Bybit
Best for weighing a large exploit against the response to it
How it rates
- MiCA authorisation obtained and EU base established in Vienna
- Monthly proof-of-reserves cadence
- Honoured withdrawals through the largest exploit in exchange history
- Largest exchange exploit on record occurred here
- Around $644m of the stolen funds reported untraceable
- Trust score and rank below the leaders in this group
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetAuthorisation from a recognised financial regulator, evidenced publicly
MiCA authorisation, Austria FMA, May 2025.
casptracker.eu/exchange/bybit/ - PartialProof of reserves with per-account verification
Programme published; per-account verification not confirmed at this check.
www.bybit.com/en/proof-of-reserves - MetMost recent reserve publication within 12 months
Monthly cadence reported.
www.bybit.com/en/proof-of-reserves - PartialReserve method documented publicly
Page published; method detail not captured at this check.
www.bybit.com/en/proof-of-reserves - PartialNo unremediated custody-loss incident on the public record (24 months)
Feb 2025 exploit of ~$1.4bn; customers reported not out of pocket, remediation disclosed.
cryptoslate.com/bybit-earns-mica-license-as-hackers-keep-644-million-fro
- MetFee page at a documented public URL
Reachable without an account.
www.bybit.com/en/help-center/article/Trading-Fee-Structure-Bybit - PartialEntry-tier maker and taker rates displayed
Fee article published; rates not captured at this check.
www.bybit.com/en/help-center/article/Trading-Fee-Structure-Bybit - PartialVolume tiers with thresholds displayed
Not captured at this check.
www.bybit.com/en/help-center/article/Trading-Fee-Structure-Bybit - Not met
- MetFee documentation readable without an account
Page retrieved at this check.
www.bybit.com/en/help-center/article/Trading-Fee-Structure-Bybit
- MetListed with an independent trust score
CoinGecko exchange dataset, trust score 9.
api.coingecko.com/api/v3/exchanges - Not met
- Not met
- Met
- Met
- MetRegulatory status disclosed publicly
Licence recorded in an EU CASP register tracker.
casptracker.eu/exchange/bybit/ - MetOperating entity and jurisdiction identifiable
EU entity and Austrian regulator named.
www.coindesk.com/policy/2025/05/29/crypto-exchange-bybit-granted-europea - MetReserve disclosure on own domain
Programme hosted on the company's own site.
www.bybit.com/en/proof-of-reserves - MetIncident disclosed with remediation on the public record
Exploit, recovery status and customer position widely reported.
cryptoslate.com/bybit-earns-mica-license-as-hackers-keep-644-million-fro - MetIndependently corroborated by a public register
Register tracker entry.
casptracker.eu/exchange/bybit/
- MetHelp centre reachable without an account
Reachable without an account at this check (HTTP 2xx).
www.bybit.com/en/help-center - PartialPublic status page
Published at a documented URL; automated retrieval blocked at this check.
www.bybit.com/en/help-center - MetPublic API documentation
Reachable without an account at this check (HTTP 2xx).
bybit-exchange.github.io/docs/ - MetPublic fee documentation
Reachable without an account at this check (HTTP 2xx).
www.bybit.com/en/help-center/article/Trading-Fee-Structure-Bybit - MetPublic legal and terms documentation
Reachable without an account at this check (HTTP 2xx).
www.bybit.com/en/help-center
Bybit holds a MiCA authorisation from Austria's Financial Market Authority and publishes monthly proof of reserves. It also suffered the largest exchange exploit on record in February 2025 — roughly $1.4bn — and reporting indicates customers were not left out of pocket while a large share of the funds was never recovered. Both facts belong in the same sentence.
Our assessment
Bybit is the venue in this table with the most consequential recent history. In February 2025 it lost roughly $1.4bn in the largest exchange exploit on record. It also holds a MiCA authorisation from Austria's Financial Market Authority, publishes monthly proof of reserves, and — by the available reporting — left no customer out of pocket. All of that belongs in the same assessment.
What happened, and what followed
The exploit was extraordinary in size. The response is the part a prospective user should weigh: withdrawals continued, customer balances were made whole, and the incident was disclosed rather than minimised. Around $644m of the stolen assets remained untraceable by later reporting, so this was absorbed by the company rather than recovered.
How our rubric treats it
Gate G3 caps any provider with unreimbursed user losses and no published remediation at 6.0. Neither condition holds here, so the gate does not trigger and the incident is recorded as a partial on the custody pillar instead. That is a deliberate judgement: a platform that covers a nine-figure loss and says so publicly is demonstrating something real about its balance sheet and its disclosure practice, even as the event itself weighs against it.
The rest of the picture
The Austrian MiCA authorisation, obtained in May 2025 with an EU base in Vienna, gives it passporting across the European Economic Area. Reserves are published monthly. On independent market data it carries a trust score of 9 with 24-hour volume above every venue here except Binance. Fee documentation was the weakest area — we could not capture rates or tier thresholds at this check.
Who it suits
Bybit fits active traders who want depth and derivatives access from an EU-authorised venue, and who have read the 2025 incident and formed their own view of it. Readers for whom a single event of that magnitude is disqualifying have five higher-scoring alternatives in this table, and that is a reasonable position to hold.
How rivals compare
Frequently asked
Did Bybit customers lose money in the 2025 hack?
Reporting indicates customers were not left out of pocket and withdrawals continued, though around $644m of the stolen funds was never recovered.
Is Bybit authorised in the EU?
It received a MiCA authorisation from Austria's Financial Market Authority in May 2025 and set up its European base in Vienna.
Should the 2025 exploit rule Bybit out?
That is your call. Our rubric records it as a partial rather than a fail because losses were covered and the response was disclosed — but an incident of that size legitimately weighs against a platform.