#Safe Wallet Contagion Risk#Hack Fund Tracing
US Court Grants Bybit Expedited Discovery to Trace $1.5B North Korea Hack Funds
WooFun2026-08-08 12:11
Key Takeaways
A US federal judge approved Bybit’s request for expedited discovery in its lawsuit against North Korea-linked hackers. This legal move aims to identify intermediaries and recover traceable assets from the $1.5 billion theft, marking a strategic shift fr
Woofun AI reports that a federal judge authorized expedited discovery for Bybit, enabling the exchange to pursue traceable assets stolen in the $1.5 billion North Korea-linked hack. The order supports Bybit's lawsuit filed against North Korea, the Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants, shifting focus from state-level judgments to intermediary identification.
The litigation timeline accelerated rapidly after Bybit filed the complaint under seal on June 18. A federal judge granted the expedited discovery request on June 19, allowing Bybit to seek account-holder identities, balances, and transaction histories from platforms indicating cooperation. A temporary restraining order issued on June 19 prevented asset transfers by unidentified defendants, with the court renewing the order on July 16 and partially granting a preliminary injunction on July 30. Certain exhibits and records remain sealed.
Woofun AI data shows that as of the June 18 filing, 90.2% of the stolen assets became untraceable after passing through mixers, cross-chain bridges, and over-the-counter dealers. The remaining 9.8% was traced to identifiable wallets, including 5.3% of the total, approximately $75.5 million, which had been frozen or recovered. These figures represent a significant decline from more than a year ago, when Bybit CEO Ben Zhou stated that 68.57% of the funds remained traceable.
The incident originated on Feb. 21, 2025, when attackers compromised Safe Wallet's infrastructure. Forensic investigators determined that compromised credentials belonging to a Safe developer enabled the injection of malicious code into cloud infrastructure. The FBI attributed the theft to North Korea on Feb. 26, 2025, linking the breach to state-sponsored cyber operations.
Bybit seeks the return of stolen assets, approximately $1.5 billion in compensatory damages, punitive damages, and treble damages under the US Racketeer Influenced and Corrupt Organizations Act. This marks a strategic pivot toward leveraging civil litigation to recover losses from complex, multi-jurisdictional cybercrime networks.
Comments
No comments yet.