A US federal court has granted crypto exchange Bybit expedited access to banking and exchange records in a civil case against North Korea. The goal is simple: trace part of the $1.5 billion stolen during the February 2025 hack, which drained one of the industry's largest hot wallets. Records unsealed on Thursday, August 6, show the lawsuit was actually filed back in mid-June, and the court issued its first rulings within a single day. Analytics firms estimate that hackers linked to North Korea have stolen billions of dollars in crypto over the past several years, and the Bybit attack ranks among the largest single episodes in that pattern.
What the court decided
Bybit filed the lawsuit under seal on June 18, 2026. The named defendants are North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified individuals the company describes as intermediate recipients of the funds. The very next day, June 19, the court granted the request for expedited discovery. That tool rarely shows up in cybercrime cases. It lets a plaintiff demand documents before formal hearings even start, while assets can still be found. On that same day the judge also issued a temporary restraining order blocking transfers of already traced assets. The order was renewed on July 16, and on July 30 the court partially granted a separate Bybit request for a preliminary injunction, widening the pool of frozen assets. Some case documents, including certain exhibits, remain sealed to this day, so the full scope of Bybit's claims is still unknown even to reporters following the case.
Who got pulled into the discovery order
Expedited discovery gives Bybit the right to demand account holder identities, balances, and full transaction histories from crypto platforms with US infrastructure. The company claims part of the stolen trail leads straight to such platforms rather than dissolving abroad immediately. According to Bybit's lawyers, some platforms agreed to cooperate voluntarily as soon as they received a copy of the court order, without waiting for a separate subpoena. Recipients include both large centralized exchanges and lesser known services registered in the US, where even small batches of funds could have landed. This is not the first time Bybit has leaned on industry partners. Right after the hack the exchange launched a bounty program for bounty hunters, and has since repeatedly asked other platforms to freeze or return assets. Right after the hack, Bybit covered the losses from its own reserves and loans from partners, so clients kept withdrawing funds without delays, and the lawsuit is no longer about the exchange's solvency but about getting the stolen money back. Legal pressure through the courts is simply the next, more formal stage of that same effort, and it gives the exchange formal power to compel data once a partner's goodwill runs out.
Where the money went
According to the filing, only 9.8% of the stolen sum remains tied to identifiable wallets that could theoretically be frozen. Of that, 5.3%, roughly $75.5 million, has already been frozen or recovered through cooperation with exchanges and analytics firms. That marks a sharp drop from last year's estimate. A year ago, Bybit CEO Ben Zhou said 68.57% of the funds could still be traced, nearly two thirds of the total. The hot wallet drained back then held mostly Ethereum, so the bulk of the $1.5 billion sits in that one coin rather than bitcoin or stablecoins. The longer assets keep moving through mixers and bridges, the smaller the odds of getting them back. Every extra hop blurs the trail and makes attribution harder. It matters for ordinary exchanges too: large sums with a shady history usually fail KYC checks and get stuck at intermediate addresses instead of reaching a final cash-out. Analysts working with Bybit keep updating their map of the funds, but admit some chains simply go dark on platforms outside US jurisdiction.
- The hack happened on February 21, 2025, through compromised Safe wallet infrastructure.
- Attackers injected malicious code using one developer's stolen credentials.
- The FBI formally linked the attack to North Korea on February 26, 2025.
What North Korea is facing
In the lawsuit, Bybit seeks the return of stolen assets plus compensatory, punitive, and treble damages under the US RICO Act, a law normally aimed at organized crime. Formally, the defendant is a state that is unlikely to ever show up in a US court or voluntarily pay a single dollar. That's why Bybit's lawyers are betting not on North Korea itself but on US-based intermediaries, where part of the funds may still have landed through accounts that look perfectly legitimate on the surface. The legal process will run for months, possibly years, given the scale of the case and the secrecy around parts of the record. But the orders already secured give Bybit real legal pressure to use against platforms that might still hold traces of the money, even if the funds themselves have long since dissolved into the network. For the industry as a whole, the case could become a precedent. If the court backs Bybit's strategy, other victims of major hacks get a ready-made template for moving fast through US courts instead of waiting for years.




Comments
Your email address will not be published. Required fields are marked *