Sat. Sep 12th, 2026

Bybit User Says Funds Have Been Frozen for 75 Days as Tiny-Transfer Cases Keep Appearing

ByJohan Shamshad

September 12, 2026 #Bybit
BybitBybit

Bybit is facing a growing cluster of unverified customer complaints involving prolonged account restrictions, including a user who says their funds have now been frozen for 75 days and several others who claim tiny attempted transfers preceded restrictions covering their entire accounts.

A Sept. 12 Trustpilot reviewer said their money had remained inaccessible for 75 days without a clear explanation, meaningful progress update or indication of when access would be restored. The user said the extended restriction had caused financial losses but did not identify the transaction that originally triggered the review.

Two other fresh complaints are more specific.

Another Sept. 12 reviewer said their account was blocked after a $5 withdrawal and had remained restricted for approximately two weeks. A Sept. 11 user separately said an attempted $15 transfer was declined before an account containing roughly $2,000 was frozen. That customer supplied compliance appeal ID W202607222947EDB20E4B6073302ED8.

The allegations remain individual customer reports and do not establish that Bybit is experiencing a platform-wide withdrawal problem. There is also no evidence that the dollar value of the attempted transactions caused the restrictions.

What makes the new reports more notable is that they arrive after several other customers recently described similar sequences involving very small crypto payments.

Small Payments Have Appeared in Several Recent Complaints

Recent Trustpilot reviews include a user who said an attempted 8.99 USDT TRC20 payment for a VPN service through crypto payment processor Heleket was rejected before their account was restricted. The customer said the withdrawal never completed and that Bybit subsequently placed withdrawals, transfers, P2P activity and trading under review.

Another user reported an attempted 13 USDT withdrawal to an address associated with Heleket before their account was restricted. A separate reviewer said an attempted 4.45 USDT hosting payment through a Heleket-generated address was stopped before being broadcast to the blockchain.

Another recent case involved 21.29 USDT intended for hosting provider VirtualDC. According to that reviewer, the merchant redirected the payment through Heleket, Bybit rejected the transaction before it reached the blockchain, and the account was then restricted.

Those reports remain unverified, and multiple reviews may ultimately have different explanations. However, the repetition makes the destination side of the transactions more interesting than their size.

A separate customer reported a 10-week restriction following receipt of approximately $30 from what the reviewer described as an Iranian platform. That case does not involve the same payment processor, but it further demonstrates why a small transaction amount does not necessarily translate into a small compliance risk.

The emerging pattern resembles other recent prolonged account restrictions and withdrawal freezes reported across centralized trading platforms, where the triggering concern can involve the counterparty or transaction history rather than the amount being moved.

Bybit Says High-Risk Addresses Can Trigger Restrictions

Bybit’s own withdrawal documentation provides an important piece of context.

The exchange says users can receive a risk warning when its system detects a potential security risk involving a withdrawal address. Bybit advises customers to consider using another address in those circumstances.

If the customer proceeds with the same destination, Bybit says the withdrawal may be rejected if the address is considered high-risk and the account may face withdrawal restrictions until additional verification has been completed.

That does not prove that Heleket, any merchant using it, or the destinations mentioned by the reviewers are classified as high-risk by Bybit. The exchange has not publicly identified the addresses responsible for the individual restrictions.

But it establishes that Bybit operates exactly the type of destination-based screening mechanism that could produce the sequence customers are describing: a small withdrawal is attempted, the address triggers risk controls, the transaction is stopped and restrictions extend beyond that individual transfer.

Similar questions have arisen elsewhere in the industry. A recent Binance withdrawal review involved an account allegedly restricted after transactions with addresses the exchange considered inconsistent with its terms. The customer remained unable to withdraw after the original review timetable expired.

Bybit Has Expanded Its On-Chain Screening

The complaints are emerging as Bybit publicly emphasizes increasingly aggressive transaction monitoring.

In its H1 2026 Risk & Security Report, the exchange said it intercepted more than 30,000 suspicious withdrawal requests involving nearly 20,000 users and more than $700 million in potential losses between Jan. 1 and June 15.

Bybit also said it identified approximately $212 million in potentially fraud-linked on-chain funds and blacklisted more than 10,000 malicious addresses. The company described its monitoring as covering 100% of business-relevant on-chain activity.

