- Bybit’s restricted list includes Garantex, Bitzlato, mixers, darknet markets and Lazarus Group.
- Users can face blocked transactions, account restrictions or liquidation if prohibited connections are detected.
- The policy shows why moving stolen crypto on-chain does not guarantee access to centralized liquidity.
Bybit has published a Restricted Counterparty List identifying crypto platforms, mixers, darknet markets, payment services and sanctioned organizations with which users are prohibited from transacting through the exchange.
The practical consequence is significant: if Bybit identifies a direct or indirect connection to a restricted entity, it says it may block transactions or funds, suspend or terminate accounts, file regulatory reports and liquidate open positions.
The publication comes as exchanges are again confronting the problem of contaminated crypto flows following Bitget’s $351.6 million security breach. There is no evidence that Bybit published the list in response to the Bitget attack, but the timing highlights how centralized platforms can become enforcement points after stolen assets begin moving across chains.
Who Is on Bybit’s Restricted Counterparty List?
The list stretches well beyond sanctioned exchanges.
Bybit Restricted Counterparties
Who appears on Bybit’s restricted list?
Crypto & payments
Garantex, Bitzlato, EXMO, Payeer, Nobitex
Guarantee markets
Huione Guarantee, Xinbi Guarantee
Mixers
Bitcoin Fog, ChipMixer, Sinbad
Wallet services
Samourai Wallet
Darknet markets
Hydra Market
Restricted groups
Lazarus Group, Hamas, Ansarallah (Houthis), ISIS-K
Note: Selected entities from Bybit’s published Restricted Counterparty List. The list covers multiple categories and should not be interpreted as exhaustive.
Bybit says its restricted counterparties include entities sanctioned or otherwise prohibited under applicable laws and regulations, including lists maintained by authorities such as the U.S. Treasury, European Union, United Kingdom and United Nations.
The exchange also makes clear that the published names should not necessarily be read as the entire universe of prohibited counterparties.
That distinction is important for users: absence from the public list does not automatically mean a counterparty is acceptable.
What Happens If Bybit Detects a Connection?
This is where the policy becomes more consequential than a conventional sanctions notice.
Bybit says it actively screens transactions and user activity against restricted counterparties on an ongoing basis.
When a prohibited connection is identified, potential actions include:
- suspending or terminating the account;
- blocking a transaction or related funds;
- filing relevant regulatory reports;
- liquidating open positions;
- cooperating with regulators or law enforcement.
The wording also covers users who transact with, transfer funds to or from, or otherwise engage directly or indirectly with prohibited entities.
For traders, that means the relevant question is not simply whether their own wallet appears on a sanctions list. Transaction history and connections to other addresses can also become relevant to an exchange’s compliance review.
A Valid Blockchain Transaction Can Still Become Unusable
That distinction is especially important after large crypto thefts.
A permissionless blockchain generally determines whether a transaction satisfies its protocol rules. It does not determine whether a centralized exchange must accept the resulting funds.
Bybit operates at that second layer.
Crypto can therefore move successfully from address A to address B while subsequently encountering restrictions when it reaches an exchange or another regulated intermediary.
This creates a practical bottleneck for stolen and sanctioned assets. Attackers may be able to move native assets through self-custodied wallets and decentralized protocols, but centralized venues can reject deposits or restrict accounts when their monitoring systems identify prohibited exposure.
Stablecoins introduce another control point because some centralized issuers can blacklist addresses at the token-contract level.
The Bitget attack has provided a live example of those different layers operating simultaneously.
Bitget’s $351.6M Hack Puts the Policy in Context
Bitget said its security systems detected unauthorized transfers at 18:31 UTC on September 24, with approximately $351.6 million in assets affected.
The exchange said cold wallets and the overwhelming majority of platform assets remained unaffected. It temporarily suspended withdrawals while keeping trading and deposits available and said the incident falls within its User Protection Fund, which held more than $464 million. Bitget’s official incident disclosure
The response quickly extended beyond Bitget.
Binance co-founder Changpeng Zhao said Binance, BNB Chain and the broader community would do what they could to help. Separately, stablecoin issuers Circle and Tether blacklisted assets associated with one identified exploiter wallet.
Tough day for Bitget. I expect and know @Binance, the @BNBCHAIN ecosystem, and the community will do everything we can to help.
Stay SAFU! 🙏 pic.twitter.com/cyAEHdSi1S
— CZ 🔶 BNB (@cz_binance) September 25, 2026
Those interventions demonstrate why the route taken after a theft can matter almost as much as the original exploit.
Moving crypto is one problem. Finding infrastructure willing to receive it is another.
Lazarus Appears on Bybit’s List, but Bitget Attribution Is Unconfirmed
One name creates an obvious intersection between the two stories: Lazarus Group.
Bybit explicitly identifies the North Korea-linked hacking organization as a restricted counterparty.
Meanwhile, Bitget CEO Gracy Chen has said indicators from the September 24 attack raised suspicions of North Korean involvement. That attribution has not been conclusively established, and the investigation remains ongoing.
The two facts should therefore remain separate.
Lazarus appearing on Bybit’s list does not demonstrate that it attacked Bitget, and Bybit’s publication should not be described as a response to the breach without evidence establishing that connection.
What the list does show is how a centralized venue would treat transactions linked to an entity already inside its prohibited-counterparty framework.
Bybit Is Making the Compliance Perimeter Visible
The most useful part of Bybit’s publication may ultimately be its transparency.
Exchange users already operate under sanctions, AML and prohibited-use rules, but those controls often become visible only when a transaction is delayed or an account enters compliance review.
A named counterparty list gives users a clearer view of some of the entities and services that can trigger restrictions before they transact with them.
It also exposes an increasingly important division inside crypto.
Blockchains determine whether transactions can execute. Centralized exchanges separately determine whether they are willing or legally permitted to accept the resulting assets.
For ordinary users, that means wallet history matters. For investigators, it creates potential intervention points.
And for hackers trying to turn stolen crypto into usable liquidity, every exchange publishing and enforcing those boundaries potentially narrows the exit.
The blockchain may move the money.
That does not mean every platform has to take it.



