Bybit Publishes Restricted Counterparty List, Naming Garantex, Bitzlato and Lazarus Group
TREE NEWS reports: Bybit has published a Restricted Counterparty List on its official website, naming a set of crypto platforms and entities that its users are barred from transacting with. The list includes Garantex, Bitzlato, EXMO, Payeer, Nobitex, Bitpapa and — notably — the Lazarus Group, the North Korean state-linked hacking collective.
The disclosure marks a shift in how a major exchange communicates sanctions and risk exposure to its user base. Rather than burying restrictions inside terms of service, Bybit has placed the roster in a public-facing document, effectively turning compliance policy into a transparent, checkable list.
Why These Names Matter
The composition of the list maps closely onto the sanctions and enforcement perimeter built over the past several years by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) and European authorities.
- Garantex — a Moscow-linked exchange sanctioned by OFAC in 2022 for facilitating ransomware and darknet payments.
- Bitzlato — dismantled in a 2023 international operation; its founder pleaded guilty to operating an unlicensed money-transmitting business tied to illicit finance.
- EXMO — a long-running Eastern European exchange with prior ties to sanctioned Russian banking infrastructure.
- Payeer — a payment processor sanctioned for enabling evasion of Russia-related restrictions.
- Nobitex — Iran’s largest crypto exchange, subject to U.S. sanctions.
- Bitpapa — a peer-to-peer marketplace frequently cited in illicit-finance reporting on Russia and the CIS region.
- Lazarus Group — the DPRK-affiliated actor behind billions of dollars in exchange hacks, including the 2025 Bybit breach itself.
The Strategic Logic
Naming Lazarus is not incidental. Bybit suffered one of the largest exchange exploits on record at the hands of that group. Including it on a restricted list is partly reputational repair and partly a defensive posture: it signals to regulators, banking partners and institutional clients that the exchange is hardening its perimeter against the exact adversary that already breached it.
More broadly, the list reflects the “compliance-by-enumeration” model that has become standard among top-tier venues. Exchanges increasingly maintain internal blocklists that go beyond OFAC’s SDN list, incorporating chain-analytics risk scores, cluster attribution and law-enforcement intelligence. Publishing them serves two purposes: it shifts responsibility onto users who ignore the guidance, and it creates a paper trail useful in licensing and audit conversations.
What to Watch
Three questions will determine whether this becomes an industry norm or a one-off:
- Enforcement — Will Bybit actually freeze or claw back funds that touch these counterparties, or is the list advisory? Detection and enforcement are very different commitments.
- Reciprocity — If other large exchanges publish comparable rosters, the practical effect is a de facto industry-wide blocklist that operates faster than formal sanctions designations.
- Arbitrage risk — Restricted counterparties rarely disappear; they migrate to smaller venues, P2P channels and mixers. A fragmented compliance map can simply push risk into less-visible corners of the market.
For users, the immediate takeaway is operational: transactions touching any listed counterparty may now be flagged, delayed or frozen. For the industry, Bybit’s move is another step toward a two-tier market — regulated venues with published exclusion lists, and an offshore periphery where those lists carry no weight.




