OKX has pushed back against reports alleging that European regulators are investigating the exchange for failing to stop funds linked to the Bybit hack. The Seychelles-based crypto platform said the claims mischaracterize its role and ignore the steps it says it took after the security breach became public. At the center of the dispute is whether OKX’s Web3 wallet and related infrastructure played a meaningful role in the movement of stolen assets.
OKX Says It Took Action After the Hack
In a post published on X on March 11, OKX said that once Bybit was hacked, it moved to block the associated funds from entering its centralized exchange. The company also said it rolled out a newly developed feature designed to detect and block hacker-linked addresses from accessing its DEX and wallet services. The statement was framed as a direct response to reporting that suggested European authorities were scrutinizing one of its wallet-related services.
OKX argued that the narrative portraying it as having failed to freeze suspicious assets was inaccurate. According to the exchange, the confusion stemmed from comments and interpretations linked to statements made by Bybit, rather than from an objective assessment of the controls OKX had already deployed. Its public messaging made clear that it does not accept the characterization that it allowed illicit funds to move freely across its systems.
Why the Web3 Wallet Became the Focus
The controversy intensified after a report claimed that hackers suspected of having North Korean backing used an OKX wallet service to launder $100 million in digital assets. That report referenced a March 4 summary shared by Bybit CEO Ben Zhou, who outlined how stolen funds had moved after the attack. In that breakdown, Zhou said that of the 40,233 ETH that passed through the OKX Web3 proxy, only 16,680 ETH remained traceable.
According to Zhou’s summary, the remaining 23,553 ETH could not be tracked further. He said that to obtain more clarity, Bybit would need information from the OKX Web3 wallet. That detail appears to have drawn the attention of European authorities, with the report stating that regulators had zeroed in on OKX’s Web3 “proxy” as they tried to understand the movement of the stolen crypto.
Some regulators, according to the same report, have called on the European Securities and Markets Authority and the European Banking Authority to take action against OKX. The scrutiny carries added significance because OKX operates under the European Union’s Markets in Crypto-Assets (MiCA) framework, making any suggestion of regulatory concern especially sensitive for the exchange and for the broader market.
OKX Rejects the Allegations
OKX has firmly denied that its Web3 services are exceptional in a way that would justify singling them out. The exchange said its wallet offering is not materially different from services provided by rival crypto platforms. In its view, the current criticism reflects a misunderstanding of how such tools operate and an unfair attempt to shift attention away from the original security failure at Bybit.
The company also directly criticized Bybit, accusing it of contributing to a false narrative. OKX said it would continue to assist Bybit and support broader industry security efforts, but it drew a hard line against what it described as misleading claims about its involvement. Its statement suggested that the issue began with a serious vulnerability at Bybit, and that subsequent commentary had distorted the role of third-party infrastructure providers.
Broader Questions for the Industry
The dispute highlights a growing tension in crypto regulation: how responsibility should be assigned when stolen funds pass through decentralized or semi-decentralized tools connected to major exchanges. As regulators sharpen their focus on asset tracing, wallet infrastructure, and compliance obligations, firms operating Web3 products may face tougher questions about where their duties begin and end.
For now, the facts publicly cited remain limited to the statements from OKX, reporting on regulator interest, and Bybit’s own summary of fund movements. What is clear is that the case has reopened difficult conversations around exchange security, post-hack tracing, and the compliance expectations attached to wallet and proxy services in the MiCA era.
If the issue escalates, it could become an important test of how European authorities approach crypto platforms that combine centralized exchange operations with Web3-facing infrastructure. It may also influence how exchanges design future controls for detecting suspicious addresses, freezing risky flows, and cooperating with counterparties after major exploits.

