Bybit has published Proof of Reserves (PoR) reports since December 2022, and the September 2026 report is its 40th. The latest snapshot was taken at 03:00 UTC on 23 September 2026, covering 50 coins with a Merkle tree. Unlike the current PoR pages of Binance and OKX, Bybit's "Independent Audit Report" page lists monthly PoR audit reports from the blockchain security firm Hacken.
Bybit is also the exchange behind the February 2025 ETH cold wallet theft. This guide covers the latest ratios on the official page, the PoR figures before and after that incident, what the Hacken audits cover, two ways to verify for yourself, and the account and withdrawal protections you can switch on. First, one thing: binding a fee rebate only takes your UID, and your assets stay in your own Bybit account.
Key points
- Report 40 (snapshot 2026-09-23): BTC 104%, ETH 103%, USDT 110%, USDC 223%. The lowest of the 50 coins is 100%.
- Third-party audit: the official "Independent Audit Report" page lists Hacken's monthly PoR audits; the latest listed is dated 26 August 2026.
- Accounts covered: trading accounts (Spot, Futures, Options, Unified Margin) and Funding accounts; sub-account assets are combined with the main account.
- 21 February 2025 incident: an ETH multisig cold wallet was attacked during a routine transfer. Bybit reported more than 400,000 ETH and stETH worth over US$1.4 billion taken, and said withdrawals were not halted.
- Account protection: Google 2FA, fund password, passkey, anti-phishing code, a 24-hour lock on new withdrawal addresses, and an address whitelist.
Report 40: major assets
Figures come from the Bybit Proof of Reserves page and the official public endpoint behind its reserve ratio page. Snapshot 2026-09-23 03:00 UTC; checked 2026-09-28.
| Asset | User assets | Bybit reserves | Reserve ratio |
|---|---|---|---|
| BTC | 56,131.76 | 58,721.99 | 104% |
| ETH | 551,868.68 | 570,018.31 | 103% |
| USDT | about 3.59 billion | about 3.96 billion | 110% |
| USDC | about 0.33 billion | about 0.75 billion | 223% |
Amounts are in units of each asset. Reserve ratio = reserves ÷ user assets, shown as a whole percent. The live official page prevails.
USDC reaches 223% because users hold relatively little USDC against the reserves, which magnifies the ratio; it has also moved the most in recent reports (see below). A reserve ratio only answers whether the wallets covered user assets at the snapshot. How far it sits above 100% says nothing about the exchange's overall finances.
The page states that user assets in scope are the personal portions of trading accounts (Spot, Futures, Options, Unified Margin) and Funding accounts, with sub-account assets shown together with the main account. It also notes that floating items such as open P&L, leverage, borrowing and wealth products can make net values differ slightly.
Recent reports and the February 2025 incident
The official endpoint keeps all 40 reports. These are the four major assets in the seven most recent 2026 reports (UTC):
| Snapshot date | BTC | ETH | USDT | USDC |
|---|---|---|---|---|
| 2026-09-23 | 104% | 103% | 110% | 223% |
| 2026-08-26 | 107% | 101% | 109% | 180% |
| 2026-07-22 | 104% | 102% | 105% | 174% |
| 2026-06-24 | 108% | 103% | 106% | 143% |
| 2026-05-27 | 108% | 104% | 106% | 164% |
| 2026-04-22 | 109% | 102% | 107% | 159% |
| 2026-03-18 | 108% | 101% | 108% | 104% |
Around February 2025, three reports in the official record are worth comparing:
| Snapshot (UTC) | BTC | ETH | USDT | USDC |
|---|---|---|---|---|
| 2025-01-16 | 113% | 109% | 113% | 117% |
| 2025-02-20 (day before the incident) | 103% | 101% | 115% | 120% |
| 2025-02-26 (five days after) | 102% | 102% | 104% | 229% |
The 26 February report fell outside the usual monthly rhythm; it was an extra report after the incident. A Bybit Learn article on 28 February 2025 also mentions an additional PoR audit after the incident. In that report the ETH reserve ratio was still above 100%.
The 21 February 2025 ETH cold wallet incident (official announcements)
According to Bybit's incident announcement that day:
- At about 12:30 UTC on 21 February 2025, during a routine move of ETH from a multisig cold wallet to a hot wallet, Bybit detected unauthorized activity in one ETH cold wallet. The attacker altered the smart contract logic and masked the signing interface to take control of that wallet.
- More than 400,000 ETH and stETH worth over US$1.4 billion went to an unidentified address.
- Bybit said all other cold wallets, including BTC, were secure and client funds were unaffected. Withdrawals were not halted, though volume could cause delays. AUM exceeded US$20 billion, and a bridge loan would be used if necessary to keep user funds available.
- One focus of the investigation was a potential vulnerability in the user interface of the Safe.global platform.
A follow-up announcement on 24 February 2025 said US$42.89 million in assets had been frozen with the help of other institutions, 254,830 ETH (about US$693 million) had been secured through OTC and other channels within 48 hours, and the bounty for recovered funds was raised to 10% of the amount recovered.
The incident happened between two snapshots, which shows what a PoR is: proof of the state at one moment. It cannot flag in advance that a wallet will be attacked. Alongside the PoR, it is worth looking at how an exchange handles incidents and whether it explains them publicly.
What the Hacken audits cover
Bybit's Independent Audit Report page lists the audit date, firm, scope and report file month by month. On the page checked 2026-09-28, the ten most recent entries (November 2025 to August 2026) all name HACKEN as the firm, with the scope "Proof of Reserves" and the repository Bybit's open-source merkle-proof. The latest is dated 26 August 2026; the report for the 23 September snapshot was not yet listed on the check date.
Note that Hacken is a blockchain security firm, and the scope is the Proof of Reserves itself, not an audit opinion on the company's financial statements from an accounting firm.
Verify it yourself: two methods
Method 1: confirm your assets are in the Merkle tree
According to the official guide, Bybit offers two ways:
- On the Bybit platform: click "Verify My Account" on the PoR page to see your Merkle path, with the node derivation shown graphically.
- With the open-source code: Bybit publishes its Merkle tree generation and verification code (Java) on GitHub. Install JDK 1.8 or later and Maven, build it, save the data from "Copy Data" on the PoR page as myProof.json in the same folder, and run the verifier.
If you opened your account after an audit, or held none of the audited tokens at the snapshot, there will be no record for that report.
Method 2: confirm wallet ownership and balances
According to the official guide (updated 2026-08-24):
- Ownership via "Send to Self": each newly published address sends a specific amount to itself at a set time. The amount comes from the nonce of the first Bitcoin block after 12:30 UTC on 11 December 2022, using "first three digits of the nonce ÷ 1,000,000". Transaction hashes are published so anyone can check them in a block explorer. Chains that do not support sending to oneself, such as TRON, use transfers between published addresses instead.
- BTC balance: Bybit publishes four BTC wallet addresses. Blockchair's Wallet statement feature can generate a statement for the snapshot date, and the four ending balances add up to the BTC reserve.
- ETH and stablecoin balances: spread across ETH, Arbitrum, BSC, Optimism, Polygon, Avalanche, Tron and other chains. Bybit provides a Python balance-checker; set the snapshot block height and it queries the addresses in bulk.
What Bybit's PoR cannot answer
These are general properties of the PoR method, not a judgment of Bybit:
- Point-in-time snapshot: movements before or after the snapshot are out of scope; the February 2025 incident happened between two snapshots.
- Listed coins only: this report covers 50 coins; other assets are not included.
- Not full financial statements: it shows the user-asset side is fully reserved but says nothing about other liabilities or operations.
- Limited audit scope: Hacken audits the PoR, which is not the same as a financial statement audit.
A PoR is a transparency tool, not regulation or insurance. It sits alongside, not in place of, wallet security and incident response.
Platform and account security
On the platform side, according to the Bybit user protection page, user funds are kept offline in cold wallets, protected from unauthorized access with multi-signature, a Trusted Execution Environment (TEE) and Threshold Signature Schemes (TSS), and Bybit runs a bug bounty program with HackerOne. The page does not publish the size of a user protection fund, so this article does not list one.
On the account side, the official account security guide recommends:
- Google 2FA: turn it on right after logging in and disable account sync in Google Authenticator; also enable 2FA on your email account.
- Passkey and Secure Transaction Approval: a passkey uses biometrics on your device; Secure Transaction Approval lets you name a primary device that must confirm high-risk actions.
- Freeze when in doubt: if you suspect your account is at risk, deactivate it from the account security page or via the link in a new-address or new-device email.
Withdrawal-side settings such as the fund password, anti-phishing code, 24-hour lock on new addresses, withdrawal address whitelist and app-only withdrawals are listed in Bybit's withdrawal security guide; how to use them, and which actions trigger a 24-hour withdrawal hold, are covered in Bybit deposits and withdrawals.
A note for users in Taiwan
Bybit is not on Taiwan's Financial Supervisory Commission (FSC) list of virtual asset service providers that have completed AML registration. See Offshore Crypto Exchanges in Taiwan: FSC Register Check. A PoR and a third-party PoR audit are transparency measures and a separate matter from regulatory supervision.
How rebates relate to asset safety
They do not directly. A rebate only needs your UID to match trading fees; no password, API key or asset permissions. More in Are Crypto Fee Rebates Real? Is Binding a Code Safe? Quant Nova's Bybit rebate is 30% for new users at Lv.1, 35% at SVIP (reachable through trading volume), and up to 40% at the invite-only Supernova tier, settled daily with every entry traceable. Rates and binding steps are in the Bybit fee rebate guide.
FAQ
How often does Bybit update its Proof of Reserves?
Roughly monthly, but not on a fixed date; in 2026 snapshots fell in the middle or second half of each month. An extra report was also made during the incident period (2025-02-26).
Is Bybit's PoR audited by a third party?
Yes. The official "Independent Audit Report" page lists Hacken's monthly PoR audit reports. The scope is the PoR, not the company's financial statements.
Is a 223% USDC ratio unusual?
A high ratio means reserves were large relative to what users held at the snapshot. Because users hold a smaller amount of USDC, the ratio also swings more. The main thing to watch is whether it drops below 100%.
Were user assets affected by the 2025 theft?
According to the official announcements, one ETH cold wallet was compromised, other cold wallets were secure, client funds were unaffected and withdrawals were not halted; 254,830 ETH was secured within 48 hours. In the 2025-02-26 PoR after the incident, the ETH reserve ratio was 102%.
Further reading
- Bybit fee rebate guide: rates and binding steps.
- Bybit deposits and withdrawals.
- Are crypto fee rebates real and safe?
- Taiwan FSC register and the status of 11 exchanges.
Reserve ratios, audit records and rules come from Bybit's official PoR page, its public endpoint, help center and announcements, checked 2026-09-28. Bybit may change them; the live official pages prevail. This article is for information only and is not investment advice.