Security at Bybit

Your security is our top priority. We employ industry-leading practices to protect your assets and data.

Cold Storage

95% of all user assets are stored in multi-signature cold wallets across geographically distributed locations.

95%

Cold Storage

Proof of Reserves

We publish regular Proof of Reserves reports verified by independent third-party auditors.

1:1

Reserve Ratio

Infrastructure Security

Multi-layered defense architecture with DDoS protection, WAF, and real-time intrusion detection.

99.99%

Uptime

24/7 Monitoring

Dedicated security operations center with real-time threat monitoring and incident response.

24/7

Monitoring

Account Protection Features

Biometric Authentication

Support for fingerprint and face recognition on mobile devices.

Hardware Key Support

YubiKey and other FIDO2/WebAuthn hardware security keys supported.

2FA Required

Two-factor authentication via Google Authenticator or SMS for all critical operations.

Anti-Phishing Code

Set a personal anti-phishing code that appears in all official Bybit emails.

Withdrawal Whitelist

Restrict withdrawals to pre-approved addresses only with a 24-hour lock period for changes.

Login Notifications

Instant alerts for new device logins, IP changes, and suspicious activity.

Certifications & Programs

SOC 2 Type II

Annual audit of security controls and operations.

ISO 27001

International standard for information security management.

CSA STAR

Cloud Security Alliance certification for cloud security.

Bug Bounty Program

Up to $100K rewards for security researchers.

Security Updates

2025 Q4

Completed SOC 2 Type II annual audit with zero findings.

2025 Q3

Launched hardware security key support for all users.

2025 Q2

Published first Merkle Tree Proof of Reserves report.

2025 Q1

Upgraded cold storage infrastructure to multi-party computation (MPC).

2024 Q4

Achieved ISO 27001 certification.

2024 Q3

Expanded bug bounty program to $100K maximum reward.