Answer

Screen your wallet for the exposure Bybit's compliance team flags — sanctions, mixers, stolen funds — before you deposit; Plastron returns a free Low-to-Critical risk verdict in seconds, with no signup.

Bybit Wallet Check

Bybit was the target of the largest crypto hack in history in 2025. Funds from that hack now circulate on-chain, and your wallet may have been exposed.

In February 2025, North Korean hacking group Lazarus exploited Bybit's cold wallet infrastructure, stealing approximately $1.5 billion in ETH and stETH. The stolen funds were rapidly moved through dozens of intermediary wallets, converted through DEX protocols, and distributed widely in an effort to obscure their origin. Blockchain analytics firms tracked these movements in near-real-time, and OFAC added new addresses to the SDN list as they were identified. The consequence for ordinary users is that wallets which received ETH or stETH through DeFi protocols in the weeks following the hack may have inadvertently accepted funds that originated from the Lazarus heist — creating exposure that can trigger compliance flags at exchanges worldwide. Bybit itself also runs compliance screening on all deposits: they have strengthened their AML program substantially since the incident and now apply heightened scrutiny to wallets with complex DeFi history. Screening your wallet identifies both the Bybit hack exposure risk and any other AML red flags before you deposit.

How Plastron Helps

Lazarus Hack Exposure Detection

Plastron's database includes addresses identified as part of the Bybit 2025 hack fund movements and Lazarus Group infrastructure. If your wallet received ETH or ERC-20 tokens through a path that traces back to these addresses, we flag it with a stolen funds classification. We check up to 1,000 transactions including DeFi swap intermediaries where the exposure is most likely to appear.

Bybit Deposit Pre-Screening

We analyze your counterparty graph against OFAC, mixer contracts, and all high-risk categories. The resulting risk score and category breakdown reflects what Bybit's compliance systems will see when your deposit arrives. A Low score means your deposit is unlikely to be held. A High or Critical score warrants investigation before sending.

DeFi Interaction Tracing

Liquidity pools, DEX routers, and bridge contracts create indirect exposure paths that basic block explorers cannot show. Plastron maps your internal smart contract calls alongside normal ETH transactions to identify exposure that runs through DeFi infrastructure — the main vector through which Lazarus funds spread after the February 2025 hack.

Risk Categories We Screen

Stolen Funds
Wallets linked to hacks, exploits, and bridge attacks. Even receiving a fraction taints your address.
Sanctions
OFAC SDN, EU, and UN sanctioned addresses. Direct or indirect exposure flags your wallet instantly.
Mixer
Tornado Cash, Blender, and other mixing protocols. Interaction with these services is a major red flag.
Darknet
Addresses associated with darknet marketplaces. Any connection triggers heightened scrutiny at exchanges.
$1.5B
Stolen in the Bybit 2025 Lazarus Group hack
Source: Bybit and on-chain analysis
40M+
Registered Bybit users
Source: Bybit
100+
OFAC addresses added related to the 2025 Bybit hack
Source: US Treasury OFAC

Frequently Asked Questions

Related Screening Tools

Free AML Screening for Crypto Wallets | PlastronNorth Korea Crypto Check — Lazarus Group ScreeningStolen Funds Check — Detect Hack and Exploit ExposureEthereum Wallet Check — Screen ETH for RiskBinance Wallet Check — Screen Before You Deposit

Screen Your Wallet Now

Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.

Explore More

Free AML Screening for Crypto Wallets | PlastronWallet Risk Check — Scan Before You DepositCrypto Compliance Check — Free Wallet ScanKYC Wallet Check — Screen Your Address FreeWallet Address Checker — Verify Any ETH Address