Why Did Bybit Seek Expedited Discovery?
Bybit has secured expanded court authority to trace assets linked to the $1.5 billion cryptocurrency theft attributed by U.S. authorities to North Korea, giving the exchange another route to pursue funds that remain identifiable more than a year after the attack.
U.S. court records unsealed on Thursday show that Bybit filed a lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. A federal judge granted the exchange’s request for expedited discovery the following day.
The order allows Bybit to seek information from third parties before the normal discovery process would typically begin. That matters because cryptocurrency tracing can identify wallets and transaction paths without necessarily revealing who controls them. Court-backed requests can help connect blockchain addresses to account holders at exchanges, infrastructure providers or other intermediaries.
Bybit alleged that some traceable assets reached exchanges operating in the United States or maintaining infrastructure there. The company sought identities of account holders, balances and transaction histories, saying certain platforms had indicated they would cooperate once presented with a court order.
The legal strategy therefore goes beyond attempting to obtain a judgment against North Korea. Bybit is trying to identify intermediaries and reach assets located within jurisdictions where courts and service providers can act.
How Much Of The Stolen Crypto Can Still Be Traced?
The main obstacle is that most of the stolen cryptocurrency has already disappeared from readily traceable transaction paths. As of Bybit’s June 18 filing, the exchange said 90.2% of the stolen assets had become untraceable after moving through mixers, cross-chain bridges and over-the-counter dealers.
Only 9.8% remained linked to identifiable wallets. Of the original total, about 5.3%, or roughly $75.5 million, had been frozen or recovered.
Those numbers show how quickly recovery prospects can deteriorate after a large crypto theft. More than a year earlier, Bybit CEO Ben Zhou had said 68.57% of the stolen funds remained traceable. The decline since then means the legal process is increasingly focused on a much smaller pool of assets.
Bybit also obtained a temporary restraining order on June 19 preventing the unidentified defendants from transferring certain traceable assets. The court renewed that order on July 16 and partially granted the company’s request for a preliminary injunction on July 30. Some supporting exhibits and other records remain sealed.
Investor Takeaway
Bybit’s case shows that blockchain visibility does not automatically translate into asset recovery. Once stolen funds pass through mixers, bridges and intermediaries, the ability to identify wallets may matter less than whether exchanges, custodians and courts can freeze the assets before they move again.
What Happened In The 2025 Bybit Hack?
The attack occurred on Feb. 21, 2025, after hackers compromised infrastructure connected to Safe Wallet. Forensic investigators said credentials belonging to a Safe developer were compromised, allowing malicious code to be injected into cloud infrastructure used during the transaction process.
The Federal Bureau of Investigation attributed the theft to North Korea on Feb. 26, 2025. The attack became one of the largest cryptocurrency thefts on record and placed fresh attention on operational security around institutional wallets, transaction approvals and third-party infrastructure.
The size of the loss also created an unusual recovery challenge. Moving $1.5 billion through transparent blockchains can leave extensive transaction records, but attackers can reduce traceability by splitting funds across thousands of transactions, switching networks, using decentralized protocols and routing assets through services that obscure ownership.
That makes speed critical. Exchanges and service providers can freeze funds when suspicious deposits are identified, but the opportunity can disappear once assets are converted, bridged or withdrawn again.
Can The Lawsuit Recover More Of Bybit’s Funds?
Bybit is seeking the return of stolen assets as well as about $1.5 billion in compensatory damages, punitive damages and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act.
Recovering damages directly from North Korea would present obvious enforcement difficulties. The more practical value of the lawsuit may therefore lie in the discovery process and court orders directed at entities that can identify account holders or freeze assets within reach of U.S. jurisdiction.
The remaining traceable pool is relatively small compared with the original theft, but tens of millions of dollars can still justify an aggressive recovery effort. Each newly identified exchange account, custodian or intermediary may provide another opportunity to stop funds before they disappear into less transparent channels.
The case also offers a model other crypto companies may follow after major hacks. Blockchain analytics can map where stolen assets travel, while litigation can compel regulated intermediaries to disclose who controls the accounts receiving them.
For Bybit, the challenge is increasingly one of time. The percentage of identifiable assets has fallen sharply since the attack, meaning each additional delay reduces the portion of the $1.5 billion theft that courts and exchanges may still be able to reach.







