โฆษณาบน KripZen — นำแบรนด์ของคุณไปอยู่ต่อหน้าผู้ชมคริปโตทั่วโลกติดต่อเรา →

← กลับไปที่หน้าคะแนนความปลอดภัย

วิธีอ่านเกรดเหล่านี้: แต่ละเกรดคำนวณจากข้อมูลที่เผยแพร่และตรวจสอบได้ — การรับรองหลักฐานเงินสำรอง ทะเบียนของหน่วยงานกำกับดูแลที่เปิดเผยต่อสาธารณะ กองทุนประกันที่เปิดเผย และประวัติเหตุการณ์ที่มีการบันทึกไว้ — ตามเกณฑ์ถ่วงน้ำหนักด้านล่าง หากกระดานเทรดใดไม่เปิดเผยข้อมูลใด เราจะระบุว่ายังไม่ได้รับการยืนยัน แทนที่จะสันนิษฐานเอง สิ่งเหล่านี้ไม่ใช่การตรวจสอบบัญชีและไม่ใช่คำแนะนำการลงทุน แต่สะท้อนข้อมูลที่เผยแพร่ ณ การทบทวนครั้งล่าสุดของเรา

B-

Bybit

Bybit publishes monthly Merkle-tree proof of reserves audited by Hacken OU and holds a partial EU MiCA licence in Austria; it stayed solvent after the February 2025 theft of roughly $1.46–1.5bn — the largest exchange hack on record — replenishing reserves in full within 72 hours.

3.3/5
เกรดความปลอดภัย

โดยSafety Deskบรรณาธิการอาวุโสด้านความปลอดภัยของเอ็กซ์เชนจ์

รีวิว Bybit ของเรา

Bybit คือแพลตฟอร์มที่สูญเงินจากการโจมตีครั้งเดียวมากกว่ากระดานเทรดใด ๆ ในประวัติศาสตร์ และยังคืนเงินให้ทุกคนได้ครบ ทั้งสองครึ่งของประโยคนี้อยู่ในเกรด B-

สิ่งที่ตรวจสอบได้

การตรวจสอบแบบ Merkle tree และการพิสูจน์หนี้สินดำเนินการรายเดือนมาตั้งแต่มิถุนายน 2024 และเผยแพร่เป็นรายงานที่ลงนามโดย Hacken OU ทั้งนี้ Hacken เป็นผู้เชี่ยวชาญด้านความปลอดภัยคริปโต ไม่ใช่ผู้สอบบัญชีการเงินระดับ Big Four ซึ่งควรทราบไว้เวลาอ่านลายเซ็น แต่ลายเซ็นจากภายนอกบริษัทก็ยังมากกว่าที่แพลตฟอร์มส่วนใหญ่ในชุดนี้เสนอ ด้านกฎเกณฑ์ Bybit EU GmbH ถือใบอนุญาต MiCA จาก FMA ของออสเตรีย ออกให้เมื่อพฤษภาคม 2025 ครอบคลุม 5 จาก 10 หมวดบริการภายใต้ MiCA

จุดที่หลักฐานสิ้นสุด

เมื่อกุมภาพันธ์ 2025 มีเงินราว 1.46 ถึง 1.5 พันล้านดอลลาร์ถูกขโมยผ่านการโจมตีแบบฟิชชิงต่อหน้าจอ multisig ของ Safe ซึ่งถูกระบุว่าเป็นฝีมือกลุ่ม Lazarus ของเกาหลีเหนือ นับเป็นการเจาะกระดานเทรดคริปโตครั้งใหญ่ที่สุดเท่าที่มีบันทึก Bybit ยังคงมีความสามารถชำระหนี้และเติมทุนสำรองกลับเต็มจำนวนภายใน 72 ชั่วโมง โดยอายัดเงินที่ถูกขโมยได้เพียง 3.54% กองทุนประกันที่รองรับการบังคับชำระบัญชีอนุพันธ์ถูกนำมาใช้ในการรับมือครั้งนั้น แต่ยอดคงเหลือปัจจุบันไม่ถูกเปิดเผย จึงไม่ทราบความสามารถในการรับเหตุการณ์ครั้งที่สอง สัดส่วนเย็นต่อร้อนก็ไม่ถูกเปิดเผยเช่นกัน การอนุมัติจาก VARA ที่ดูไบเป็นแบบชั่วคราวและยังไม่เปิดดำเนินการ ไม่ใช่ใบอนุญาตที่ใช้งานอยู่ FCA ของสหราชอาณาจักรออกคำเตือนสาธารณะเมื่อกุมภาพันธ์ 2025 และ Bybit กลับเข้าสหราชอาณาจักรเมื่อธันวาคม 2025 ผ่าน Archax ซึ่งอยู่ในกำกับของ FCA ไม่ใช่ด้วยใบอนุญาตของตัวเอง

