Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerSwapCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

US Court Upholds Bybit’s Request to Trace Funds From $1.5B Hack

bullish:

0

bearish:

0

Us Court Upholds Bybit’s Request To Trace Funds From $1.5b Hack

Newly unsealed court records show a US judge granted Bybit expedited discovery in the exchange’s ongoing legal push to identify assets tied to a $1.5 billion North Korea-linked attack. The ruling is aimed at helping Bybit move from broad allegations toward practical, court-backed tracing—an approach that can matter when large portions of stolen crypto have already been obfuscated.

According to the filings, Bybit brought the case under seal on June 18, naming North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unnamed defendants. The court granted the expedited discovery request the following day, giving Bybit a faster route to request information that could pinpoint alleged intermediaries and determine what—if any—stolen funds remain recoverable through identifiable on-chain or account-linked activity.

Key takeaways

  • Unsealed records confirm a federal judge granted Bybit expedited discovery tied to the June 18 lawsuit over the $1.5 billion 2025 North Korea-linked hack.
  • Bybit claims 90.2% of stolen assets became untraceable after moves through mixers, cross-chain bridges, and OTC trading channels.
  • The company reports 9.8% of the funds were traceable to identifiable wallets, including 5.3% (about $75.5 million) that were frozen or recovered.
  • Bybit obtained a temporary restraining order that the court renewed and partially supported with a preliminary injunction decision later in July.
  • The complaint seeks relief that includes compensatory, punitive and treble damages under the US RICO statute.

Expedited discovery: turning allegations into targeted asset recovery

The court documents describe Bybit’s strategy as an attempt to identify alleged actors and intermediaries that may have handled stolen funds after the hack. Expedited discovery typically shortens the timeline for obtaining information from counterparties or other relevant parties—particularly important in high-stakes crypto cases where defendants may move assets quickly or hide trail details behind complex transaction structures.

In the complaint, Bybit alleges that some traceable assets ended up on or through platforms that operate in the United States or maintain US-based infrastructure. Bybit sought account-holder identities, balances and transaction histories, arguing that certain platforms indicated they would cooperate once a court order was issued.

From an investor and market-structure standpoint, this matters because court-ordered discovery can bridge a gap that often exists in crypto investigations: even when chain analytics suggest where funds may have gone, legal access to counterparties’ records is often what enables meaningful recovery efforts.

How much of the stolen crypto was still traceable?

Bybit’s filing includes a key metric about how the attackers allegedly laundered the stolen assets. As of the June 18 submission, the exchange said 90.2% of the funds had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% it said could be tied to identifiable wallets.

Within that smaller traceable portion, Bybit reported that 5.3% of the total theft—about $75.5 million—had been frozen or recovered. The rest of the traceable amount was described as still linked to identifiable wallets, implying it may be recoverable if the legal process can connect those wallets to accountable parties.

Bybit’s numbers also suggest a significant shift compared with more than a year earlier. The exchange previously reported that 68.57% of the stolen funds remained traceable, a claim attributed to Bybit CEO Ben Zhou at the time. In this newer filing, the traceability figure has dropped materially, underscoring how quickly stolen crypto can become harder to recover as it moves through layered obfuscation techniques.

Restraining orders and injunction steps in July

Alongside expedited discovery, Bybit secured legal measures designed to prevent alleged defendants from moving certain traceable assets while the case progresses. The company obtained a temporary restraining order on June 19 against the unnamed defendants, aimed at halting transfers of specific traceable funds.

That restraining order was renewed on July 16. The court also partially granted Bybit’s request for a preliminary injunction on July 30. While the records indicate that some exhibits and related materials remain sealed, the sequence reflects a court willingness to support Bybit’s attempt to preserve at least part of the identifiable asset set while discovery and claims move forward.

Background of the Feb. 21, 2025 hack and FBI attribution

The underlying incident dates to Feb. 21, 2025. Bybit said the attackers compromised the Safe Wallet infrastructure after gaining access through compromised credentials associated with a Safe developer. Forensic investigations cited in earlier coverage described malicious code being injected into Safe’s cloud infrastructure.

The FBI attributed the theft to North Korea on Feb. 26, 2025, according to its public notice on the incident. That attribution has been central to how regulatory and law enforcement narratives have framed the event, and it helps explain why a civil lawsuit targeting North Korea-linked entities would be pursued alongside asset-tracing and recovery measures.

In the complaint, Bybit seeks recovery related to approximately $1.5 billion, including compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. In practical terms, the damages claim indicates Bybit is not only seeking to preserve and identify assets but also to establish broader liability if the court finds actionable wrongdoing and causation.

What to watch next

The immediate question is whether expedited discovery turns the “traceable” wallet subset into actionable, court-backed targets—especially given Bybit’s claim that most of the stolen crypto has already become untraceable. Readers should watch how the case develops as sealed exhibits are gradually revealed and as the court’s preliminary injunction posture evolves, because those steps can determine how much of the remaining identifiable funds can realistically be recovered.

This article was originally published as US Court Upholds Bybit’s Request to Trace Funds From $1.5B Hack on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.