In a major development for the cryptocurrency industry, a United States federal judge has officially supported Bybit’s aggressive legal effort to trace and recover assets stolen in a devastating $1.5 billion cyberattack. The massive theft, which occurred on February 21, 2025, was quickly attributed by the FBI to North Korea’s notorious Lazarus Group. Now, newly unsealed court documents reveal that Bybit has been granted “expedited discovery,” a powerful legal tool that allows the cryptocurrency exchange to actively hunt down the remaining traceable funds hidden across platforms with US operations.
The Legal Strategy: Hunting Down the Stolen Crypto
Bybit quietly initiated this legal battle by filing a sealed lawsuit on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group, and twenty unnamed individuals. Just one day later, the court granted the exchange’s request for expedited discovery. This critical legal victory gives Bybit a practical and immediate way to identify the middlemen handling the stolen loot, rather than simply waiting on an impossible-to-collect judgment against the North Korean government. With this authority, Bybit can legally demand account-holder identities, transaction histories, and balance details from exchanges operating within the United States.
To ensure the remaining funds do not slip away while the investigation continues, Bybit successfully secured a temporary restraining order to stop the unidentified defendants from moving any traceable assets. The court renewed this freeze in mid-July and partially granted a preliminary injunction shortly after. According to the lawsuit, several US-based platforms have already indicated they are willing to cooperate and hand over the requested user data now that a formal court order is in place. Bybit is ultimately seeking the return of the stolen assets, alongside compensatory, punitive, and treble damages under the US Racketeer Influenced and Corrupt Organizations (RICO) Act.
The Shrinking Trail: Where Did the $1.5 Billion Go?
The original hack was executed after cybercriminals compromised the cloud infrastructure of Safe Wallet by stealing a developer’s credentials and injecting malicious code. While Bybit moved quickly to track the fallout, the window to recover the funds is closing rapidly. As of the June legal filings, Bybit revealed that a staggering 90.2% of the stolen $1.5 billion has already become completely untraceable. The hackers successfully laundered the vast majority of the crypto through complex over-the-counter dealers, cross-chain bridges, and privacy mixers.
This represents a massive drop in visibility compared to the months immediately following the breach. Over a year ago, Bybit CEO Ben Zhou optimistically reported that nearly 69% of the stolen funds were still traceable on the blockchain. Today, only 9.8% of the assets can be tracked to identifiable wallets. Despite the heavy losses, the legal and forensic push has not been entirely in vain. Through aggressive tracking, Bybit has managed to successfully freeze or recover roughly 5.3% of the total stolen amount, equating to a solid $75.5 million saved from the hackers’ hands.