Bybit safe now?
Legitimacy is settled; safety is the separate file — the theft exposed a real signing-layer dependency that has since been rotated, but custodial risk is inherent.