Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro
Cryptocurrency exchange Bybit has issued warnings to users regarding transfers involving sanctioned organizations. Sending cryptocurrency to or receiving funds from such entities is now prohibited, whether conducted directly or through intermediaries.
The exchange published a list titled Restricted Counterparties that can be updated at any time. Among the entities listed are the North Korean cybercriminal group Lazarus and the Russian developer of cryptographic protection tools CryptoPro. Bybit does not claim any direct connection between these organizations beyond their presence on sanctions lists.
Outgoing transfers to prohibited counterparties will be automatically declined. Funds received from listed addresses or related wallets may be frozen, and returning them to the sender is not always possible as legislation may require indefinite holding. User accounts involved in such activity risk suspension or permanent closure.
Bybit reminds users that blockchain transactions are public, enabling fund tracing without requiring admissions from wallet owners. The list is not exhaustive, and the platform may block operations involving counterparties not yet formally added.
These restrictions are part of Bybit's terms of service, which authorize termination of service for any persons or organizations appearing on sanctions lists maintained by the United States, European Union, and United Kingdom.
Related articles
Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics
A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.
Russia's MinTsifry Flags Google Android Developer Verification Rules as Risk to Domestic Apps
Russia's Ministry of Digital Development is assessing new Google policies that will require developer registration for Android apps distributed outside Google Play. The changes, starting in select countries in 2026 and expanding globally in 2027, could block sideloading of Russian applications previously removed from official stores due to sanctions. Minister Maksut Shadaev described the scenario as a potential barrier where users may no longer freely install APK files from third-party sources. Google plans to retain advanced modes and ADB installation options with extra warnings for unverified apps. Custom firmware projects such as LineageOS have stated their devices will remain unaffected by the verification system. Russian banks, marketplaces, and other services that rely on direct APK distribution are viewed as the most exposed.
Rosfinmonitoring Denies Mass Bank Account Blocks Over Partial Data Matches with Sanctions Lists
Rosfinmonitoring has issued clarifications rejecting reports of potential widespread freezes of bank accounts due to partial matches between client data and records of individuals subject to asset freezes. The agency stressed that the draft law is not intended to penalize people who merely share surnames or have similar name transliterations with sanctioned persons. Criteria for determining partial matches have not yet been defined and will be established by a separate order only after the federal law is adopted and real cases are analyzed. The measure provides only for temporary suspension of a transaction rather than automatic refusal or indefinite account blocking. Earlier reports from Izvestia had warned that loosely defined partial-match rules could generate numerous false positives affecting ordinary clients.
Understanding GOST Cryptography Standards: A Practical Guide for Russian Developers
The article provides a beginner-friendly breakdown of Russian GOST cryptographic standards, separating the core functions of hashing, digital signatures, and encryption. It covers the evolution of GOST algorithms across three generations from the 1990s to the current 2012+ standards including Stribog, Kuznechik, and Magma. Detailed explanations address how PKCS#11 interfaces with hardware tokens, how X.509 certificates function as digital passports, and how formats like CAdES, XAdES, and PAdES package signatures for verification. Comparisons with Western equivalents such as SHA-256, RSA, and AES help developers map familiar concepts to GOST implementations. The guide emphasizes practical integration with tools like CryptoPro for tasks involving detached signatures and certificate requests in PKCS#10 and PKCS#12 containers.