OKX has pushed back against reports that European regulators are investigating the exchange over its alleged failure to stop funds tied to the Bybit hack. The Seychelles-based crypto platform said the narrative is misleading and argued that it had already taken concrete steps to block suspicious activity after the incident.
The dispute centers on how stolen assets moved after the Bybit breach and whether OKX’s wallet-related infrastructure played a role in helping hackers obscure those funds. OKX, which falls under the scope of the European Union’s Markets in Crypto-Assets (MiCA) framework, said the claims about its failure to freeze assets were driven by statements originating from Bybit and then amplified in media coverage.
OKX Responds to Reports of Regulatory Scrutiny
According to the report cited by OKX, European regulators were said to be examining the exchange’s custody wallet service after allegations that hackers connected to the Bybit attack used the service to launder $100 million in digital assets. The report linked that conclusion to a summary shared earlier by Bybit CEO Ben Zhou describing how part of the stolen funds moved through the crypto ecosystem.
OKX rejected the suggestion that it failed to act. In a March 11 post on X, the exchange said that once Bybit was hacked, it blocked the associated funds from moving into its centralized exchange. It also said it rolled out a newly developed feature designed to detect and block hacker-linked addresses from accessing its DEX or wallet services.
That response was meant to counter the growing perception that OKX had become a weak point in the containment effort after the Bybit breach. By stressing both centralized exchange restrictions and additional controls on Web3-facing tools, OKX sought to present itself as an active participant in damage control rather than a passive conduit.
Bybit Data Became the Basis of the Dispute
The controversy appears to stem largely from a breakdown published by Ben Zhou on March 4. In that summary, Zhou said that 40,233 ETH had moved through the OKX Web3 proxy. Of that amount, only 16,680 ETH could be traced, while the remaining 23,553 ETH was described as untraceable.
Zhou said that recovering visibility into those missing flows would require information from the OKX Web3 wallet. That point seems to have drawn the attention of European regulators, who reportedly focused on OKX’s Web3 “proxy” service while assessing how much responsibility service providers may bear when stolen crypto moves through decentralized or semi-custodial infrastructure.
The report further said that some regulators had called on the European Securities and Markets Authority and the European Banking Authority to take action against OKX. Even without a formal enforcement outcome disclosed in the source material, the mention of those institutions elevated the issue from an industry dispute to a potentially broader regulatory question.
Web3 Wallets and Compliance Boundaries
At the heart of the disagreement is the nature of OKX’s Web3 wallet offering. OKX argued that the service is not fundamentally different from products offered by rival crypto exchanges. In other words, the company is contesting the idea that its wallet or proxy tools should be singled out as uniquely problematic simply because they appeared in the post-hack fund trail.
This distinction matters because the crypto industry continues to wrestle with where responsibility begins and ends for platforms that provide access to decentralized tools. Centralized exchanges are generally expected to freeze suspicious deposits when they can identify them. Web3 wallets and proxy services, however, often sit in a more contested area when it comes to tracing, screening, and intervention.
By emphasizing that it blocked funds from entering its centralized platform and introduced additional protections for wallet and DEX services, OKX is making the case that it responded within the limits of what its systems could support at the time. The exchange also appears to be signaling that regulators should not confuse the existence of fund flows through a service with proof of negligence or non-compliance.
OKX Criticizes Bybit’s Claims
Beyond denying the regulatory-investigation narrative, OKX directly criticized Bybit for what it called false claims. The exchange said it would continue helping Bybit and supporting the broader industry, but it strongly rejected assertions that it had played an improper role in the aftermath of the hack.
In its statement, OKX said the misinformation about its involvement was distracting from the original cause of the crisis: a serious security vulnerability on Bybit’s own exchange. That framing suggests OKX wants the market to separate two issues that have become increasingly blurred in public discussion—first, the initial security failure that enabled the theft, and second, the later movement of funds across external platforms and tools.
The exchange’s rebuttal also reflects a broader reputational concern. In high-profile crypto hacks, downstream service providers can quickly come under pressure if stolen assets are seen moving through their products, even when the initial breach occurred elsewhere. By publicly challenging Bybit’s version of events, OKX is attempting to draw a firmer line around its role and liability.
Why the Story Matters
The episode highlights how quickly a hack can evolve into a wider debate over compliance, wallet infrastructure, and regulatory expectations in Europe. Because OKX is subject to MiCA, any suggestion of regulator scrutiny carries added weight for market participants watching how the EU will apply its crypto rules in practice.
It also shows the growing tension between centralized compliance obligations and the operational realities of Web3 services. When stolen funds move through wallet proxies, DEX routes, or other blockchain-based tools, tracing and intervention become more complex. That complexity can create conflicting narratives between affected exchanges, service providers, and regulators trying to determine who should have acted, when, and how.
For now, the facts presented in the source material show a sharp disagreement rather than a resolved enforcement case. Bybit’s published fund-flow summary raised questions about traceability, while OKX insists it blocked relevant funds, added anti-abuse functionality, and is being unfairly portrayed. Until more details emerge from either regulators or the companies involved, the dispute is likely to remain a focal point in discussions about crypto security and responsibility.

