Insights
How AI and Automation Are Changing Blockchain Security

The USD 1.5 billion Bybit breach exposed critical weaknesses in digital asset security. SOOHO.IO’s AI-powered Reagent brings continuous monitoring and automated response to the challenge of protecting blockchain assets.
When USD 1.5 billion disappeared
On February 21, 2025, cryptocurrency exchange Bybit was carrying out a routine transfer from an Ethereum cold wallet to a hot wallet. That ordinary operation became one of the largest digital asset thefts in history.
Approximately 401,000 ETH—worth around USD 1.5 billion, or KRW 2 trillion, at the time—was stolen.
The assets left the cold wallet but went to an attacker’s wallet instead of the intended destination. Blockchain analytics company Elliptic described it as the largest known single theft in history.

Major cryptocurrency thefts. Source: Elliptic.
Despite the industry’s growing maturity, large-scale breaches continue. Losses from cryptocurrency hacks exceeded USD 2 billion in 2024, marking the fourth consecutive year in which annual thefts exceeded USD 1 billion. Source: Reuters.
The Bybit incident challenged the assumption that cold storage alone is enough. Keeping keys offline reduces certain risks, but the systems and processes used to authorize transactions can still be compromised.
How attackers are adapting
The Bybit breach involved more than a single technical flaw. According to Chainalysis’s analysis, the attack involved sophisticated phishing and social engineering. The signers were misled into approving a malicious transaction that altered the multisignature wallet’s contract logic.
The incident illustrates a difficult reality: technical controls alone are not enough. Human decisions and the interfaces people rely on can undermine even a strong security architecture.
GK8 CTO Shahar Shamai described the attack as a combination of computer intrusion, social engineering, and smart contract weaknesses. Source: Ledger Insights.
His analysis highlighted an Operation parameter set to 1 rather than 0, allowing delegateCall to be used to take control of the wallet.
The attack was attributed to the North Korea-linked Lazarus Group. Chainalysis reported that North Korean hackers stole USD 1.34 billion across 47 incidents in 2024; the Bybit theft alone exceeded that annual total.
Major cryptocurrency thefts
Bybit was the largest incident at the time, but earlier attacks had already exposed a range of weaknesses in blockchain security:
1. Poly Network — August 2021
Amount stolen: USD 610 million
Weakness: Cross-chain bridge vulnerabilities and flaws in permissions between contracts.
2. Ronin Network — March 2022
Amount stolen: USD 540 million
Weakness: Concentrated validator control and bridge security weaknesses.
3. Coincheck — January 2018
Amount stolen: USD 530 million
Weakness: Inadequate hot-wallet security and the absence of multisignature controls.
4. Mt. Gox — 2011–2014
Amount stolen: USD 500 million
Weakness: Weak internal security controls and flaws in wallet management.
5. Wormhole — February 2022
Amount stolen: USD 320 million
Weakness: A smart contract flaw that allowed signature verification to be bypassed.
Recurring weaknesses in blockchain security
These incidents reveal several common patterns:
1. Smart contract vulnerabilities
Smart contracts are central to blockchain applications, but flaws in their code can create serious risks. Because deployed contracts can be difficult to change, even a small bug may expose hundreds of millions of dollars in assets.
2. Complexity across DeFi protocols
As decentralized finance grows more interconnected, interactions between protocols introduce additional security risks.
3. Concentrated control in exchanges and bridges
Even within an ecosystem built around decentralization, exchanges and bridges can become concentrated points of failure and attractive targets for attackers.
4. Exposure to social engineering
As Bybit demonstrated, phishing, spoofing, and other forms of social engineering can undermine technical security controls.
5. Monitoring systems that operate around the clock
Blockchain networks run continuously, but manual monitoring makes immediate response difficult. A response delay averaging more than four hours, as discussed here, can give attackers ample time to move millions of dollars in assets.
The need for a different approach
Bybit and earlier incidents call for a fundamental reassessment of blockchain security. With billions of dollars at stake, organizations need to ask:
How can smart contract vulnerabilities be identified and addressed before an attack?
How can threats be handled in real time, around the clock, with less dependence on manual intervention?
How can organizations strengthen both technical controls and human decision-making?
How can they improve fund tracing and the prospects of recovery after a breach?
Blockchain security needs to place greater emphasis on prevention, supported by AI and automation as well as incident response.
That is the challenge SOOHO.IO’s Reagent is designed to address.

Reagent: AI-powered blockchain security
Developed by SOOHO.IO, Reagent applies AI-driven automation to blockchain security. It draws on the company’s smart contract auditing experience since 2019 to support continuous protection of blockchain networks.
The security track record presented here includes:
📊 280,000+ security audit reports issued
💰 USD 2.4 billion+ in assets protected
🔍 24,000+ vulnerabilities identified proactively
🤝 200+ partnerships
What makes blockchain security different?
Blockchain presents several challenges that differ from those of conventional IT systems.
1. Transactions are difficult to reverse
Once a blockchain transaction is finalized, it generally cannot be reversed, making recovery after an attack exceptionally difficult.
2. Contracts execute their code
Smart contracts follow their deployed logic, including unintended bugs. A small mistake in that logic can therefore have significant consequences.
3. Attacks can happen at any time
Networks do not close for weekends, holidays, or overnight hours. Attackers can act at any time, while security teams face the practical limits of human availability.
4. Attack vectors keep evolving
Flash-loan attacks, reentrancy vulnerabilities, and MEV-related attacks are among the blockchain-specific techniques that require specialized defenses.
How Reagent addresses these challenges
Reagent is designed around the security requirements of blockchain environments.
Intelligent monitoring
Alongside predefined rules, Reagent uses AI and machine learning to learn patterns of normal blockchain activity and detect deviations in real time.
Unusual gas usage, unexpected token movements, and suspicious contract calls can be identified quickly, helping security teams investigate anomalies more efficiently.
Rapid response
Reagent is designed to respond to detected threats in milliseconds. Shortening the interval between detection and action can help limit the potential impact of an attack.
Continuous improvement
Reagent learns from emerging attack patterns and defensive techniques. Data gathered across hundreds of blockchain networks helps inform its ability to anticipate and prepare for new threats.
Where Reagent can be used
Automated security systems such as Reagent can support a range of blockchain environments:
Central bank digital currency systems
Reagent has been introduced into a central bank CBDC project to strengthen the security of voucher management. It supports the demanding security requirements associated with national financial infrastructure through:
Pre-deployment smart contract audits to identify vulnerabilities early
Security risk reduction before launch
Real-time monitoring for suspicious activity
Large-scale DeFi protocols
Protocols managing substantial assets face complex contract structures and cross-chain operations. Automated security can help them:
Detect and respond to attack attempts in real time
Identify and remediate smart contract vulnerabilities proactively
Improve operational efficiency and shorten response times
Building a more secure blockchain ecosystem
Blockchain is changing finance, logistics, healthcare, and other industries. Sustainable adoption depends on security being built into that progress.
SOOHO.IO positions Reagent as infrastructure for a more secure blockchain ecosystem. With the track record outlined above—280,000 reports, USD 2.4 billion in assets protected, and more than 200 partnerships—it helps organizations strengthen their approach to digital asset security.
Strengthen your blockchain security with Reagent.
Book a complimentary consultation with a SOOHO.IO blockchain security specialist.
We will help identify the approach that fits your environment.
SOOHO.IO Official Channels
Website: https://www.sooho.io/
X (Twitter): https://twitter.com/soohoio
LinkedIn: https://www.linkedin.com/company/sooho/



