Several Bybit users say their accounts were placed under compliance restrictions immediately after they attempted relatively small cryptocurrency payments to addresses supplied by payment processor Heleket, raising questions over whether the exchange is treating some Heleket-linked wallets as high risk.
The reports, posted independently on Trustpilot in late August and early September, describe a similar sequence: a user attempts an on-chain withdrawal to pay for an online service through Heleket, Bybit declines the transaction, and wider restrictions are then placed on the user’s account.
The claims have not been independently verified, and Bybit has not publicly said that Heleket itself triggered the compliance actions.
One user said they attempted to send just 8.99 USDT over the Tron network on Aug. 27 to pay for a VPN service. According to the review, Heleket supplied the destination address. The withdrawal was rejected and the user’s account was subsequently placed under an internal review that restricted withdrawals, internal transfers, peer-to-peer transactions and trading.
Bybit responded publicly to the complaint, saying the restriction was a compliance action carried out in line with regulatory guidelines and that such reviews could take time. The exchange did not mention Heleket or disclose what caused the review.
Another user reported an almost identical experience involving a considerably smaller payment. The reviewer said their account was restricted on Sept. 1 after an attempted 3.99 USDT payment for a virtual machine through Heleket. They said the transaction itself was declined but that they subsequently lost access to almost $2,000 held in their Bybit account.
Bybit replied that it was escalating the case to its compliance team using the appeal number provided by the customer. Again, the exchange did not identify Heleket as the reason for the restriction.
A third reviewer said withdrawals and trading were restricted after an attempted 58.21 USDT transfer on Aug. 28 to pay for online services. The user said Bybit rejected the withdrawal before it reached the blockchain, meaning no transaction hash was generated. The reviewer said Heleket later confirmed that the destination wallet belonged to its payment system.
Bybit responded that it was referring the case to a senior compliance contact.
Other recent reviews describe similar circumstances without specifying the payment amount. One user said an Aug. 27 payment using Heleket to purchase proxy services was followed by an account block. Another said Bybit restricted their account following an attempted payment through Heleket on Aug. 23, even though the underlying transaction was not completed and the funds were returned to their account.
The clustering does not establish that Bybit has implemented a blanket restriction on Heleket. Trustpilot reviews are user-generated and the circumstances surrounding individual accounts cannot be independently confirmed.
However, Bybit’s own documentation shows that the exchange does screen destination addresses and can restrict accounts after attempted withdrawals to wallets it considers risky.
The exchange’s withdrawal FAQ says users can receive a warning when its systems detect a potential security risk associated with an address. If a user proceeds, Bybit says the withdrawal may be rejected when the destination is considered high risk, and the account may then face withdrawal restrictions pending additional verification.
Bybit separately says it blocks withdrawals to wallet addresses that have been confirmed as associated with fraudulent activity.
That makes the Heleket connection particularly notable because the payment processor has already attracted scrutiny elsewhere in the crypto industry.
Heleket Has Already Been Flagged by Another Major Exchange
South Korean exchange Bithumb imposed an immediate block on all cryptocurrency deposits and withdrawals involving Heleket on May 21.
In its official notice, Bithumb said Heleket was suspected of links to illegal activity involving money laundering and terrorist financing. It said the measure was implemented to comply with South Korea’s anti-money laundering and virtual-asset protection rules and to protect customer assets.
The action followed an April investigation by blockchain intelligence firm TRM Labs.
TRM said it assessed with “high confidence” that Heleket and Russia-linked cryptocurrency payment processor Cryptomus were operationally connected. The firm cited shared infrastructure and branding, overlapping personnel, liquidity sourcing and coordinated blockchain activity.
TRM went further, assessing that Heleket was likely developed by Cryptomus administrators or affiliates and saying illicit actors appeared to migrate toward Heleket after compliance controls at Cryptomus tightened.
Its analysis found Heleket had almost five times the average illicit exposure observed among payment processors in TRM’s data. TRM also traced early Heleket liquidity to Garantex, the Russian cryptocurrency exchange that had been sanctioned by Western authorities.
Heleket itself says it operates AML and counter-terrorist financing procedures and conducts due diligence to detect and prevent financial crime.
There is currently no public indication that Bybit has followed Bithumb in formally blocking all transfers involving Heleket. But the appearance of several recent user reports involving the same payment processor, combined with Bybit’s stated policy of restricting withdrawals to high-risk addresses, creates a narrower question for the exchange: whether Heleket-associated wallets are currently subject to enhanced screening or risk controls.
The Payment Size Is Almost Beside the Point
What makes these complaints interesting is not really the $3.99, $8.99 or $58.21 amounts.
At first glance, freezing wider account functionality following such tiny attempted transfers looks disproportionate. A person trying to spend four dollars is hardly behaving like the stereotypical money launderer moving millions through an exchange.
But blockchain compliance systems do not necessarily think in those terms.
The risk can sit with the address rather than the amount.
If an exchange’s blockchain analytics provider labels a destination wallet, payment processor or cluster of addresses as having exposure to sanctioned entities, stolen funds or other illicit activity, even a tiny transaction can create a compliance event. The four-dollar payment is not important because it poses a large financial risk. It is important because it connects one address to another.
That could explain why these reports look so similar.
It also explains why the transactions apparently being rejected before broadcast is noteworthy. At least some users say no crypto actually reached Heleket. If those accounts were nevertheless placed under review immediately afterward, the attempted destination itself may have been enough to trigger a risk-control process.
That remains an inference rather than something Bybit has confirmed.
There is also a significant difference between blocking a transaction and restricting the customer’s entire account.
An exchange has an obvious reason to stop money flowing to an address it believes presents elevated risk. The harder question is what should happen to a user who may have had no idea that an ordinary merchant was using a controversial payment processor behind the scenes.
Crypto checkout pages make this especially messy. A customer might think they are buying a VPN, hosting service or another perfectly ordinary product. The merchant generates an invoice, a processor produces a deposit address and the customer sends the funds. The customer may never have chosen the payment processor at all.
That creates the possibility of what might be called compliance contamination: a user enters a risk review not because of their own transaction history but because of infrastructure selected by a merchant.
Bithumb solved that problem in the simplest possible way. It publicly blocked Heleket transfers altogether. That at least tells customers what they cannot do.
If Bybit is also treating Heleket-related addresses as particularly risky, transparency becomes more complicated. Exchanges generally cannot publish the details of transaction-monitoring systems without making them easier to circumvent. But users also cannot avoid a processor they do not know is problematic.
The emerging cluster of reports therefore matters more than any individual complaint.
One account restriction could have dozens of explanations. Several users independently naming the same payment processor, describing rejected transfers followed immediately by compliance reviews, is enough to justify asking Bybit for clarification.
It is not yet evidence of a formal Heleket ban.
But given Bithumb’s May action and TRM Labs’ findings, it would not be surprising if addresses connected to the processor were receiving much closer scrutiny across major exchanges. The important question now is whether Bybit’s recent restrictions reflect isolated address-level flags or a broader policy toward the Heleket network.
