
Bybit’s effort to recover assets from the $1.5 billion February 2025 hack has moved deeper into the U.S. court system, with a federal judge granting expedited discovery and later part of the exchange’s request for a preliminary injunction.
Summary
- Bybit secured expedited discovery allowing requests for identities, balances and transaction histories from U.S.-linked platforms.
- Court records show temporary restraints began June 19, with a partial preliminary injunction July 30.
- Bybit reports $48.4 million recovered and $30.5 million frozen across 28-plus exchanges and custodians worldwide.
- Bybit said 90.2% of stolen assets were untraceable when its June complaint was initially filed.
- The FBI officially attributes the February 2025 theft to North Korean cyber actors called TraderTraitor.
Bybit filed the case on June 18 in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants.
The exchange’s latest update, published Aug. 7, says about $48.4 million of stolen assets has been recovered, while more than $30.5 million remains frozen across more than 28 exchanges and custodians. That puts roughly $78.9 million in the recovered or frozen category, although the frozen portion has not yet been returned to Bybit.
U.S. court gives Bybit faster access to records
Court records show Judge John D. Bates granted expedited discovery on June 19, one day after Bybit filed its complaint under seal. The measure allows the exchange to seek account identities, balances and transaction histories from platforms with U.S. operations that may hold information tied to the stolen funds. The court also issued a temporary restraining order that day to stop certain traceable assets from being moved.
The restraining order was renewed on July 16. On July 30, Bates granted Bybit’s request for a preliminary injunction in part, preserving identified assets while the case continues. Bybit said the court found that “Bybit has demonstrated a likelihood of success on the merits.” That is an interim legal finding, not a final ruling that all allegations in the complaint have been proved.
Most stolen assets are now harder to trace
Bybit said in its June filing that 90.2% of the stolen assets had become untraceable after moving through mixers, cross-chain bridges and over-the-counter dealers. Only 9.8% remained connected to identifiable wallets at that point, while about 5.3% of the original theft, roughly $75.5 million, had been frozen or recovered.
Those figures do not establish that the remaining assets are permanently unrecoverable. “Untraceable” describes Bybit’s stated ability to follow the transaction trail at the time of filing. The new discovery authority could provide offchain records, including customer identities and account histories, that blockchain analysis alone cannot supply. Meanwhile, Bybit’s newer Aug. 7 figures separate $48.4 million already recovered from more than $30.5 million still frozen.
The decline in traceability has been steep. CEO Ben Zhou said in March 2025 that 88.87% of the stolen funds could still be traced, while 7.59% had gone dark and 3.54% had been frozen. The June 2026 filing shows how much more difficult following the assets became as laundering continued.
FBI attribution and Safe findings support the case
The theft occurred on Feb. 21, 2025. Five days later, the FBI formally attributed the attack to North Korea and said it tracks the activity as “TraderTraitor.” The agency said the attackers converted some stolen assets into Bitcoin and other cryptocurrencies and dispersed them across thousands of addresses on multiple blockchains.
The FBI also urged exchanges, bridges, blockchain analytics firms, DeFi services and other virtual asset providers to block transactions linked to addresses it identified in the laundering operation. Bybit says its civil proceeding remains separate from ongoing U.S. criminal investigations and that it continues sharing blockchain intelligence with the agency.
The attack was also traced to compromised infrastructure connected to Safe Wallet. As previously reported, forensic investigators found that a compromised Safe developer machine enabled the attackers to propose a disguised malicious transaction. Safe later said its review found no vulnerability in its smart contracts or source code and that it rebuilt infrastructure and rotated credentials after the breach.
Bybit launched a bounty program shortly after the hack to encourage investigators and platforms to help identify and freeze stolen funds. The federal lawsuit adds discovery and injunction tools to that earlier recovery strategy, giving the exchange another route to identify intermediaries connected to assets within reach of U.S. legal process.
Bybit must turn asset freezes into recoveries
The complaint seeks return of the stolen assets, about $1.5 billion in compensatory damages, punitive damages and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, according to the unsealed court records. Those requests remain claims for relief. The court has not entered a final judgment awarding those damages against North Korea, the Lazarus Group or the unidentified defendants.
The next stage centers on discovery and enforcement. Bybit can seek records from relevant service providers while the preliminary injunction restricts movement of certain identified assets. Further recovery will depend on whether the exchange can connect wallets to identifiable account holders or intermediaries and reach assets held by entities subject to enforceable court orders.
Bybit also credited international cooperation for earlier progress, citing German authorities’ action against eXch and the German-Swiss disruption of Cryptomixer.io, services the exchange said were used to move illicit proceeds. Those actions are separate from the Washington case but form part of a broader effort to close laundering routes used after the theft.
For now, the U.S. court orders give Bybit a stronger legal route to pursue assets that remain within reach, but they do not guarantee additional recovery. The next material developments will include responses to discovery requests, attempts to identify the John Doe defendants, possible additional asset restraint orders and later rulings on the exchange’s claims. Bybit said it intends to seek further judicial relief as the litigation proceeds.