
Expedited discovery lets Bybit seek account identities and balances from US-based platforms after 90% of stolen assets became untraceable.
A federal judge has backed Bybit's effort to trace assets stolen in the $1.5 billion North Korea-linked hack, granting the exchange expedited discovery in a sealed lawsuit unsealed Thursday.
The court gave Bybit authority to seek account-holder identities, balances and transaction histories from platforms that operate or maintain infrastructure in the United States. The order, dated June 19, came one day after Bybit filed the lawsuit under seal against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants.
Bybit argued in its complaint that some traceable stolen assets had reached US-based exchanges. The company said those platforms had indicated they would cooperate after receiving a court order.
The judge also issued a temporary restraining order on June 19 that barred the unidentified defendants from transferring certain traceable assets. The court renewed that order on July 16 and partially granted Bybit's request for a preliminary injunction on July 30. Some exhibits and other records remain sealed.
As of the June 18 filing, 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers, Bybit said. The remaining 9.8% had been traced to identifiable wallets. Of that, 5.3% of the total -- roughly $75.5 million -- had been frozen or recovered.
Those figures mark a sharp decline from more than a year ago. Bybit CEO Ben Zhou said at the time that 68.57% of the funds remained traceable.
The lawsuit itself seeks the return of the stolen assets, approximately $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act.
The hack occurred Feb. 21, after attackers compromised Safe Wallet's infrastructure. Forensic investigators said compromised credentials belonging to a Safe developer allowed the attackers to inject malicious code into its cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.