How to read these grades: each is derived from published, checkable disclosures — proof-of-reserves attestations, public regulatory registers, disclosed insurance funds and the documented incident record — using the weighted rubric below. Where an exchange does not disclose something, we mark it unverified rather than assume it. These are not audits and not investment advice; they reflect what was published as of our last review.
Bybit
Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46–1.5bn — the largest exchange hack on record — replenishing reserves in full within 72 hours.
BySafety DeskSenior Exchange Safety Editor
Our Bybit review
Bybit is the venue that lost more money to a single attack than any exchange in history and still paid everybody back. Both halves of that sentence are in the B-.
What checks out
Merkle-tree and proof-of-liabilities audits have run monthly since June 2024 and are published as signed reports by Hacken OU. Hacken is a crypto-security specialist rather than a Big Four financial auditor, which is worth knowing when you read the signature — but a signature from outside the company is still more than most of this corpus offers. On the regulatory side, Bybit EU GmbH holds an EU MiCA licence from the Austrian FMA, granted in May 2025 and covering 5 of the 10 MiCA service categories.
Where the evidence stops
In February 2025 roughly $1.46–1.5bn was taken through a phishing attack on a Safe multisig interface, attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, and only 3.54% of the stolen funds were ever frozen. The insurance fund that backstops derivatives liquidations was drawn on in that response, but its standing balance is not disclosed, so its capacity to absorb a second event is unknown. The cold/hot storage split is also undisclosed. The Dubai VARA approval is provisional and non-operational, not a live licence; the UK FCA issued a public warning in February 2025, and Bybit re-entered the UK in December 2025 through FCA-regulated Archax rather than on its own permission.
How to read the grade
Solvency through the worst attack the sector has seen is real evidence about a balance sheet, and it is not evidence that the attack surface has changed. The B- credits the recovery and refuses to treat it as a security record.
Grade breakdown
Every KripZen grade comes from the same five weighted checks. Here is how Bybit scores on each.
- Proof of reservesWeight 30%
Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor.
What this means → meets this factor - CustodyWeight 25%
Cold/hot storage split is not disclosed; we could not confirm it from a primary source.
What this means → partial or unverified - RegulationWeight 20%
EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax.
What this means → partial or unverified - InsuranceWeight 15%
Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed.
partial or unverified - Incident historyWeight 10%
About $1.46–1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen.
does not meet this factor