Federal Judge Approves Bybit's Request to Track $1.5B in Assets from North Korea-Linked Cyberattack

Federal Judge Approves Bybit's Request to Track $1.5B in Assets from North Korea-Linked Cyberattack

The cryptocurrency exchange receives court authorization to obtain user identities, account balances and transaction records from platforms operating within United States jurisdiction.

Court documents from the United States that were made public on Thursday reveal that a federal magistrate has approved cryptocurrency exchange Bybit's initiative to track down funds taken during the $1.5 billion cyberattack attributed to North Korea, providing the platform with expedited discovery privileges.

The unsealed records indicate that Bybit initiated legal proceedings under confidential seal on June 18, naming North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unknown parties as defendants. The following day, on June 19, the court approved Bybit's motion for expedited discovery.

This discovery authorization provides Bybit with an actionable pathway to unmask suspected intermediaries and recover a limited fraction of the stolen cryptocurrency that can still be traced, instead of depending entirely on a legal judgment against the North Korean state.

Within its legal complaint, Bybit asserted that portions of the traceable cryptocurrency arrived at exchanges that either operate within or maintain technological infrastructure on United States soil. The exchange requested information including account holder identities, current balances and complete transaction records, noting that specific platforms had signaled their willingness to provide cooperation upon receipt of a judicial order.

Bybit says 90% of stolen funds became untraceable

Additionally, Bybit secured a temporary restraining order on June 19 that prohibits the unnamed defendants from moving specific traceable cryptocurrency holdings. The court extended this order on July 16 and on July 30 granted part of Bybit's motion for a preliminary injunction. Certain exhibits and additional court documents continue to remain under seal.

According to the June 18 court filing, Bybit reported that 90.2% of the stolen cryptocurrency had become impossible to trace following movement through mixing services, cross-chain bridges and over-the-counter trading desks. The balance of 9.8% had been successfully traced to identifiable digital wallets, which includes 5.3% of the total amount, approximately $75.5 million, that has been either frozen or successfully recovered.

These numbers represent a significant decline from over a year earlier, when Bybit CEO Ben Zhou stated at that point in time that 68.57% of the stolen funds could still be traced.

The cyberattack took place on Feb. 21, 2025, following the attackers' successful compromise of Safe Wallet's technology infrastructure. Digital forensic experts determined that stolen authentication credentials that belonged to a Safe developer enabled the threat actors to insert malicious code into the platform's cloud-based infrastructure. The FBI publicly attributed the theft to North Korea on Feb. 26, 2025.

The legal filing demonstrates that Bybit is pursuing the complete return of the stolen cryptocurrency assets, compensatory damages totaling approximately $1.5 billion, punitive damages and treble damages pursuant to the United States Racketeer Influenced and Corrupt Organizations Act.

← Back to Blog