Skip to content
Crypto Almanac Daily
B
Exchanges

Bybit

Best for weighing a large exploit against the response to it

EU status:MiCA authorised (Austria FMA, May 2025)Proof of reserves:MonthlyFeb 2025 exploit:~$1.4bn; customers reported not out of pocketIndependent trust score:9 — rank 8Rubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
7.3
out of 10
Open account
Scorecard

How it rates

Counterparty & custody risk · 35%7.0
Cost transparency · 20%6.0
Market quality · 20%6.0
Transparency & track record · 15%10.0
Public documentation surface · 10%9.0
Pros
  • MiCA authorisation obtained and EU base established in Vienna
  • Monthly proof-of-reserves cadence
  • Honoured withdrawals through the largest exploit in exchange history
Cons
  • Largest exchange exploit on record occurred here
  • Around $644m of the stolen funds reported untraceable
  • Trust score and rank below the leaders in this group
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Counterparty & custody risk · 35% weight7/10 points · 7.0/10
Cost transparency · 20% weight6/10 points · 6.0/10
Market quality · 20% weight6/10 points · 6.0/10
Transparency & track record · 15% weight10/10 points · 10.0/10
Public documentation surface · 10% weight9/10 points · 9.0/10

Bybit holds a MiCA authorisation from Austria's Financial Market Authority and publishes monthly proof of reserves. It also suffered the largest exchange exploit on record in February 2025 — roughly $1.4bn — and reporting indicates customers were not left out of pocket while a large share of the funds was never recovered. Both facts belong in the same sentence.

Our assessment

Bybit is the venue in this table with the most consequential recent history. In February 2025 it lost roughly $1.4bn in the largest exchange exploit on record. It also holds a MiCA authorisation from Austria's Financial Market Authority, publishes monthly proof of reserves, and — by the available reporting — left no customer out of pocket. All of that belongs in the same assessment.

What happened, and what followed

The exploit was extraordinary in size. The response is the part a prospective user should weigh: withdrawals continued, customer balances were made whole, and the incident was disclosed rather than minimised. Around $644m of the stolen assets remained untraceable by later reporting, so this was absorbed by the company rather than recovered.

How our rubric treats it

Gate G3 caps any provider with unreimbursed user losses and no published remediation at 6.0. Neither condition holds here, so the gate does not trigger and the incident is recorded as a partial on the custody pillar instead. That is a deliberate judgement: a platform that covers a nine-figure loss and says so publicly is demonstrating something real about its balance sheet and its disclosure practice, even as the event itself weighs against it.

The rest of the picture

The Austrian MiCA authorisation, obtained in May 2025 with an EU base in Vienna, gives it passporting across the European Economic Area. Reserves are published monthly. On independent market data it carries a trust score of 9 with 24-hour volume above every venue here except Binance. Fee documentation was the weakest area — we could not capture rates or tier thresholds at this check.

Who it suits

Bybit fits active traders who want depth and derivatives access from an EU-authorised venue, and who have read the 2025 incident and formed their own view of it. Readers for whom a single event of that magnitude is disqualifying have five higher-scoring alternatives in this table, and that is a reasonable position to hold.

Alternatives

How rivals compare

ServiceScoreBest for
Binance9.7lowest published spot fees, outside the EURead →
Kraken9.7verifiable reserves and EU authorisationRead →
Reference

Frequently asked

Did Bybit customers lose money in the 2025 hack?

Reporting indicates customers were not left out of pocket and withdrawals continued, though around $644m of the stolen funds was never recovered.

Is Bybit authorised in the EU?

It received a MiCA authorisation from Austria's Financial Market Authority in May 2025 and set up its European base in Vienna.

Should the 2025 exploit rule Bybit out?

That is your call. Our rubric records it as a partial rather than a fail because losses were covered and the response was disclosed — but an incident of that size legitimately weighs against a platform.