Court clears Bybit to chase the money trail behind its $1.5B North Korea hack
A federal judge granted the exchange expedited discovery over exchanges with US operations, but Bybit's own filings show just how much of the trail has already gone cold.
By Jane Doe
Published on Aug 8, 2026
- Newly unsealed US court records show Bybit won expedited discovery to trace stolen funds from the February 2025 hack linked to North Korea.
- Bybit sued North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants under seal on June 18; a judge granted expedited discovery the next day.
- As of that filing, 90.2% of the stolen assets were untraceable after passing through mixers, cross-chain bridges, and OTC desks — only 5.3% (about $75.5 million) has been frozen or recovered.
- Bybit is seeking the full $1.5 billion back plus punitive and treble damages under the US RICO Act, but a judgment against North Korea is only as useful as the assets it can actually reach.
What happened
Court records unsealed on Thursday confirm that a US federal judge has backed Bybit's attempt to trace assets stolen in the $1.5 billion hack that investigators linked to North Korea. The exchange filed its lawsuit under seal on June 18, naming North Korea itself, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. The court granted expedited discovery the following day, June 19.
Expedited discovery is the practical engine of the case: it lets Bybit demand account-holder identities, balances, and transaction histories from exchanges and platforms that operate or maintain infrastructure in the US, rather than depending entirely on a legal judgment against a state that will almost certainly never pay it. Bybit's complaint states that some of the traceable stolen assets reached exchanges with US operations, and that certain platforms had already signaled they'd cooperate once a court order was in hand.
The underlying theft happened on February 21, 2025, after attackers compromised Safe Wallet's infrastructure. Forensic investigators traced the breach to stolen credentials belonging to a Safe developer, which let attackers inject malicious code into the company's cloud infrastructure. The FBI publicly attributed the theft to North Korea five days later, on February 26, 2025.
Background: why exchanges sue in US courts over offshore hacks
Filing in a US court doesn't require the hackers to be American, or even identifiable. What it buys is jurisdiction over the exchanges, banks, and payment processors that stolen funds pass through if any of them touch US infrastructure. A discovery order compels those third parties to hand over account data, even though they aren't accused of wrongdoing themselves — it's the fastest legal lever to unmask intermediaries sitting between a hack and a cash-out.
Why it matters
The case turns a slow-moving criminal attribution story into an active civil asset hunt. North Korea isn't going to show up and pay a judgment, so the discovery order matters far more than the eventual verdict: it's the mechanism that could actually put names to the wallets and OTC desks that touched the stolen funds.
The case also carries a broader signal for the industry: Bybit is leaning on the US Racketeer Influenced and Corrupt Organizations Act (RICO), which allows for treble damages — three times the proven loss — on top of compensatory and punitive damages. That's a far more aggressive posture than the criminal-referral-and-wait approach exchanges have typically taken after state-linked hacks.
The numbers
Bybit's own accounting, as stated in the June 18 filing, shows how quickly stolen crypto becomes unreachable once it starts moving through laundering infrastructure.
Source figures only. Bybit CEO Ben Zhou's 68.57% figure is dated only as "more than a year ago" relative to the June 18 filing — see flag below.
Market reaction
The source material contains no price data, trading volume, or sentiment indicators tied to this court ruling, and no market-moving language beyond the case's own dollar figures.
What's next / things to watch
The docket already shows a pattern of the court siding with Bybit on interim relief: a temporary restraining order granted June 19, renewed July 16, and a preliminary injunction partially granted July 30. Some exhibits and other records in the case remain sealed, so the full list of named or newly identified defendants isn't public yet.
With expedited discovery in hand, the next concrete step is exchanges and platforms with US operations turning over account identities, balances, and transaction histories tied to the traceable 9.8% of funds. Whether that produces usable leads on the 20 unidentified defendants — or simply confirms dead ends — is the open question the source doesn't yet answer.
Methodology & sourcing notes
All figures in this piece (dollar amounts, percentages, and dates) are taken directly from the unsealed court filing details reported in the source article. No figures were estimated, extrapolated, or sourced elsewhere. Two figures are explicitly flagged above for ambiguity rather than smoothed into precise-sounding claims: the dating of the 68.57% figure, and the composition of the $75.5 million "frozen or recovered" total.
FAQs
What happened in the Bybit hack?
Attackers compromised Safe Wallet's infrastructure on February 21, 2025, using stolen credentials from a Safe developer to inject malicious code, resulting in roughly $1.5 billion in stolen crypto. The FBI attributed the theft to North Korea on February 26, 2025.
How much of the stolen $1.5 billion can actually be recovered?
As of Bybit's June 18 filing, 90.2% of the funds were untraceable after moving through mixers, cross-chain bridges, and OTC desks. Of the remaining 9.8% traced to identifiable wallets, 5.3% (about $75.5 million) has been frozen or recovered.
Who is Bybit suing?
North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants, in a lawsuit filed under seal on June 18.
What is "expedited discovery" and why does it matter here?
It's a court order letting Bybit demand account identities, balances, and transaction histories from exchanges and platforms with US operations — a practical way to unmask intermediaries who handled traceable stolen funds, without waiting for a judgment against North Korea itself.
What damages is Bybit seeking?
The lawsuit seeks the return of the stolen assets (about $1.5 billion), plus compensatory damages, punitive damages, and treble damages under the US Racketeer Influenced and Corrupt Organizations Act (RICO).
- Source article references a related Cointelegraph piece, "Bybit made 'slow but steady comeback' in 2025 after massive hack: CoinGecko," but provides no URL — not linked here per sourcing rules.
- No other external URLs were present in the supplied source material.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.