Skip to main content

US Court Upholds Bybit’s Request to Trace Funds From $1.5B Hack



Newly unsealed court records show a US judge granted Bybit expedited discovery in the exchange’s ongoing legal push to identify assets tied to a $1.5 billion North Korea-linked attack. The ruling is aimed at helping Bybit move from broad allegations toward practical, court-backed tracing—an approach that can matter when large portions of stolen crypto have already been obfuscated.



According to the filings, Bybit brought the case under seal on June 18, naming North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unnamed defendants. The court granted the expedited discovery request the following day, giving Bybit a faster route to request information that could pinpoint alleged intermediaries and determine what—if any—stolen funds remain recoverable through identifiable on-chain or account-linked activity.



Key takeaways



  • Unsealed records confirm a federal judge granted Bybit expedited discovery tied to the June 18 lawsuit over the $1.5 billion 2025 North Korea-linked hack.

  • Bybit claims 90.2% of stolen assets became untraceable after moves through mixers, cross-chain bridges, and OTC trading channels.

  • The company reports 9.8% of the funds were traceable to identifiable wallets, including 5.3% (about $75.5 million) that were frozen or recovered.

  • Bybit obtained a temporary restraining order that the court renewed and partially supported with a preliminary injunction decision later in July.

  • The complaint seeks relief that includes compensatory, punitive and treble damages under the US RICO statute.



Expedited discovery: turning allegations into targeted asset recovery


The court documents describe Bybit’s strategy as an attempt to identify alleged actors and intermediaries that may have handled stolen funds after the hack. Expedited discovery typically shortens the timeline for obtaining information from counterparties or other relevant parties—particularly important in high-stakes crypto cases where defendants may move assets quickly or hide trail details behind complex transaction structures.



In the complaint, Bybit alleges that some traceable assets ended up on or through platforms that operate in the United States or maintain US-based infrastructure. Bybit sought account-holder identities, balances and transaction histories, arguing that certain platforms indicated they would cooperate once a court order was issued.



From an investor and market-structure standpoint, this matters because court-ordered discovery can bridge a gap that often exists in crypto investigations: even when chain analytics suggest where funds may have gone, legal access to counterparties’ records is often what enables meaningful recovery efforts.



How much of the stolen crypto was still traceable?


Bybit’s filing includes a key metric about how the attackers allegedly laundered the stolen assets. As of the June 18 submission, the exchange said 90.2% of the funds had become untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% it said could be tied to identifiable wallets.



Within that smaller traceable portion, Bybit reported that 5.3% of the total theft—about $75.5 million—had been frozen or recovered. The rest of the traceable amount was described as still linked to identifiable wallets, implying it may be recoverable if the legal process can connect those wallets to accountable parties.



Bybit’s numbers also suggest a significant shift compared with more than a year earlier. The exchange previously reported that 68.57% of the stolen funds remained traceable, a claim attributed to Bybit CEO Ben Zhou at the time. In this newer filing, the traceability figure has dropped materially, underscoring how quickly stolen crypto can become harder to recover as it moves through layered obfuscation techniques.



Restraining orders and injunction steps in July


Alongside expedited discovery, Bybit secured legal measures designed to prevent alleged defendants from moving certain traceable assets while the case progresses. The company obtained a temporary restraining order on June 19 against the unnamed defendants, aimed at halting transfers of specific traceable funds.



That restraining order was renewed on July 16. The court also partially granted Bybit’s request for a preliminary injunction on July 30. While the records indicate that some exhibits and related materials remain sealed, the sequence reflects a court willingness to support Bybit’s attempt to preserve at least part of the identifiable asset set while discovery and claims move forward.



Background of the Feb. 21, 2025 hack and FBI attribution


The underlying incident dates to Feb. 21, 2025. Bybit said the attackers compromised the Safe Wallet infrastructure after gaining access through compromised credentials associated with a Safe developer. Forensic investigations cited in earlier coverage described malicious code being injected into Safe’s cloud infrastructure.



The FBI attributed the theft to North Korea on Feb. 26, 2025, according to its public notice on the incident. That attribution has been central to how regulatory and law enforcement narratives have framed the event, and it helps explain why a civil lawsuit targeting North Korea-linked entities would be pursued alongside asset-tracing and recovery measures.



In the complaint, Bybit seeks recovery related to approximately $1.5 billion, including compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. In practical terms, the damages claim indicates Bybit is not only seeking to preserve and identify assets but also to establish broader liability if the court finds actionable wrongdoing and causation.



What to watch next


The immediate question is whether expedited discovery turns the “traceable” wallet subset into actionable, court-backed targets—especially given Bybit’s claim that most of the stolen crypto has already become untraceable. Readers should watch how the case develops as sealed exhibits are gradually revealed and as the court’s preliminary injunction posture evolves, because those steps can determine how much of the remaining identifiable funds can realistically be recovered.



https://www.cryptobreaking.com/us-court-upholds-bybits-request/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=US%20Court%20Upholds%20Bybit’s%20Request%20to%20Trace%20Funds%20From%20$1.5B%20Hack%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...