News
Platform news and market context
News
Platform news and market context
Bybit Gains US Court Approval to Track Stolen Assets from $1.5 Billion North Korea-Linked Hack
A federal judge has granted crypto exchange Bybit expedited discovery, empowering it to trace a portion of the $1.5 billion in assets stolen in a hack attributed to North Korea by seeking data from platforms with US operations.

A United States federal judge has supported cryptocurrency exchange Bybit's attempt to trace assets connected to a $1.5 billion theft linked to North Korea, according to court records that were unsealed on Thursday. The judge's approval of expedited discovery for Bybit provides the company with a legal tool to pursue the stolen funds.
The lawsuit was initially filed under seal by Bybit on June 18, naming North Korea, its Reconnaissance General Bureau, the Lazarus Group, and twenty other unidentified defendants. The court granted Bybit's motion for expedited discovery just one day later, on June 19.
This legal authority offers Bybit a tangible method for identifying alleged intermediaries and recovering a small fraction of the stolen cryptocurrency that can still be traced. It is a more direct approach than simply seeking a legal judgment against North Korea.
In its complaint, Bybit asserted that some of the traceable assets had been moved to cryptocurrency exchanges that either operate or have infrastructure within the United States. The company is seeking to obtain the identities of account holders, account balances, and complete transaction histories from these platforms. Bybit noted that certain exchanges had already signaled a willingness to cooperate once they received a formal court order.
In addition to the discovery order, Bybit secured a temporary restraining order on June 19. This order prohibits the unidentified defendants from transferring specific traceable assets. The court subsequently renewed that order on July 16 and, on July 30, partially approved Bybit's motion for a preliminary injunction. It should be noted that some exhibits and other case records continue to be sealed from public view.
According to the June 18 filing, the vast majority of the stolen funds, 90.2%, have been rendered untraceable after being processed through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% has been tracked to identifiable digital wallets. Of that amount, 5.3% of the total stolen funds—equivalent to approximately $75.5 million—has been successfully frozen or recovered.
These figures represent a significant decline in traceability from over a year ago. At that time, Bybit CEO Ben Zhou stated that 68.57% of the stolen funds were still traceable.
The original security breach took place on February 21, 2025, when attackers infiltrated the infrastructure of Safe Wallet. Forensic analysis determined that the attackers used compromised credentials belonging to a Safe developer to inject malicious code into the wallet's cloud systems. The Federal Bureau of Investigation (FBI) officially attributed the theft to North Korea on February 26, 2025.
The lawsuit details Bybit's legal objectives, which include the full return of the stolen assets. The exchange is also seeking approximately $1.5 billion in compensatory damages, in addition to punitive damages and treble damages as provided for under the U.S. Racketeer Influenced and Corrupt Organizations (RICO) Act.
Discussion about this post
No comment yet
Be the first to share your opinion!