Those are self-reported security figures, and they cannot be used to explain any particular customer case. They do, however, show the scale at which Bybit is automatically analyzing wallets and transactions.

The exchange’s documentation also distinguishes ordinary security locks from more complicated reviews. Certain account-security changes can create a standard 24-hour withdrawal restriction, while suspicious activity can lead to requests for documents and further manual review.

Bybit says one self-service account-unban process involving suspicious activity normally takes around five to seven working days, although that guidance does not necessarily apply to the AML or compliance appeals described by the reviewers.

That distinction matters when a restriction reaches 75 days.

Long review periods are increasingly becoming a customer-service issue across financial platforms. Recent complaints involving withdrawal delays and account holds at Polymarket and a permanently locked account at Skrill show how quickly legitimate fraud or compliance controls can become a trust problem when customers cannot determine what is being reviewed or when it will end.

The More Important Signal May Be the Destination, Not the Amount

The instinctive reaction to these complaints is to focus on the tiny transactions.

Five dollars. Fifteen dollars. Eight dollars and ninety-nine cents.

That makes the restrictions sound disproportionate, but transaction size may actually be the least important variable.

Modern crypto compliance systems do not simply ask whether a withdrawal is large. They ask where it is going, what that address has previously interacted with, whether associated wallets have links to scams, stolen funds, sanctions exposure, darknet services or other high-risk activity, and sometimes how many hops separate the customer from those risks.

A $5 transaction to an address carrying a severe risk flag can therefore attract more attention than a $50,000 transfer to a well-established low-risk wallet.

That is why the clustering around merchant-generated payment addresses deserves investigation.

If several unrelated Bybit customers genuinely attempted ordinary payments through the same processor and were independently restricted immediately afterward, the useful question is not whether Bybit has decided that small withdrawals are suspicious.

It is whether those payments ultimately resolve to the same wallet infrastructure, address clusters or risk-scoring provider.

Heleket itself cannot be characterized as the cause on the evidence currently available. Payment processors can generate different addresses for different merchants and transactions, and an exchange’s blockchain analytics may assign different risk scores even to addresses belonging to the same infrastructure.

Still, there is now enough repetition to test the hypothesis.

The destination addresses from the 8.99, 13, 4.45 and 21.29 USDT cases could be compared on-chain. Investigators could examine whether they converge on common collection wallets, payment-processor infrastructure or counterparties carrying the same risk labels.

The $5 and $15 cases become much more important if their destinations overlap with that cluster.

A 75-Day Freeze Creates a Different Kind of Exchange Risk

None of this demonstrates that Bybit lacks the assets to honor withdrawals.

That distinction is essential. A compliance freeze and an exchange liquidity problem are not the same thing. Questions about reserve backing, such as those raised in broader discussions around Proof of Reserves, address whether customer assets exist. Compliance restrictions concern whether a specific customer is permitted to move them.

But from the affected user’s perspective, that distinction becomes less comforting as the review stretches from days into months.

A centralized exchange may be perfectly solvent while an individual customer still experiences the practical reality of having no access to their money.

This is the trade-off inherent in custody.

Keeping assets on an exchange reduces some of the technical burden of managing private keys and gives users access to trading, recovery tools and centralized support. Moving funds into self-custody removes the exchange’s ability to impose a withdrawal freeze, but replaces that counterparty risk with key-management, wallet-security and recovery risks of its own.

For Bybit, the reputational issue is therefore not whether it screens risky transactions. A major exchange would be expected to do so.

The harder question is what happens after the screening system fires.

If the $5, $15 and other tiny transfers involved genuinely high-risk destinations, restrictions may have a defensible compliance basis. But customers still need a review mechanism capable of distinguishing an innocent payment to a merchant-generated address from deliberate interaction with illicit infrastructure.

Seventy-five days without a clear outcome suggests that the bottleneck may no longer be detection. It may be resolution.

The next useful evidence is therefore highly specific: the actual destination addresses behind the newest $5 and $15 cases, the addresses from the earlier Heleket-linked payments, and the eventual duration and result of each compliance appeal.

If those addresses converge, the story becomes less about tiny transfers unexpectedly freezing accounts and more about one destination network repeatedly colliding with Bybit’s risk systems.

If they do not, the pattern points instead toward a broader question about how aggressively Bybit’s compliance controls are restricting accounts after low-value transactions.

Either outcome would be more informative than transaction size alone.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *