
Bybit won U.S. court approval for expedited discovery to trace $1.5B stolen by North Korea's Lazarus Group. Only $75.5M recovered so far as 90% of funds went dark.
A U.S. federal court approved expedited discovery for Bybit last month, giving the exchange access to account records and transaction histories on platforms with U.S. operations as it pursues the $1.5 billion stolen in February's Lazarus Group hack.
The breach hit on Feb. 21, 2025. Attackers compromised Safe Wallet's cloud infrastructure using stolen developer credentials, then injected malicious code to drain a large cryptocurrency position. The FBI confirmed North Korean involvement five days later, on Feb. 26. Bybit filed its lawsuit on June 18, naming North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. The next day, a federal judge signed the expedited discovery request and granted a temporary restraining order barring the unnamed defendants from moving traceable assets.
The discovery order is broad. Bybit can demand account identities, balances, and full transaction histories from any exchange or platform with U.S. ties. The goal is to identify intermediaries who may have helped move the stolen funds, possibly without knowing their origin. Several exchanges had said they would cooperate once a court order was in hand, Bybit's legal team said.
The temporary restraining order from June 19 was renewed on July 16. On July 30, a partial preliminary injunction came through, though some court records remain sealed, limiting visibility into which assets were frozen.
Bybit's legal theory extends beyond standard civil recovery. The exchange seeks $1.5 billion in compensatory damages, plus punitive and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act. RICO is typically used against organized crime. Applying it to a state-sponsored hacking operation is aggressive, but Bybit appears determined to use every available tool.
The recovery numbers are sobering. As of the June filing, 90.2% of the stolen funds had been passed through mixers and cross-chain bridges, then through over-the-counter dealers, making them effectively untraceable. That left 9.8% still trackable, with $75.5 million frozen or recovered so far. Bybit CEO Ben Zhou said that over a year earlier, 68.57% of the funds were still traceable. The window closed fast.
The Lazarus Group has executed similar operations before. Forensic investigators found the attack technically sophisticated: compromised developer credentials were used to plant malicious code inside a cloud system, not a brute-force assault on Bybit's front end. The breach was quiet and targeted.
Suing North Korea directly is nearly impossible to enforce. The country will not appear in a U.S. federal court. But the lawsuit creates a legal record, compels third-party platforms to hand over data, and potentially opens the door to seizing assets in jurisdictions where enforcement is feasible. The 20 unidentified defendants are likely the real target – intermediaries who moved money through exchanges with U.S. connections. Some may not yet know they are defendants.
The partial preliminary injunction from July 30 remains under seal, limiting visibility into which assets have been frozen.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.