Skip to main content

US Court OKs Expedited Discovery for Bybit’s $1.5B North Korea Hack Tracing



Unsealed US court records released this week indicate a federal judge has allowed crypto exchange Bybit to move quickly in its bid to track and recover funds tied to the $1.5 billion North Korea-linked attack that hit the platform in February 2025. The order grants Bybit expedited discovery, a procedural step that can help the exchange identify alleged intermediaries and pursue a limited portion of stolen assets that remain capable of being traced.



According to the docket on CourtListener, Bybit filed its lawsuit under seal on June 18 against North Korea, the Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. The court granted the request for expedited discovery the following day, June 19—an early authorization that signals the court’s willingness to support time-sensitive efforts to obtain transactional and account information relevant to the case.



Key takeaways



  • Bybit secured expedited discovery in a US case targeting parties allegedly involved in the February 2025 North Korea-linked $1.5 billion hack.

  • The exchange argues that only a minority of stolen funds remains traceable, with 9.8% identified as linked to identifiable wallets as of the June 18 filing.

  • A temporary restraining order was obtained on June 19, renewed on July 16, and partially backed by a preliminary injunction on July 30.

  • Bybit’s complaint seeks recovery of approximately $1.5 billion, including compensatory, punitive, and treble damages under US RICO law.

  • The share of traceable funds reported by Bybit has fallen significantly versus a prior estimate cited by its CEO over a year earlier.



Expedited discovery aims to narrow the recovery path


Expedited discovery changes the practical timeline for Bybit’s legal strategy. In a standard civil case, parties often wait longer for evidence requests and responses. Here, the court’s decision effectively gives Bybit a faster route to request information that can help determine who may be holding, routing, or facilitating portions of stolen crypto.



The records indicate Bybit’s complaint asserts that some of the assets it claims were stolen were routed to exchanges and other services that operate in, or maintain infrastructure in, the United States. Bybit’s filings sought account-holder identities, balances, and transaction histories from relevant platforms—information the company argued would be available after receiving a court order.



For investors and market participants watching post-incident enforcement, this matters because stolen-fund recoveries in crypto often depend on how quickly claimants can obtain counterparty data before assets shift again. A court-backed discovery window can also clarify whether intermediaries are identifiable enough to support targeted lawsuits or enforcement.



Bybit cites a steep drop in traceable funds


Beyond procedure, the court documents also provide a snapshot of how much of the alleged theft Bybit believes remains linkable. In its June 18 filing, Bybit stated that 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers.



That leaves 9.8% traced to identifiable wallets, including 5.3% of the total (about $75.5 million) that Bybit said had been frozen or recovered. The company also appears to be positioning these traceable portions as the realistic starting point for an asset-recovery effort—rather than expecting a full return of the entire sum through a judgment against North Korea alone.



The exchange’s figures also reflect a notable change from earlier in the case. The records reference remarks by Bybit CEO Ben Zhou more than a year earlier, stating that 68.57% of the funds remained traceable at the time. If those earlier estimates are taken at face value, the current accounting suggests a major degradation in traceability over time—consistent with how attackers and intermediaries may move value across services designed to obscure origin.



Restraining order and partial injunction support preservation of assets


Court filings also show that Bybit obtained a temporary restraining order on June 19 aimed at stopping the unidentified defendants from transferring certain traceable assets. The court renewed that order on July 16 and partially granted Bybit’s request for a preliminary injunction on July 30.



While the documents indicate the court is actively managing the case to preserve at least some assets, some exhibits and other materials remain sealed. That confidentiality limits what outside observers can confirm about the precise scope of the relief, but the procedural milestones themselves underscore that Bybit’s claims are progressing through the federal court system rather than remaining purely theoretical.



Background: the 2025 hack and attribution


The alleged theft dates back to Feb. 21, 2025. According to earlier reporting referenced in the court-linked account, attackers compromised Safe Wallet’s infrastructure after obtaining access through compromised credentials tied to a Safe developer, allowing malicious code to be injected into its cloud environment.



For its attribution, the FBI published a public notice on Feb. 26, 2025 stating that the theft was carried out in connection with North Korea. That attribution is important context for the lawsuit because it frames the alleged threat actor behind the event, even as the civil claims focus on specific defendants and mechanisms to recover assets.



In its lawsuit, Bybit is seeking return of stolen assets estimated at approximately $1.5 billion, along with compensatory damages, punitive damages, and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. The inclusion of RICO indicates Bybit is pursuing broader claims beyond a single breach—attempting to fit the alleged behavior into a pattern of racketeering-type conduct recognized under US law.



As court records show, Bybit’s current push is not just about winning a judgment, but about securing the evidence and preservation measures needed to make recovery feasible in practice. With most of the claimed funds allegedly rendered untraceable, the value of expedited discovery and early injunctive relief is likely to be judged by whether Bybit can identify counterparties while the remaining traceable portion is still reachable.



Going forward, readers should watch what information the expedited discovery process yields and whether the preliminary injunction’s partial scope expands as the court reviews more sealed exhibits—especially as Bybit’s own accounting suggests traceability has fallen sharply since earlier estimates.



https://www.cryptobreaking.com/us-court-oks-expedited-discovery/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=US%20Court%20OKs%20Expedited%20Discovery%20for%20Bybit’s%20$1.5B%20North%20Korea%20Hack%20Tracing%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...