Skip to content
EX Exchange Atlas

Bybit Review

Founded 2018 · Bybit Affiliate / Partner (direct)

EU MiCA CASP

By Ledger

Visit site

Bybit is a large Dubai-headquartered derivatives exchange known for perpetual futures. Its EU entity, Bybit EU GmbH, holds a confirmed MiCA CASP authorisation via Austria's FMA (granted 28/05/2025, verified on the ESMA register 09/07/2026) — a change from earlier in 2026 when its status was unconfirmed. Separately, it suffered the largest crypto hack in history in February 2025 — approximately $1.5B in ETH stolen from a cold wallet. The exchange remained operational throughout and its founder responded publicly, but the incident is material information for any prospective user, independent of its licensing status.

Regulatory Standing

Bybit is headquartered in Dubai and operates globally, but its regulatory footprint is uneven. It has received regulatory warnings or restrictions in multiple jurisdictions, including the UK (FCA) and several EU member states.

Under the EU's Markets in Crypto-Assets (MiCA) regulation, Bybit's EU entity, Bybit EU GmbH, holds a confirmed CASP (Crypto-Asset Service Provider) authorisation granted by Austria's FMA on 28/05/2025, verified directly against ESMA's official register on 09/07/2026.

A CASP authorisation passports across the EU/EEA, but EU-based users should still verify the current live entry and consult their own national regulator before trading, as authorisation status can change.

This is factual information only, not financial advice. Regulation can change; check the ESMA CASP register and your local regulator for current status.

The February 2025 Security Incident

In February 2025, Bybit disclosed that approximately $1.5 billion in ETH had been stolen from a cold wallet — widely reported as the largest crypto exchange hack in history.

The theft occurred via a compromised Safe{Wallet} smart contract interface. Attackers manipulated the signing process during a routine transfer, enabling them to redirect funds to an attacker-controlled address despite appearing as a legitimate multisig transaction.

Bybit's founder Ben Zhou responded publicly, confirming the breach, asserting that user funds were covered, and pledging to replace the stolen assets. The exchange remained operational throughout and subsequently published updates on the investigation and asset restoration.

Independent blockchain security researchers attributed the attack to the Lazarus Group, a North Korea-linked threat actor responsible for multiple large-scale crypto thefts.

The incident highlights supply-chain risk in smart contract infrastructure, even for assets held in cold storage. It is material information that any prospective Bybit user should weigh.

Products and Platform

Bybit's core offering is derivatives trading — particularly perpetual futures contracts across crypto pairs. It is widely used by active traders for its liquidity depth and range of contracts.

The platform also offers spot trading, options, copy trading, and an earn/yield product suite.

Bybit has published Proof of Reserves (PoR) reports, providing Merkle-tree attestations of on-chain asset holdings relative to user liabilities. PoR provides partial transparency but is not equivalent to a full third-party audit.

The trading interface is considered feature-rich, with advanced order types suitable for experienced derivatives traders.

Status and Summary

Bybit is a large, operationally active exchange with a strong derivatives product suite. Its EU entity now holds a confirmed MiCA CASP authorisation (Austria/FMA, May 2025) — but it also suffered the largest hack in crypto exchange history in February 2025, and that history is a separate, material fact from its licensing status.

The exchange's public response to the hack and its continued operation are noted, but the incident represents a significant risk event that distinguishes Bybit from exchanges with no comparable breach history.

EU-resident users should still verify the current live MiCA compliance status on the ESMA register before depositing funds, as authorisation status can change. This review is provided as independent public information; it is not financial advice.

Strengths & limitations

Strengths

  • Established derivatives-focused exchange (since 2018) with spot and earn products.
  • Deep liquidity in perpetual futures (where legally available to you).

Limitations

  • Suffered the largest crypto exchange hack on record (~US$1.5B, February 2025) — a material risk factor independent of its now-confirmed EU licence.
  • Derivatives-heavy; heavily restricted by country, and leverage sharply increases risk.
  • We have not completed a hands-on test, so we publish no fees, limits or rating.

Frequently asked questions

Was Bybit hacked?

Yes. In February 2025, Bybit suffered a breach in which approximately $1.5 billion in ETH was stolen from a cold wallet via a compromised Safe{Wallet} smart contract. It is the largest crypto exchange hack on record. The exchange remained operational, founder Ben Zhou responded publicly, and the exchange asserted that user funds were covered. The breach is material information any prospective user should consider.

Is Bybit regulated in the EU under MiCA?

Yes. As checked against ESMA's official MiCA CASP register on 09/07/2026, Bybit's EU entity, Bybit EU GmbH, holds a full MiCA CASP authorisation granted by Austria's FMA on 28/05/2025. This is a change from earlier in 2026, when Bybit's status was unconfirmed. EU-based users should still check the live ESMA register entry before relying on it, as authorisation status can change.

Does Bybit have Proof of Reserves?

Yes, Bybit has published Proof of Reserves reports using Merkle-tree attestation, allowing users to verify that on-chain holdings correspond to stated user liabilities. PoR provides a degree of transparency but is not a substitute for a comprehensive third-party financial audit.