Sign up
Subscribe
Home / news / US court grants Bybit expedited discovery in $1.5 billion North Korea-linked hack case
news

US court grants Bybit expedited discovery in $1.5 billion North Korea-linked hack case

US court grants Bybit expedited discovery in $1.5 billion North Korea-linked hack case

A federal judge in the United States has backed Bybit’s attempt to trace stolen crypto assets by granting expedited discovery in its lawsuit over the February hack. For PSPs and exchanges, the important detail is simple: when funds pass through mixers, cross-chain bridges and OTC desks, tracing becomes a legal and operational race, not just an investigation.

  1. Unsealed court records show that Bybit filed the lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court granted expedited discovery on June 19, giving Bybit a route to identify alleged intermediaries and pursue the portion of stolen assets that remains traceable.
  2. Bybit said in its complaint that some traceable assets reached exchanges operating or maintaining infrastructure in the US. It asked for account-holder identities, balances and transaction histories, arguing that certain platforms had indicated they would cooperate once they received a court order.
  3. The court also granted a temporary restraining order on June 19 preventing the unidentified defendants from transferring certain traceable assets. That order was renewed on July 16, and the court partially granted Bybit’s request for a preliminary injunction on July 30. Some exhibits and other records remain sealed.
  4. As of the June 18 filing, Bybit said 90.2% of the stolen assets had become untraceable after moving through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% had been traced to identifiable wallets, including 5.3% of the total, about $75.5 million, that had been frozen or recovered.
  5. The figures are a sharp drop from more than a year ago, when Bybit CEO Ben Zhou said 68.57% of the funds remained traceable. The hack occurred on Feb. 21, 2025, after attackers compromised Safe Wallet’s infrastructure; forensic investigators said compromised credentials belonging to a Safe developer allowed malicious code to be injected into its cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26, 2025.

Bybit is seeking the return of the stolen assets, about $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. For high-risk payment providers, the message is not subtle: once assets touch multiple intermediaries, court-backed discovery can become part of the recovery playbook, especially where US-facing infrastructure is involved.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!