Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

Bybit Wins Court Order to Trace $1.5B Stolen by Lazarus Group

Diagram showing Bybit's legal pursuit of stolen cryptocurrency through US court system

Bybit’s February 2025 nightmare turned into a courtroom offensive this week. Court records unsealed Thursday reveal that a federal judge granted the exchange expedited discovery authority on June 19, giving Bybit a legal pathway to trace stolen assets that North Korea-linked hackers funneled through platforms with US operations.

The exchange filed suit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unnamed defendants. The complaint alleges that portions of the $1.5 billion stolen in the hack reached exchanges maintaining infrastructure in the United States, and Bybit wants names, balances, and transaction histories from those platforms.

The Discovery Order Gives Bybit Real Leverage

Expedited discovery is not a typical procedural win. Under normal circumstances, parties in federal litigation wait months before they can compel third parties to produce records. The court’s accelerated timeline lets Bybit subpoena exchanges now, while wallets and accounts might still be frozen rather than drained further.

According to the unsealed filings, certain platforms had already signaled they would cooperate once they received a valid court order. That detail matters: it suggests some exchanges were waiting for legal cover before handing over customer data. The discovery authority converts informal willingness into enforceable obligation.

Bybit also obtained a temporary restraining order on June 19 preventing unidentified defendants from moving specific traceable assets. The court renewed that order on July 16 and partially granted a preliminary injunction on July 30. Several exhibits remain sealed, so the exact scope of frozen funds is unclear. But the sequence tells us the court found Bybit’s evidence credible enough to restrain assets before a full trial.

Ninety Percent Already Gone Into the Fog

Here’s the sobering math. As of Bybit’s June 18 filing, 90.2% of the stolen funds had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. Only 9.8% remained in identifiable wallets. Of that remainder, about 5.3% of the total haul (roughly $75.5 million) had been frozen or recovered.

Those percentages mark a steep decline from a year earlier. Bybit CEO Ben Zhou said in early 2025 that 68.57% of the funds were still traceable. The difference captures how quickly sophisticated launderers can obscure stolen crypto when they have time and resources.

To put the $75.5 million recovery in perspective: that represents just 5% of the $1.5 billion headline figure. If Bybit’s litigation ultimately recovers every dollar currently frozen, the exchange would still be out more than $1.4 billion. The discovery order is a tool, not a miracle.

90.2% of Bybit’s stolen funds became untraceable through mixers, bridges, and OTC dealers within 16 months of the hack.

How the Hack Unfolded

The breach occurred on February 21, 2025, when attackers compromised Safe Wallet’s infrastructure. Forensic investigators later determined that credentials belonging to a Safe developer had been stolen, allowing the hackers to inject malicious code into Safe’s cloud environment. That code then manipulated Bybit’s multisig wallet during routine operations.

The FBI formally attributed the theft to North Korea on February 26, 2025. That attribution came just five days after the hack, unusually fast by federal standards, and pointed to the Lazarus Group’s distinctive operational patterns.

The attack followed a familiar playbook. Lazarus Group has specialized in supply-chain compromises, targeting third-party infrastructure rather than hitting exchanges directly. By poisoning Safe Wallet’s developer credentials, the hackers bypassed Bybit’s own security controls entirely. The exchange’s signing process worked exactly as designed; it just signed transactions the attackers had crafted.

The lawsuit seeks more than just the return of stolen assets. Bybit is pursuing approximately $1.5 billion in compensatory damages, punitive damages, and treble damages under the US Racketeer Influenced and Corrupt Organizations Act (RICO).

Treble damages are significant. Under RICO, if Bybit proves the defendants engaged in racketeering activity, the court can triple any actual damages award. A $1.5 billion compensatory judgment could become $4.5 billion.

Of course, collecting a judgment against North Korea presents its own challenges. The regime holds no seizable assets in the United States. But the lawsuit’s real targets appear to be the “20 unidentified defendants” and any intermediary platforms that facilitated the laundering. If discovery reveals that specific exchanges knew or should have known they were processing stolen funds, those entities could face direct liability.

