BNB $598.14 +0.99%
XRP $1.04 +0.49%
ETH $1,918.86 -0.14%
BTC $64,973.94 0.00%
BNB $598.14 +0.99%
XRP $1.04 +0.49%
ETH $1,918.86 -0.14%
BTC $64,973.94 0.00%
BREAKING
Crypto Exchanges

Bybit Gets U.S. Court Backing to Chase $1.5B Lazarus Group Theft

Bybit Gets U.S. Court Backing to Chase $1.5B Lazarus Group Theft
Bybit Gets U.S. Court Backing to Chase $1.5B Lazarus Group Theft

Community Trust ScoreVerified

85%
Real
Verified13 votes
Updated 2 hours ago

A U.S. federal court handed Bybit a significant legal weapon last month. The court approved expedited discovery, letting the crypto exchange dig into account records and transaction histories held by platforms with U.S. operations — all in pursuit of the $1.5 billion stolen in what’s become one of the biggest crypto heists on record.

The hack hit on February 21, 2025. North Korean attackers got into Safe Wallet’s cloud infrastructure using compromised credentials from a developer, then injected malicious code that let them drain a massive amount of cryptocurrency. The FBI confirmed North Korea’s involvement just five days later, on February 26, 2025. Bybit filed its lawsuit on June 18, naming North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. The very next day, June 19, a federal judge signed off on the expedited discovery request. Same day, Bybit also locked in a temporary restraining order blocking the unidentified defendants from moving any traceable assets.

Not exactly a small ask.

Advertisement

What the Court Actually Authorized

The expedited discovery order is pretty broad. Bybit can now demand account identities, balances, and full transaction histories from exchanges and platforms that have U.S. connections. The goal is to identify intermediaries — people or entities that may have helped move or hide the stolen funds, possibly without fully knowing what they were handling. Several exchanges have already said they’d cooperate once they get a court order in hand, which is basically what Bybit just secured.

The temporary restraining order from June 19 was renewed on July 16. Then on July 30, a partial preliminary injunction came through — though some of those court records are still sealed, so the full scope of what got frozen isn’t totally clear yet.

The legal theory behind the lawsuit isn’t just standard civil recovery. Bybit is going after compensatory damages of $1.5 billion, but it’s also claiming punitive damages and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act — RICO. That’s a statute usually associated with organized crime prosecutions, and it lets courts triple the damages awarded if the conduct qualifies. Applying it to a state-sponsored North Korean hacking operation is aggressive, maybe even a long shot, but Bybit seems committed to using every available legal tool.

The Traceability Problem

Here’s the hard part. As of when Bybit filed in June, 90.2% of the stolen funds had already gone dark — passed through mixers, cross-chain bridges, and over-the-counter dealers in a way that made them effectively untraceable. That left 9.8% still trackable, with $75.5 million either frozen or recovered so far.

And that 9.8% is actually a sharp drop from where things stood earlier. Bybit CEO Ben Zhou said that over a year ago, 68.57% of the funds were still traceable. The window closed fast. The attackers moved quickly and deliberately, using layered obfuscation tools that are specifically designed to break the on-chain trail. Mixers and cross-chain bridges are hard enough to follow individually — combined with OTC dealers, they can make funds disappear from any practical tracking perspective.

The Lazarus Group has pulled off this kind of operation before. They’re not amateurs. Forensic investigators found that the attack on Safe Wallet’s infrastructure was technically sophisticated — compromised developer credentials used to plant malicious code inside a cloud system, not some brute-force attack on Bybit’s own front end. The breach was quiet, targeted, and it worked.

Bybit’s situation isn’t unique in crypto. Exchanges have faced state-sponsored attacks for years, and the recovery rate on stolen funds has historically been low. The tools available to investigators — blockchain analytics, subpoenas, court orders — are getting better, but so are the laundering techniques on the other side.

What Comes Next

The partial preliminary injunction from July 30 keeps some pressure on, but the sealed records make it hard to know exactly what’s been locked down. Bybit’s legal team is probably using the discovery window right now to gather data from cooperating exchanges before the trail gets any colder.

Suing North Korea directly is also, practically speaking, close to impossible to enforce. The country won’t show up in a U.S. federal court. But the lawsuit still matters — it creates a legal record, it lets Bybit compel third-party platforms to hand over data, and it potentially opens the door to seizing assets in jurisdictions where enforcement is actually possible.

The 20 unidentified defendants are probably where the real action is. Those are the intermediaries, the people who moved money through exchanges with U.S. ties. Some of them may not even know they’re defendants yet.

Bybit has $75.5 million frozen or recovered so far, against a $1.5 billion loss.

Frequently Asked Questions

What did the U.S. court authorize Bybit to do in the Lazarus Group case?

On June 19, a federal judge approved Bybit’s request for expedited discovery, allowing the exchange to obtain account identities, balances, and transaction histories from platforms with U.S. operations to trace stolen assets.

How much of the $1.5 billion stolen from Bybit has been recovered?

As of Bybit’s June filing, $75.5 million has been frozen or recovered, representing 9.8% of the stolen funds — down sharply from 68.57% that was traceable over a year earlier, per CEO Ben Zhou.

Community Trust IndexModerate Confidence
85%
Real
Real85%15%Fake
13 community signals

Pankaj K

Pankaj is a skilled engineer with a passion for cryptocurrencies and blockchain technology. He brings a technical perspective to his coverage of smart contracts, layer-2 solutions, and crypto infrastructure.

Advertisement

Related Stories