N. Korea's Lazarus Lost 90% of Bybit's $1.5B in Crypto, but a Federal Judge Just Opened the Tracing Back Door
A federal judge has approved expedited discovery in Bybit's lawsuit seeking to trace funds stolen in the February 2025 North Korea-linked hack, according to court records unsealed on Thursday. The exchange filed the case under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants, with the court granting the expedited discovery request one day later on June 19. The discovery authority allows Bybit to identify alleged intermediaries and pursue a small portion of stolen assets that remain traceable, rather than relying solely on a judgment against North Korea.
In its complaint, Bybit alleged that some traceable assets reached exchanges operating or maintaining infrastructure in the US. The company sought account-holder identities, balances and transaction histories, stating that certain platforms had indicated they would cooperate after receiving a court order. Bybit also obtained a temporary restraining order on June 19 preventing the unidentified defendants from transferring certain traceable assets. The court renewed the order on July 16 and partially granted Bybit's request for a preliminary injunction on July 30. Some exhibits and other records remain sealed.
As of the June 18 filing, Bybit said 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% had been traced to identifiable wallets, including 5.3% of the total, about $75.5 million, that had been frozen or recovered. The figures mark a sharp drop from more than a year ago, when Bybit CEO Ben Zhou said 68.57% of the funds remained traceable. The lawsuit shows that Bybit is seeking the return of the stolen assets, approximately $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act.
The hack occurred on Feb. 21, 2025, after attackers compromised Safe Wallet's infrastructure. Forensic investigators said compromised credentials belonging to a Safe developer allowed the attackers to inject malicious code into its cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26, 2025.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.