อ่านเกรดนี้อย่างไร

การรอดพ้นจากการโจมตีที่หนักที่สุดของวงการโดยยังชำระหนี้ได้ คือหลักฐานจริงเกี่ยวกับงบดุล แต่ไม่ใช่หลักฐานว่าพื้นผิวการโจมตีเปลี่ยนไปแล้ว เกรด B- ให้เครดิตกับการฟื้นตัว และปฏิเสธที่จะนับมันเป็นประวัติด้านความปลอดภัย

รายละเอียดเกรด

ทุกเกรดของ KripZen มาจากห้าการตรวจสอบที่ถ่วงน้ำหนักเหมือนกัน นี่คือคะแนนของ Bybit ในแต่ละข้อ

  • การพิสูจน์เงินสำรองน้ำหนัก 30%

    Merkle-tree and proof-of-liabilities audits by Hacken OU, monthly since June 2024 and published as signed reports; Hacken is a crypto-security specialist rather than a Big Four financial auditor.

    ข้อนี้หมายความว่าอย่างไร → ผ่านปัจจัยนี้
  • การเก็บรักษาสินทรัพย์น้ำหนัก 25%

    Cold/hot storage split is not disclosed; we could not confirm it from a primary source.

    ข้อนี้หมายความว่าอย่างไร → บางส่วนหรือยังไม่ได้ตรวจสอบ
  • การกำกับดูแลน้ำหนัก 20%

    EU MiCA licence via Bybit EU GmbH (Austrian FMA, May 2025) covering 5 of the 10 MiCA service categories, plus provisional, non-operational VARA approval in Dubai; the UK FCA issued a public warning in February 2025 and Bybit re-entered the UK in December 2025 through FCA-regulated Archax.

    ข้อนี้หมายความว่าอย่างไร → บางส่วนหรือยังไม่ได้ตรวจสอบ
  • ประกันน้ำหนัก 15%

    Maintains a dedicated insurance fund backstopping derivatives liquidations, which was drawn on in the post-hack solvency response, but its standing balance is not disclosed.

    บางส่วนหรือยังไม่ได้ตรวจสอบ
  • ประวัติเหตุการณ์น้ำหนัก 10%

    About $1.46–1.5bn stolen in February 2025 through a Safe multisig interface phishing attack attributed to North Korea's Lazarus Group — the largest crypto exchange hack on record. Bybit remained solvent and fully replenished reserves within 72 hours, but only 3.54% of the stolen funds were ever frozen.

    ไม่ผ่านปัจจัยนี้

เอ็กซ์เชนจ์อื่นที่เราให้เกรด

A-KrakenKraken holds a Wyoming SPDI charter, CFTC and SEC registrations and two EU MiCA authorisations, and has published Merkle-tree proof of reserves verified by Armanino LLP since February 2022; it discloses no insurance-fund figure.B-BinanceBinance publishes a self-attested proof-of-reserves page and a $1bn SAFU user-protection fund, which covered the May 2019 hot-wallet theft of about 7,000 BTC in full; it settled U.S. Bank Secrecy Act and sanctions charges for $4.3bn in November 2023 and remains under a five-year DOJ compliance monitorship.B+BitgetBitget publishes a monthly open-source Merkle-tree proof of reserves showing BTC at 138% and ETH at 181%, and cites a protection fund its own sources size differently; ASIC issued an investor alert in July 2025 over unlicensed high-leverage derivatives.BCoinbaseCoinbase is a publicly traded, SEC-reporting U.S. company licensed in 45 states and holding a New York BitLicense, and the SEC's 2023 case against it was dismissed with prejudice in February 2025; it runs no crypto-specific proof-of-reserves programme and its last disclosed crime-insurance figure dates from 2019.B-Crypto.comCrypto.com discloses more than $870m of insurance cover, had its SEC investigation closed with no action in March 2025 and holds a Malta MiCA authorisation; its proof-of-reserves position is contested between our sources, and it reimbursed all users after a January 2022 incident that drained about $34–35m from 483 accounts.BHTXHTX publishes monthly Merkle-tree proof of reserves that excludes corporate holdings, discloses only a Pakistani no-objection certificate among its authorisations, blocked the entire EU rather than seek MiCA licensing, and faces UK FCA High Court proceedings.