This approach mirrors other recent cases where hack victims have pursued intermediaries rather than the hackers themselves. Earlier this year, a Manhattan judge allowed Aave to pursue recovery of $71 million in hacked ETH linked to Lazarus Group activity, while separately allowing terror victims to maintain claims against the frozen funds. The legal landscape around stolen crypto is evolving quickly, with courts increasingly willing to grant discovery that pierces exchange anonymity.

Diagram showing how Bybit’s $1.5 billion in stolen funds flowed through mixers and bridges, with 90% becoming untraceable

What This Means for Exchange Security and Compliance

The Bybit litigation establishes a template. Exchanges hit by state-sponsored hackers now have a roadmap: file quickly, seek expedited discovery, obtain restraining orders against identified wallets, and use US courts to compel cooperation from platforms with American operations.

That last point deserves emphasis. Any exchange maintaining servers, employees, bank accounts, or registered entities in the United States falls within subpoena reach. The extraterritorial effect is substantial. A Singapore-based exchange that processes withdrawals through a US banking partner could find itself producing records in Virginia federal court.

For compliance teams, the message is clear. Know-your-customer data isn’t just a regulatory checkbox; it’s potential evidence in billion-dollar litigation. Exchanges that can identify account holders quickly will satisfy court orders faster and face less legal exposure themselves. Those that cannot may find themselves named as defendants in future suits.

Bybit’s 90% loss rate also illustrates the limits of post-hack remediation. Once funds hit mixers like Tornado Cash or cross-chain bridges with weak compliance controls, tracing becomes exponentially harder. The most effective security is prevention, not recovery.

The Lazarus Group has now been linked to more than $3 billion in crypto thefts since 2017, with the Bybit hack ranking among the largest single incidents. North Korean hackers have reportedly used stolen crypto to fund weapons programs, which is why the FBI moves quickly on attribution. But attribution and recovery are different things. Knowing who stole the money does not mean getting it back.

The Clock Is Still Running

Some exhibits remain sealed, which suggests Bybit and the court want to avoid tipping off defendants who might still be reachable. The partial preliminary injunction granted on July 30 indicates ongoing asset freezes, but we do not know the dollar amounts involved or the platforms affected.

What we do know: Bybit is playing a long game. The exchange absorbed a $1.5 billion loss and continued operating, which itself required substantial capital reserves. CoinGecko reported earlier this year that Bybit made a “slow but steady comeback” after the hack. This litigation appears to be part of that rehabilitation strategy: demonstrating to users and regulators that the exchange will pursue every legal avenue to recover funds.

The discovery process will likely take months. Subpoenas must be served, platforms must respond, and Bybit’s legal team must analyze whatever data they receive. If specific wallets or accounts are identified, follow-on motions for asset seizure could come next.

Bybit’s complaint opens a window into how the exchange views its own victimization. The company is not just claiming theft; it is alleging racketeering and seeking punitive damages. That framing positions North Korea’s hacking apparatus as an ongoing criminal enterprise, not a one-time adversary. Whether US courts ultimately enforce judgments against a sovereign nation remains uncertain. But the discovery authority Bybit has already obtained is producing real information, and that information might lead to intermediaries with attachable assets.

When Zhou said a year ago that most of the stolen funds were still traceable, he probably expected better odds. The 68.57% has collapsed to under 10%. The lawsuit, filed seventeen months after the hack, is Bybit’s attempt to salvage what remains before the trail goes completely cold. The court’s willingness to grant expedited discovery suggests judges understand the urgency. Once funds disperse through enough mixers, no subpoena can follow them.

Bybit lost $1.5 billion in a single afternoon. The exchange may eventually recover tens of millions through this litigation, possibly more if intermediary liability expands. But the gap between what was stolen and what is recoverable captures a hard truth about crypto security in 2026: the technology that makes assets borderless also makes stolen assets vanishingly hard to trace.

Source Material

Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email