Bybit is using U.S. federal court to squeeze a North Korea-linked hacking network from another angle: records, freezes, and legal pressure aimed at recovering money from its February 2025 $1.5 billion theft.
- Judge John D. Bates granted expedited discovery and partial injunction relief
- The FBI attributed the hack to North Korea’s “TraderTraitor” campaign
- More than $30.5 million remains frozen across 28-plus exchanges and custodians
- Frozen is not recovered; the money is still not back in Bybit’s hands
Bybit filed suit on June 18 in the U.S. District Court for the District of Columbia against North Korea, the Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants. Judge John D. Bates moved fast, granting expedited discovery on June 19 and issuing a temporary restraining order the same day. That TRO was renewed on July 16, and on July 30 Bates granted Bybit wins U.S. court support to trace $1.5B hack funds in part.
Bybit said the court found that it had “demonstrated a likelihood of success on the merits.” That sounds encouraging, and it is, but keep the legal weight in perspective. A preliminary injunction is a temporary order, not a final ruling. It does not mean Bybit has won the case or that the full $1.5 billion will be clawed back.
What it does mean is that the court is willing to help preserve assets and push for records while the case moves forward. In crypto theft recovery, that matters a lot. Once stolen funds start bouncing through mixers, bridges, OTC channels, and custodians, the chain of custody gets ugly fast.
For readers new to the jargon: expedited discovery lets a party gather evidence faster than normal, often from exchanges or custodians with records that live off-chain. A temporary restraining order is an emergency stop sign. A preliminary injunction is a longer-lasting temporary order meant to keep certain assets from moving while the court sorts things out.
That legal machinery is the real story here. Public blockchain data can show where funds moved, but it usually cannot identify the person or service behind a wallet. Off-chain records, like KYC data, IP logs, account history, and withdrawal records, are what can turn a suspicious address into something a court can actually use.
Bybit’s Aug. 7 update said about $48.4 million of stolen assets had been recovered and more than $30.5 million remained frozen across more than 28 exchanges and custodians. Combined, that comes to roughly $78.9 million. That is progress, but it is still a tiny slice of the original hit.
And frozen is not the same as recovered. Frozen funds are trapped. Recovered funds are back. That distinction matters because a wallet held by the collar is not the same thing as cash in hand.
Bybit also said that in its June filing, 90.2% of the stolen assets had become untraceable. At that point, 9.8% remained tied to identifiable wallets, and about 5.3% of the original theft, roughly $75.5 million, had been frozen or recovered. Those numbers come from different snapshots in time, so they should not be treated like one neat ledger. In a live theft investigation, traceability can change by the hour.
Bybit CEO Ben Zhou said in March 2025 that 88.87% of the stolen funds could still be traced, 7.59% had gone dark, and 3.54% had been frozen. Again, that is a different date and likely a different tracing methodology. The useful takeaway is not the decimal-point theater. It is the brutal fact that stolen crypto gets harder to track the longer criminals have to move it around.
The FBI’s position is blunt. Five days after the theft, it attributed the attack to North Korea and called the activity North Korea Responsible for $1.5 Billion Bybit Hack. The bureau said the stolen assets were converted into Bitcoin and other cryptocurrencies and dispersed across thousands of addresses on multiple blockchains. It urged exchanges, bridges, blockchain analytics firms, DeFi services, and other virtual asset providers to block transactions linked to the addresses it identified.
That is the ugly but familiar pattern. Criminals do not need to break Bitcoin itself to steal billions. They need to compromise the people, systems, and interfaces around it, then move quickly enough that the trail becomes a mess before anyone can freeze it.
The Safe Wallet angle shows how fragile that surrounding layer can be. Lazarus Group's Attack on Safe{Wallet}: Understanding the forensic work points to a compromised Safe developer workstation and front-end manipulation, not a proven vulnerability in Safe’s smart contracts or source code. That is an important distinction. A smart-contract flaw is one kind of failure. A compromised development machine or interface layer is another, and often a more embarrassing one.
