US court lets Bybit trace funds from $1.5B North Korea hack
A U.S. judge granted Bybit expedited discovery and temporary restraints to trace assets from a $1.5 billion hack U.S. authorities link to North Korea.
A federal judge granted crypto exchange Bybit expedited discovery and temporary restraints to trace assets tied to a $1.5 billion hack that U.S. authorities attribute to North Korea. Bybit filed the lawsuit under seal on June 18 against North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court approved expedited discovery on June 19 and issued a temporary restraining order the same day.
The discovery authority allows Bybit to seek account-holder identities, balances and transaction histories from platforms that indicated they would comply with a court order. The filings state some traceable assets flowed through exchanges that operate or maintain infrastructure in the United States. The temporary freeze on certain traceable assets was renewed on July 16, and the court partially granted a preliminary injunction on July 30. Some exhibits and other records remain sealed.
In its June 18 complaint, Bybit reported that 90.2% of the stolen assets became untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% was traced to identifiable wallets, and 5.3% of the total — about $75.5 million — had been frozen or recovered as of the filing. The company previously indicated a larger share had been traceable more than a year earlier.
The theft occurred on Feb. 21, 2025, when attackers compromised Safe Wallet’s infrastructure. Forensic investigators reported that compromised credentials belonging to a Safe developer allowed the attackers to inject malicious code into cloud infrastructure. The FBI publicly attributed the theft to North Korean actors on Feb. 26, 2025.
Bybit is seeking the return of the stolen assets, roughly $1.5 billion in compensatory damages, punitive damages and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act. The expedited discovery is intended to let Bybit identify alleged intermediaries and compel platforms to produce account information and transaction records so the company can pursue the traceable funds directly.
Unsealed court records do not identify the 20 unnamed defendants or specific wallet details. The discovery and temporary restraints provide a targeted legal route to recover the portion of funds that remained traceable after the attackers used laundering services and obfuscation tools.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








