Bybit Names Restricted Crypto Counterparties as Hack Risks Rise

Sep 25, 2026, 9:50 p.m. 2 sources negative

Key takeaways:

  • USDT and USDC issuer blacklists show token-level controls now reinforce exchange KYC against stolen funds.
  • Bybit's broad counterparty screening may push illicit flows toward DEXs, raising DeFi compliance risks.
  • Traders should watch withdrawal halts and protection funds as breach attribution risks sector-wide compliance tightening.

Bybit has published a Restricted Counterparty List identifying platforms, mixers, darknet markets, payment services and sanctioned organizations that users are prohibited from transacting with through the exchange. The list includes Garantex, Bitzlato, EXMO, Payeer, Nobitex, Huione Guarantee, Xinbi Guarantee, Bitcoin Fog, ChipMixer, Sinbad, Samourai Wallet, Hydra Market and the Lazarus Group, among others.

According to Bybit, the exchange actively screens transactions and user activity on an ongoing basis. If it detects a direct or indirect connection to a restricted entity, it may block transactions or funds, suspend or terminate accounts, file regulatory reports, liquidate open positions and cooperate with regulators or law enforcement. The published names are not exhaustive, and absence from the list does not mean a counterparty is acceptable.

The publication comes after Bitget reported a $351.6 million security breach on September 24, 2026. Bitget said unauthorized transfers were detected at 18:31 UTC, while cold wallets and the overwhelming majority of platform assets remained unaffected. The exchange temporarily suspended withdrawals, kept trading and deposits available, and said the incident falls within its User Protection Fund, which held more than $464 million.

Binance co-founder Changpeng Zhao said Binance, BNB Chain and the broader community would do what they could to help. Stablecoin issuers Circle and Tether blacklisted assets associated with one identified exploiter wallet, another sign of how centralized issuers can enforce controls at the token-contract level.

Bybit explicitly identifies the North Korea-linked Lazarus Group as a restricted counterparty. Bitget CEO Gracy Chen said indicators from the September 24 attack raised suspicions of North Korean involvement, but that attribution remains unconfirmed and the investigation is ongoing.

The policy highlights the difference between permissionless blockchain execution and centralized liquidity access. Stolen or sanctioned crypto may move on-chain, but centralized exchanges can reject deposits or restrict accounts. For hackers trying to convert stolen assets into usable liquidity, every exchange enforcing such boundaries potentially narrows the exit.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.