A longtime Bybit customer says roughly $25,000 in funds were restricted after the exchange rejected a 21 USDT withdrawal to an address it classified as high-risk — even though Bybit had allegedly processed a payment to the exact same destination two months earlier.
The unverified customer report, published Sept. 13, adds a potentially important detail to the recent cluster of tiny-transfer cases involving Bybit compliance restrictions.
According to the customer, who says they have used Bybit for around six years, a 21 USDT TRC20 withdrawal attempted on Sept. 6 was rejected because the destination was considered high-risk. A Compliance review was opened shortly afterward, restricting access to approximately $25,000.
The customer says the same TRON address was not new.
On July 3, Bybit had allegedly completed a 20 USDT withdrawal to that exact destination without raising a compliance warning or blocking the account.
That creates a more specific question than whether small withdrawals can trigger large account restrictions: what changed in the risk assessment of the destination between July and September?
The July transaction and the claimed ownership of the receiving account have not been independently verified. Bybit has also not publicly confirmed why the Sept. 6 transaction was rejected or whether the destination’s classification changed after the earlier withdrawal.
User Says Destination Was Linked to an HTX Account
The customer said they investigated the recipient only after the September withdrawal was rejected and learned that the address was associated with an HTX account belonging to an online-gaming teammate of an acquaintance.
They said they did not know that information when initiating the withdrawal.
The customer also said they had completed a compliance questionnaire and supplied Source of Funds documentation and transaction histories covering their cryptocurrency activity. According to the report, Bybit support subsequently said no additional documents or action were currently required.
On Sept. 12, the customer says a support representative told them their funds were “safe” and requested that the compliance review be prioritized. The review nevertheless remained ongoing on Sept. 13 without an estimated completion date.
The customer said existing trading positions could be closed but could not be increased or averaged while the restriction remained active.
There is currently no evidence that the customer’s approximately $25,000 balance is missing or that the restriction reflects a liquidity problem at Bybit.
That distinction matters because proof of reserves addresses whether an exchange has assets backing customer balances, while an account-specific compliance restriction concerns whether a particular customer is allowed to move those assets.
Bybit Says High-Risk Addresses Can Lead to Account Restrictions
Bybit’s published withdrawal rules closely match the sequence described by the customer, although they do not explain this individual case.
The exchange says users may receive a warning when its systems detect a potential security risk associated with a withdrawal address. If a customer continues with that destination and the address is deemed high-risk, Bybit says the withdrawal can be rejected and the account can be subjected to withdrawal restrictions pending additional verification.
Bybit separately says it blocks withdrawals to addresses confirmed as being associated with fraudulent activity.
That makes destination risk — rather than the 21 USDT amount — the more relevant variable.
The exchange has substantially expanded its on-chain monitoring. In its H1 2026 Risk & Security Report, Bybit said it intercepted more than 30,000 suspicious withdrawal requests involving nearly 20,000 users and more than $700 million in potential losses between Jan. 1 and June 15.
It also reported identifying approximately $212 million in potentially fraud-linked on-chain funds and blacklisting more than 10,000 malicious addresses.
Those figures do not establish that the HTX-linked destination in this case was malicious. They do show that Bybit operates a large and actively maintained address-screening system capable of changing how destinations are treated as new blockchain intelligence becomes available.
Earlier Approval Does Not Guarantee an Address Stays Low-Risk
An address successfully passing an exchange’s controls once does not necessarily mean it will continue to pass them indefinitely.
Blockchain risk systems can incorporate subsequent transactions, new links to sanctioned or fraudulent wallets, updated clustering information, new law-enforcement intelligence or changes in the methodology used by an exchange or its analytics providers.
An address considered low-risk in July could therefore theoretically receive a different assessment in September.
But that remains only one possible explanation here.
Bybit has not said whether the address’s score actually changed, whether another wallet connected to it triggered the review, or whether the customer’s own transaction history contributed to the restriction.
Similar ambiguity around why money can be seen but not moved has appeared elsewhere. Recent crypto withdrawal restrictions at other trading platforms have shown how important it is to distinguish technical outages, compliance holds and custody problems rather than treating every inaccessible balance as the same type of event.
