Insights

How AI and Automation Are Changing Blockchain Security

The USD 1.5 billion Bybit breach exposed critical weaknesses in digital asset security. SOOHO.IO’s AI-powered Reagent brings continuous monitoring and automated response to the challenge of protecting blockchain assets.

When USD 1.5 billion disappeared

On February 21, 2025, cryptocurrency exchange Bybit was carrying out a routine transfer from an Ethereum cold wallet to a hot wallet. That ordinary operation became one of the largest digital asset thefts in history.

Approximately 401,000 ETH—worth around USD 1.5 billion, or KRW 2 trillion, at the time—was stolen.

The assets left the cold wallet but went to an attacker’s wallet instead of the intended destination. Blockchain analytics company Elliptic described it as the largest known single theft in history.

Major cryptocurrency thefts. Source: Elliptic.

Despite the industry’s growing maturity, large-scale breaches continue. Losses from cryptocurrency hacks exceeded USD 2 billion in 2024, marking the fourth consecutive year in which annual thefts exceeded USD 1 billion. Source: Reuters.

The Bybit incident challenged the assumption that cold storage alone is enough. Keeping keys offline reduces certain risks, but the systems and processes used to authorize transactions can still be compromised.

How attackers are adapting

The Bybit breach involved more than a single technical flaw. According to Chainalysis’s analysis, the attack involved sophisticated phishing and social engineering. The signers were misled into approving a malicious transaction that altered the multisignature wallet’s contract logic.

The incident illustrates a difficult reality: technical controls alone are not enough. Human decisions and the interfaces people rely on can undermine even a strong security architecture.

GK8 CTO Shahar Shamai described the attack as a combination of computer intrusion, social engineering, and smart contract weaknesses. Source: Ledger Insights.
His analysis highlighted an Operation parameter set to 1 rather than 0, allowing delegateCall to be used to take control of the wallet.

The attack was attributed to the North Korea-linked Lazarus Group. Chainalysis reported that North Korean hackers stole USD 1.34 billion across 47 incidents in 2024; the Bybit theft alone exceeded that annual total.


Major cryptocurrency thefts

Bybit was the largest incident at the time, but earlier attacks had already exposed a range of weaknesses in blockchain security:

1. Poly Network — August 2021

Amount stolen: USD 610 million
Weakness: Cross-chain bridge vulnerabilities and flaws in permissions between contracts.

2. Ronin Network — March 2022

Amount stolen: USD 540 million
Weakness: Concentrated validator control and bridge security weaknesses.

3. Coincheck — January 2018

Amount stolen: USD 530 million
Weakness: Inadequate hot-wallet security and the absence of multisignature controls.

4. Mt. Gox — 2011–2014

Amount stolen: USD 500 million
Weakness: Weak internal security controls and flaws in wallet management.

5. Wormhole — February 2022

Amount stolen: USD 320 million
Weakness: A smart contract flaw that allowed signature verification to be bypassed.


Recurring weaknesses in blockchain security

These incidents reveal several common patterns:


1. Smart contract vulnerabilities

Smart contracts are central to blockchain applications, but flaws in their code can create serious risks. Because deployed contracts can be difficult to change, even a small bug may expose hundreds of millions of dollars in assets.


2. Complexity across DeFi protocols

As decentralized finance grows more interconnected, interactions between protocols introduce additional security risks.


3. Concentrated control in exchanges and bridges

Even within an ecosystem built around decentralization, exchanges and bridges can become concentrated points of failure and attractive targets for attackers.


4. Exposure to social engineering

As Bybit demonstrated, phishing, spoofing, and other forms of social engineering can undermine technical security controls.


5. Monitoring systems that operate around the clock

Blockchain networks run continuously, but manual monitoring makes immediate response difficult. A response delay averaging more than four hours, as discussed here, can give attackers ample time to move millions of dollars in assets.


The need for a different approach

Bybit and earlier incidents call for a fundamental reassessment of blockchain security. With billions of dollars at stake, organizations need to ask:

  • How can smart contract vulnerabilities be identified and addressed before an attack?

  • How can threats be handled in real time, around the clock, with less dependence on manual intervention?

  • How can organizations strengthen both technical controls and human decision-making?

  • How can they improve fund tracing and the prospects of recovery after a breach?

Blockchain security needs to place greater emphasis on prevention, supported by AI and automation as well as incident response.

That is the challenge SOOHO.IO’s Reagent is designed to address.



Reagent: AI-powered blockchain security

Developed by SOOHO.IO, Reagent applies AI-driven automation to blockchain security. It draws on the company’s smart contract auditing experience since 2019 to support continuous protection of blockchain networks.

The security track record presented here includes:

  • 📊 280,000+ security audit reports issued

  • 💰 USD 2.4 billion+ in assets protected

  • 🔍 24,000+ vulnerabilities identified proactively

  • 🤝 200+ partnerships


What makes blockchain security different?

Blockchain presents several challenges that differ from those of conventional IT systems.


1. Transactions are difficult to reverse

Once a blockchain transaction is finalized, it generally cannot be reversed, making recovery after an attack exceptionally difficult.


2. Contracts execute their code

Smart contracts follow their deployed logic, including unintended bugs. A small mistake in that logic can therefore have significant consequences.


3. Attacks can happen at any time

Networks do not close for weekends, holidays, or overnight hours. Attackers can act at any time, while security teams face the practical limits of human availability.


4. Attack vectors keep evolving

Flash-loan attacks, reentrancy vulnerabilities, and MEV-related attacks are among the blockchain-specific techniques that require specialized defenses.



How Reagent addresses these challenges

Reagent is designed around the security requirements of blockchain environments.


Intelligent monitoring

Alongside predefined rules, Reagent uses AI and machine learning to learn patterns of normal blockchain activity and detect deviations in real time.

Unusual gas usage, unexpected token movements, and suspicious contract calls can be identified quickly, helping security teams investigate anomalies more efficiently.


Rapid response

Reagent is designed to respond to detected threats in milliseconds. Shortening the interval between detection and action can help limit the potential impact of an attack.


Continuous improvement

Reagent learns from emerging attack patterns and defensive techniques. Data gathered across hundreds of blockchain networks helps inform its ability to anticipate and prepare for new threats.



Where Reagent can be used

Automated security systems such as Reagent can support a range of blockchain environments:


Central bank digital currency systems

Reagent has been introduced into a central bank CBDC project to strengthen the security of voucher management. It supports the demanding security requirements associated with national financial infrastructure through:

  • Pre-deployment smart contract audits to identify vulnerabilities early

  • Security risk reduction before launch

  • Real-time monitoring for suspicious activity


Large-scale DeFi protocols

Protocols managing substantial assets face complex contract structures and cross-chain operations. Automated security can help them:

  • Detect and respond to attack attempts in real time

  • Identify and remediate smart contract vulnerabilities proactively

  • Improve operational efficiency and shorten response times


Building a more secure blockchain ecosystem

Blockchain is changing finance, logistics, healthcare, and other industries. Sustainable adoption depends on security being built into that progress.

SOOHO.IO positions Reagent as infrastructure for a more secure blockchain ecosystem. With the track record outlined above—280,000 reports, USD 2.4 billion in assets protected, and more than 200 partnerships—it helps organizations strengthen their approach to digital asset security.



Strengthen your blockchain security with Reagent.

Book a complimentary consultation with a SOOHO.IO blockchain security specialist.
We will help identify the approach that fits your environment.



SOOHO.IO Official Channels

Recommended Articles

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.

START WITH SOOHO.IO

Build the future of finance with SOOHO.IO.