Bybit Publishes Restricted Counterparty List, Blacklists Lazarus Group and Dozens of Crypto Platforms
Key Takeaways
- •Bybit's Restricted Counterparty List covers dozens of entities, including platforms such as Garantex, Bitzlato, EXMO, Payeer, and Nobitex, several of which have prior enforcement records.
- •The blacklist also names sanctioned organizations, including the North Korea-linked Lazarus Group, Hamas, Ansarallah, and ISIS-K, alongside coin mixers like Samourai Wallet and ChipMixer and darknet markets like Hydra Market and Sinbad.
- •The restrictions are grounded in Section 23 of Bybit's Platform Terms and Section 28 of the BVAPO Terms, tied to sanctions registries such as the U.S. Treasury's SDN list and the EU's Consolidated Financial Sanctions List.
- •Bybit conducts ongoing screening and may suspend or terminate linked accounts, block transactions, file regulatory reports, and liquidate open positions when a prohibited connection is identified.
- •The FBI attributed Bybit's February 2025 theft of approximately $1.5 billion in ether to a hacking program associated with the Lazarus Group, which appears on the new list.

Bybit has published a comprehensive Restricted Counterparty List identifying the digital asset trading platforms, payment processors, wallets, and organizations that are barred from accessing its services. The full list is published on the exchange's official website.
The list spans trading platforms, payment processors, coin mixers, darknet markets, and sanctioned organizations, including Lazarus Group, Hamas, Ansarallah, and ISIS-K. The exchange said it actively screens transactions against the named entities and reserves the right to suspend accounts, block funds, and report violations to regulators.
Dozens of Restricted Platforms and Services
The Restricted Counterparty List includes well-known industry names such as Garantex, Bitzlato, EXMO, Payeer, and Nobitex. Other flagged platforms include Bitpapa, Chatex, Cryptex, Grinex, and Rapira. The exchange also named WhiteBird, OMPFinex, Ramzinex, HTX, and Wallex among restricted services. Several entries arrive with prior enforcement records: the U.S. Treasury sanctioned Garantex in 2022, while Bitzlato was hit with a U.S. money-laundering order and a French-led takedown in 2023.
Additional entries cover Tetherland, Bit24, QvaPay, and two guarantee marketplaces, Huione Guarantee and Xinbi Guarantee. These marketplaces have drawn scrutiny for facilitating illicit fund transfers across Southeast Asia.
The publication of the list was flagged by Wu Blockchain on X:
Source:
— Wu Blockchain (@WuBlockchain) September 25, 2026
Mixing services Samourai Wallet, Bitcoin Fog, and ChipMixer appear on the list as well, alongside the darknet markets Sinbad and Hydra Market. Many of these services have already been targeted by authorities: Hydra Market, once the world's largest darknet market, was dismantled in a 2022 international operation, ChipMixer was shut down in 2023, the U.S. Treasury sanctioned Sinbad that same year, and Samourai Wallet's founders were charged by U.S. prosecutors in 2024.
Legal Basis and Ongoing Screening
Bybit cited its Platform Terms and Conditions as the basis for the restrictions. Under Section 23 of these terms, and Section 28 of the BVAPO Terms, the exchange does not offer services to entities designated under applicable sanctions frameworks. This includes names on the U.S. Treasury's Specially Designated Nationals list, the EU's Consolidated Financial Sanctions List, and equivalent registries maintained by competent authorities worldwide.
The exchange said its screening process runs on an ongoing basis rather than as a one-time check. Where a connection to a prohibited entity is identified, Bybit may suspend or terminate accounts linked to that entity. It may also block related transactions, file regulatory reports, and liquidate open positions tied to the account.
Sanctioned Organizations and User Obligations
Beyond crypto platforms, the list names organizations tied to security concerns, including Lazarus Group, also known as Hidden Cobra, the North Korea-linked hacking group that U.S. officials have blamed for some of the largest thefts in crypto history. Hamas, referred to as the Islamic Resistance Movement, appears alongside Ansarallah, commonly known as the Houthis. ISIS-K, listed as ISIS-Khorasan, rounds out the named organizations. The Lazarus entry carries particular weight for Bybit itself: the FBI attributed the exchange's February 2025 theft of roughly $1.5 billion in ether to a hacking program associated with the Lazarus Group.
Bybit also outlined user obligations tied to these restrictions in its terms. Users who transact with, transfer funds to, or otherwise engage with a prohibited entity violate the platform's terms. Users who become aware of such a transaction are required to inform Bybit immediately under the policy.
The exchange stated that it reserves the right to take all necessary steps to maintain compliance with applicable laws, including cooperation with regulatory and law enforcement authorities across relevant jurisdictions. Bybit did not specify a timeline for updates to the list. Since restrictions are tied to external sanctions registries and screening runs on an ongoing basis, the composition of the list can change as authorities update their designations.
The move reflects a broader pattern among major cryptocurrency exchanges tightening compliance amid rising regulatory pressure. Platforms handling sanctioned counterparties face growing scrutiny from global financial watchdogs. Bybit's published list gives users a reference point for avoiding inadvertent violations tied to these entities.
Source: Blockonomi