The $21 Withdrawal Is Probably the Least Important Number
The most striking number in the story is $21.
But it may also be the least meaningful.
Compliance systems do not generally decide that a transfer is harmless because it is small. If the destination carries a serious enough risk signal, a $21 transaction can reveal the same counterparty relationship as a $21,000 transaction.
That helps explain why a tiny attempted transfer can trigger scrutiny covering an entire account balance.
What is harder to explain to a customer is why a destination that worked two months earlier suddenly becomes serious enough to restrict roughly $25,000.
That is the real story here.
If the user’s timeline is accurate, Bybit’s screening system did not merely identify a risky address. It produced two different outcomes for the same destination within roughly nine weeks.
That does not automatically mean one decision was wrong. It may mean the intelligence changed.
And if the intelligence changed, the next question is what changed it.
The Address History Could Make This Case Testable
This case is more useful than many anonymous account-freeze complaints because the central claim can potentially be tested on-chain.
If transaction IDs or the destination address become available, the July 3 payment and attempted Sept. 6 withdrawal can be compared against the address’s activity between those dates.
Investigators could look for interaction with newly flagged wallets, transfers involving known high-risk clusters, intermediary addresses or changes in where the HTX account ultimately routed funds.
That could also help determine whether this case connects with the earlier small-transfer cluster or represents something different.
The previous Bybit complaints largely involved very small payments to merchant or payment-processor addresses. This customer instead says the destination belonged to an HTX account.
If those seemingly unrelated cases eventually converge on the same risk infrastructure, analytics provider or wallet cluster, the pattern becomes considerably more significant.
If they do not, then Bybit may simply be applying destination screening aggressively across a broad range of unrelated transactions.
Access Risk Is Becoming as Important as Custody Risk
Crypto investors usually think about exchange risk in terms of solvency: does the platform actually hold the assets it says it holds?
Cases like this expose another risk.
You can have assets sitting inside a solvent exchange and still be unable to move them.
We have seen the same underlying problem appear in different forms, from a permanently locked account after funding to customers encountering multiple payment and regulatory restrictions while trying to move relatively small balances.
None of those situations are identical, but they highlight the same practical issue: account access is part of liquidity.
A displayed balance is useful only if the customer can transfer, trade or withdraw it when necessary.
Open-Ended Reviews Are the Bigger Reputational Problem
Bybit has a legitimate reason to stop transactions that its systems believe could expose customers or the platform to fraud, sanctions or money-laundering risk.
The bigger problem is what happens after the automated control fires.
A false positive lasting minutes is an inconvenience.
A false positive lasting weeks or months becomes a financial problem.
That is why published timelines matter. Other platforms have at least provided explicit redemption timelines even when customers cannot immediately access assets. A defined delay allows users to plan. An indefinite compliance review does not.
For Bybit, the key operational challenge is therefore not detecting more risky addresses. Its own numbers suggest it is already doing that at considerable scale.
It is building a review process capable of resolving the edge cases created by those controls.
That becomes especially important when an algorithm can stop a $21 transaction while restricting a balance more than a thousand times larger.
The July-to-September Gap Is What to Watch
The next evidence needed in this case is unusually clear.
The July 3 transaction ID would establish that the same destination really was previously approved. The address history could then show what happened before the Sept. 6 retry.
If something identifiable changed on-chain between the two dates, the case would offer a rare view into how quickly exchange risk classifications can evolve.
If nothing meaningful changed, the focus would shift toward Bybit’s screening methodology and whether changes in internal or third-party risk models can suddenly turn previously accepted destinations into compliance triggers.
There is also a broader custody question. Moving funds into self-custody reduces the ability of a centralized exchange to impose a withdrawal freeze, but it transfers responsibility for security and key management entirely to the user.
That trade-off is unlikely to disappear.
For now, the strongest angle is not that Bybit froze approximately $25,000 over $21.
It is that, according to the customer, Bybit accepted the same address in July and rejected it as high-risk in September.
Finding out what happened to that address between those dates could explain far more than the transaction amount ever will.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

