Verified User Says $80 USDT Transfer Led to Compliance Review
Bybit is facing a fresh customer complaint over its transaction-monitoring controls after a KYC-verified user said an attempted transfer of just 80 USDT to a friend resulted in an immediate withdrawal restriction and compliance review.
The complaint, posted on Trustpilot on Sept. 4, does not by itself establish wrongdoing by Bybit or explain why the transaction was flagged. However, it adds to a cluster of recent user reports involving relatively small crypto withdrawals that allegedly resulted in broader account restrictions.
The Sept. 4 reviewer said they attempted to send 80 USDT to a friend for personal expenses before their withdrawal access was immediately placed under “Compliance Review.”
The user said their account had already completed KYC and that they subsequently provided requested verification information. They identified the case publicly as Case ID 27417577.
Bybit responded directly to the review, saying the case was being sent to its compliance team and that the company would follow up by email. The exchange did not confirm that the size or stated personal purpose of the transaction caused the restriction.
That distinction is important because other recent complaints point more specifically to destination-address risk rather than transaction size.
A separate user said an attempted 20 USDT withdrawal over the TRC-20 network was rejected on Aug. 27. According to the reviewer, an email from Bybit said the transaction had been intercepted because of “high risk associated with the destination address” and advised the customer to use another address.
The user claimed broader withdrawal and trading restrictions were nevertheless placed on the account and remained in effect seven days later.
Another customer reported trying to withdraw 13 USDT over TRC-20 to an address associated with crypto payment processor Heleket on Aug. 29. That reviewer similarly claimed the destination was identified as high risk and that the attempted transaction was followed by an account-wide compliance review.
Bybit publicly replied that it was taking the case to its compliance team.
A third complaint involves an even smaller amount.
One user said an 8.99 USDT payment initiated on Aug. 27 for a VPN service through an address generated by Heleket was rejected, after which withdrawals, internal transfers, P2P activity and trading were restricted while the account underwent review.
Bybit later told the reviewer it was moving the matter to a senior compliance team member.
The individual reviews remain unverified customer claims, and there is no evidence that the cases share the same underlying compliance trigger.
The concentration of Heleket references is nevertheless notable. Another customer separately said their account was restricted following an attempted payment through the same processor on Aug. 23, while a Reddit user described a similar experience and another commenter claimed a $30 Heleket-related withdrawal led to an account restriction.
None of those complaints establishes that Heleket itself is problematic.
Heleket describes itself as a crypto payment processor that generates payment addresses for merchants. Its own documentation includes AML procedures under which transactions may be placed into a locked status while a payer completes KYC or source-of-funds checks.
Bybit’s published withdrawal policies, meanwhile, explicitly state that its systems assess destination addresses for security risk.
If an address is considered potentially risky, Bybit advises customers to use an alternative. The exchange says a withdrawal may be rejected when an address is classified as high risk and that the user’s account can subsequently face withdrawal restrictions while additional verification is carried out.
That policy does not establish what happened in the $80 case. The Sept. 4 reviewer described the recipient simply as a friend, and Bybit’s public response did not disclose why the transaction was referred for compliance review.
The exchange has also responded more broadly to complaints about restrictions, saying each account is handled individually according to its particular circumstances and the regulatory requirements applying to the relevant Bybit entity.
Bybit said compliance reviews can take time and encouraged customers to provide individual case or ticket numbers rather than treating separate complaints as evidence of a common issue.
Its rules also increasingly reflect Travel Rule requirements. Depending on the jurisdiction, users sending crypto may be required to identify whether the destination is another service provider or a personal wallet and supply information about the recipient. Preliminary Travel Rule reviews can be triggered even for ordinary withdrawals.
There is therefore no public evidence so far of a minimum transaction amount below which Bybit suspends its risk controls.
What the recent complaints show instead is that very small transactions can apparently still encounter the same automated blockchain-risk screening applied to much larger withdrawals.
The Amount May Be Almost Irrelevant to the Algorithm
The instinctive reaction to an $80 account restriction is to ask why a major exchange would care about such a small transaction.
That may be the wrong question.
Blockchain compliance systems do not necessarily judge risk the same way a human customer does. To the user, $13, $20 or $80 looks economically trivial. To automated transaction monitoring, the important variable may be where the crypto is going, what other addresses have interacted with that destination and how the wallet is classified by blockchain analytics.
Bybit’s own documentation supports that interpretation. It explicitly warns that a withdrawal address deemed high risk can cause a transaction to be rejected and can result in restrictions pending further checks.
In that system, $20 sent to an address carrying an elevated risk score could potentially attract more scrutiny than $20,000 sent to a well-established regulated exchange.
That is defensible from an AML perspective. Risk controls that disappear below an arbitrary dollar threshold would be easy to circumvent by splitting transactions into smaller amounts.
But the recent complaints expose a different problem: proportionality after the alert fires.
Blocking one questionable transfer is relatively easy to understand. Restricting all withdrawals — and in some alleged cases trading, P2P activity and internal transfers — while giving the customer no clear completion date creates a much bigger consequence than the transaction that triggered the review.
That is where the story becomes less about whether Bybit should screen addresses and more about how efficiently it resolves false positives.
The repeated public complaints share another characteristic. Several users say they are willing to provide documents but have instead been told that no additional information is currently required and that they must wait for compliance.
Those statements remain allegations, but if accurate, they create an awkward user experience: the customer cannot resolve the problem themselves because they do not know what triggered it, what evidence would clear it or when the review will finish.
There are legitimate reasons exchanges cannot reveal every detail of transaction-monitoring systems. Explaining precisely how addresses are scored could help criminals design transactions to evade those controls.
But there is a difference between keeping an AML model secret and leaving legitimate users without a meaningful review process.
The Heleket cluster makes that issue particularly interesting. Multiple customers appear to believe they were simply paying ordinary online merchants through a crypto processor. If the processor or particular addresses in its payment infrastructure are receiving elevated risk classifications somewhere in Bybit’s monitoring stack, users may have no way of knowing before they send.
That hypothesis is not yet proven.
Nor should four or five public complaints be turned into evidence of a systemic Bybit freeze problem. Trustpilot and Reddit are self-selecting sources, and unhappy users are far more likely to post than customers whose withdrawals complete normally.
Still, the low values make these cases worth watching.
The question for Bybit is not whether an $80 transfer can legitimately trigger compliance screening. Clearly, under a risk-based system, it can.
The more important question is what happens next — and whether an automated risk alert on a tiny transaction can leave an otherwise verified customer unable to access much larger balances for days or weeks.
That is the part of the pattern Bybit has yet to explain publicly.
