Skip to main content
BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——
Preise
cryptoAug 8, 2026, 12:53 PM

Bybit Wins Expedited Discovery in $1.5B North Korea-Linked…

Court records show Bybit is pursuing expedited discovery in a $1.5B North Korea-linked hack case, but just 9.8% of stolen assets remain traceable.

Bybit is pursuing a U.S. lawsuit tied to the $1.5 billion cryptocurrency theft that federal authorities attributed to North Korea, with newly unsealed court records showing the exchange has secured expedited discovery powers to chase the shrinking pool of assets that can still be traced.

The exchange filed its sealed complaint on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unnamed defendants. A federal judge granted expedited discovery the next day, allowing Bybit to seek information from third parties before the normal discovery timetable would begin. Bybit has argued that such court-backed requests can help link blockchain addresses to account holders at exchanges, infrastructure providers and other intermediaries, especially where some traceable assets reached platforms operating in the U.S. or maintaining infrastructure there.

As of the June 18 filing, however, Bybit said 90.2% of the stolen funds had become untraceable after moving through mixers, cross-chain bridges and over-the-counter dealers. Only 9.8% remained tied to identifiable wallets, and about 5.3% — roughly $75.5 million — had been frozen or recovered. The figures mark a sharp decline from earlier estimates: more than a year after the attack, Bybit CEO Ben Zhou had said 68.57% of the stolen funds remained traceable.

The court also granted a temporary restraining order on June 19 barring the unidentified defendants from moving certain traceable assets. That order was renewed on July 16, and on July 30 the court partially granted Bybit’s request for a preliminary injunction. Some supporting exhibits and other records remain sealed.

The underlying heist occurred on Feb. 21, 2025, when hackers compromised infrastructure tied to Safe Wallet. Forensic investigators found that credentials belonging to a Safe developer had been compromised, allowing malicious code to be injected into cloud infrastructure used during transaction processing. The FBI publicly attributed the theft to North Korea on Feb. 26, 2025.

Bybit is seeking the return of the stolen assets, roughly $1.5 billion in compensatory damages, and punitive and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act. Recovery from North Korea itself faces obvious enforcement hurdles, but the case’s practical value may rest on court orders directed at intermediaries that can identify account holders or freeze assets within U.S. reach. With the identifiable pool shrinking rapidly, the case highlights how speed matters: once stolen crypto is bridged, mixed or converted, the window for recovery can close quickly. The lawsuit may also serve as a template for other crypto firms considering litigation after major hacks.

Source: FinanceFeeds