A fake Bybit login page captured your credentials. The attacker accessed your account, disabled security features, and withdrew your crypto. Bybit's compliance team in Dubai can freeze the receiving account — but they're slower than Binance (5-14 business days) and require a police report. We trace the stolen funds on-chain and file emergency freeze requests before the attacker can cash out.
Phishing attacks on Bybit users follow the same pattern as Binance phishing but with Bybit-specific elements. The attacker creates a fake Bybit login page — bybit-secure-login.com, bybit-verify-account.net, or bybit-support-verify.com. The victim receives a phishing email ("Bybit Security: Unusual login activity") or a Telegram message from a fake Bybit support agent. They enter credentials on the fake page, and the attacker captures them in real-time.
The derivatives complication: Bybit is derivatives-focused — many users have open perpetual futures positions. A phishing attacker who gains access to your Bybit account can not only withdraw spot balances but also close your futures positions and withdraw the released margin. This means the damage can be larger than your visible account balance — open positions that get liquidated by the attacker add to your losses.
Bybit's anti-phishing phrase: Bybit offers an anti-phishing phrase feature — a custom word that appears in all legitimate Bybit emails. If you set this up and an email doesn't contain your phrase, it's fake. However, most users don't enable this feature, and attackers have started including fake anti-phishing phrases in their phishing emails (by guessing common phrases like "Bybit" or "Secure").
The geo-restriction problem: Bybit geo-restricts its services in certain countries (US, UK, parts of Canada). If you're in a restricted region, you may have accessed Bybit through a VPN — which means you can't contact Bybit support through their official channels (they'll detect your geo-restriction). This is a unique challenge for Bybit phishing victims. We handle all communication through our Swiss office, bypassing these restrictions.
Compliance structure: Bybit's compliance team operates from Dubai under VARA regulation. They process legal requests through their compliance email and law enforcement portal. Bybit does not publish response time statistics. In our experience, properly formatted legal requests receive a response within 5-14 business days — slower than Binance (3-7 days) but faster than MEXC (7-21 days).
Freeze capability: Bybit can freeze the attacker's receiving account but requires a police report or court order — not just a private attorney's letter. Bybit is generally more cooperative with requests from jurisdictions where they are regulated (UAE, EU under MiCA). For requests from non-regulated jurisdictions, Bybit may require MLAT channels.
KYC disclosure: Bybit discloses account holder information to law enforcement or through a court order. Bybit's KYC (mandatory since 2023) includes: government ID, selfie verification, and proof of address. The attacker's real identity is on file — they cannot cash out anonymously on Bybit.
The derivatives liquidation risk: If the attacker accessed your Bybit account and you have open futures positions, they can close your positions and withdraw the margin. This happens fast — sometimes within minutes of the phishing attack. We check whether positions were liquidated by the attacker and whether the liquidated margin can be traced. Unfortunately, futures losses (where the attacker closes positions at a loss to you) are generally unrecoverable — the loss went to the market counterparties.
A client received a Telegram message from an account impersonating Bybit support: "Your account requires immediate verification due to suspicious API activity." The message contained a link to bybit-verify-api.com. The client entered their email, password, and Google Authenticator code on the fake page.
The attack: Within 15 minutes, the attacker logged into the real Bybit, closed the client's open ETH perpetual long positions (releasing €45,000 in margin), and withdrew the total balance of €110,000 (€65,000 spot + €45,000 released margin) to an external wallet. The external wallet then sent funds to a Bybit deposit address — the attacker's own Bybit account.
Our response: The client contacted us 8 hours after the attack. We traced the withdrawal on-chain — funds went to an external wallet, then to a Bybit deposit address. We filed an emergency freeze request with Bybit's Dubai compliance team. Bybit froze the attacker's account (containing €78,000 in USDT) within 7 business days. The attacker's KYC revealed a resident of Turkey.
Outcome: 71% recovery (€78,000 of €110,000). The €45,000 in futures margin was recoverable because the attacker hadn't traded it — they withdrew directly. The €32,000 gap was due to the attacker withdrawing to a second wallet before the freeze. Criminal proceedings initiated through Turkish authorities.
Details anonymized to protect client confidentiality. Swiss professional secrecy applies.
Was your own Bybit account also frozen? Bybit may restrict victim accounts after phishing incidents. Our Bybit account unlock practice can resolve this while we trace the stolen funds.
Warning: After a phishing attack, fake "recovery services" will contact you. Read our recovery scam warning before engaging anyone.
Three key differences: (1) Bybit's compliance team is slower (5-14 days vs Binance's 3-7 days). (2) Bybit is derivatives-focused — attackers can close your futures positions and withdraw the released margin, potentially causing more damage than your visible spot balance. (3) Bybit geo-restricts certain countries — if you accessed Bybit through a VPN, you can't contact their support directly without risking account closure. We bypass this by communicating through our Swiss office.
It depends. If the attacker closed your positions and withdrew the released margin to their own account, the margin is traceable and potentially recoverable (it's a direct withdrawal). However, if the attacker manipulated your positions to cause liquidation (e.g., closing at a market loss), those trading losses went to market counterparties and are generally unrecoverable. We trace the actual withdrawn amounts — not the paper losses from position closure.
Yes, but Bybit requires a police report or court order — not just a private attorney's letter. Bybit's Dubai compliance team (VARA-regulated) processes these requests. Response time: 5-14 business days. For non-UAE jurisdictions, we use MLAT or coordinate with law enforcement in VARA-recognized jurisdictions. Bybit cannot ignore properly formatted international legal requests.
Yes. Bybit geo-restricts certain countries (US, UK, parts of Canada), but the attacker's account is not restricted. We file the legal request from our Swiss office, which is not subject to Bybit's geo-restrictions. The freeze applies to the attacker's account regardless of your location. You should not contact Bybit directly — your geo-location may trigger account closure. We handle all communication.
Yes — Bybit offers an anti-phishing phrase that appears in all legitimate Bybit emails. If you set this up and an email doesn't contain your phrase, it's fake. However, most users don't enable this feature. Attackers have also started guessing common anti-phishing phrases. We recommend setting a unique, random phrase — not something predictable like "Bybit" or "Secure."
Yes — Bybit support does not initiate contact on Telegram. Legitimate Bybit support is only available through the Bybit app or bybit.com official channels. Telegram accounts claiming to be Bybit support are always scammers. They typically ask for your email, password, 2FA code, or remote screen access (AnyDesk). Never share these. If you already shared credentials, change your password immediately, disable active sessions, and contact us.
Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. We respond within 6 hours.