United States court records show that a federal judge granted crypto exchange Bybit expedited discovery in its lawsuit against North Korea and related entities, allowing the company to trace assets stolen in the $1.5 billion hack. Bybit alleges that some stolen funds remain traceable, while the majority have become untraceable after passing through mixing services and other platforms.
A federal judge in the United States has authorised Bybit to pursue expedited discovery in its lawsuit against North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. The move follows a $1.5 billion hack attributed to North Korea, which Bybit claims compromised Safe Wallet’s infrastructure in February 2025. The court’s decision includes a temporary restraining order aimed at preventing the transfer of traceable assets.
Bybit’s legal action, filed under seal on 18 June, seeks the return of stolen assets and damages under the US Racketeer Influenced and Corrupt Organizations Act. The firm alleges that 9.8% of the stolen funds remain traceable, with $75.5 million of that amount already frozen or recovered. However, 90.2% of the stolen assets are reportedly untraceable, having been routed through mixing services and other platforms.
The lawsuit has seen several procedural milestones, including the renewal of the temporary restraining order on 16 July and a partial grant of Bybit’s request for a preliminary injunction on 30 July. The FBI attributed the hack to North Korea on 26 February 2025, though the broader claim remains based on alleged evidence.
Ben Zhou, Bybit’s CEO, said more than 68% of the stolen funds were traceable over a year ago, though the current figure has fallen significantly. The identities of the 20 unidentified defendants remain unconfirmed, and it is alleged that some traceable assets may have reached exchanges operating in the United States.
The case highlights the challenges of recovering stolen digital assets in cross-border cybercrime investigations. Bybit’s pursuit of expedited discovery underscores the exchange’s efforts to hold North Korea-linked entities accountable, even as the majority of the stolen funds remain beyond reach.
Written by Daniel Brooks
Security Desk