Crypto users love to talk as if the blockchain is the whole system. It is not. The chain may keep perfect records while the front end lies, the signing flow is poisoned, or a trusted workstation is already owned. The ledger is honest. The humans and tools around it are where the rot usually starts.
The broader lesson is not that crypto is broken. It is that security in this space has to cover much more than cold storage slogans and smart-contract audits. Exchanges, custodians, wallets, bridges, developer systems, and sign-off workflows all sit in the blast radius when attackers go after the weak link. If the industry wants serious trust, it has to stop pretending the chain alone can carry that load.
Bybit has also leaned on cooperation outside the courtroom. The company credited German authorities for action against eXch and a German-Swiss disruption of Cryptomixer.io, both separate from the Washington case but useful in shutting down laundering routes. That is how recovery tends to work in practice: tracing, subpoenas, freezes, and cross-border enforcement, not some magical blockchain bounty hunt where the villain politely returns the loot.
What does the court action actually change?
It gives Bybit more tools to gather evidence and preserve assets tied to the hack. That can help identify chokepoints and expose off-chain records, but it does not guarantee a final judgment or full repayment.
How much money has been recovered so far?
Bybit said on Aug. 7 that about $48.4 million had been recovered and more than $30.5 million remained frozen. The frozen portion is still not back in Bybit’s possession.
Why do the recovery numbers keep changing?
Because the figures come from different dates and different tracing snapshots. In a case this large, what is traceable, frozen, or already laundered can shift quickly as funds move across chains and through intermediaries.
What is “TraderTraitor”?
That is the FBI’s label for the North Korea-linked activity it says was behind the Bybit theft. The bureau says the stolen assets were moved across thousands of addresses on multiple blockchains.
Did Safe’s smart contracts get hacked?
Based on the material cited here, the more careful reading is no. Sygnia’s findings point to a compromised Safe developer workstation and front-end manipulation, not a proven flaw in Safe’s smart contracts or source code.
Can the remaining stolen funds still be traced?
Some of them may be, but the trail gets weaker as funds move through mixers, bridges, OTC routes, and custodians. At that point, tracing becomes lower-confidence and far more dependent on off-chain records.
Why does North Korea keep showing up in these hacks?
Because crypto is a useful revenue source and sanctions workaround for a regime that needs hard currency. The FBI says the Bybit theft fits that pattern.
For anyone still pretending crypto theft is just a matter of “hacking the blockchain, ” this case says otherwise. The chain is only one layer. The real fight is at the chokepoints: custodians, compliance teams, KYC records, IP logs, and the courts that can force those records into daylight.
That is why the industry keeps watching cases like North Korea Responsible for $1.5 Billion Bybit Hack and the forensic reporting around the attack so closely: they show how the laundering playbook works in practice, not in some fluffy conference keynote fantasy.
And if you want the blunt version of what happened after the theft, Bybit’s own post-mortem on North Korea’s Lazarus Group Orchestrates Record $1.5B Bybit hack makes it clear that this was not some random opportunistic smash-and-grab. It was disciplined, state-backed, and methodical.
The laundering phase was just as brutal, as shown in Lazarus Group’s $1.4B Bybit Hack: 62, 200 ETH Moved, Full cleanup moving at a pace that would make most compliance teams break into a cold sweat. When billions move that fast, time is the enemy, and bureaucracy is not exactly known for sprinting.
There is also a wider lesson for developers and security teams: North Korea’s Lazarus Group Targets Crypto Devs via npm and other supply-chain tricks because the weakest link is often not the chain itself, but the software pipeline feeding it.
For a broader look at why stolen crypto is such a pain to recover once it is dispersed, This $1.5 billion hack is exposing just how 'irreversible stolen crypto really is is a reminder that “irreversible” is usually a feature until you are the one trying to undo a theft. Then it suddenly feels a lot less elegant.
Finally, Sygnia’s report on the attack and the FBI’s own attribution both fit into the same grim truth: the Lazarus Group’s attack on Safe{Wallet} was not about defeating Bitcoin or Ethereum at the protocol level. It was about exploiting human systems, sloppy operational security, and the messy reality of how crypto is actually used.
Further reading
For more on the supply-chain side of this mess, start with this one: