Expedited discovery enables the exchange to obtain account identities, balances and transaction records from platforms operating in the United States.

US court records unsealed Thursday reveal that a federal judge approved crypto exchange Bybit’s effort to trace assets stolen in the $1.5 billion North Korea-linked hack by granting the company expedited discovery.

According to court records, Bybit filed the lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. A federal court granted the exchange’s request for expedited discovery the following day, on June 19.

The discovery order gives Bybit a practical way to identify alleged intermediaries and pursue a traceable portion of the stolen funds, instead of depending solely on a judgment against North Korea.

In its complaint, Bybit alleged that some traceable assets moved through exchanges operating in the US or using US-based infrastructure. The company requested account-holder identities, balances and transaction records, noting that certain platforms had indicated their willingness to cooperate once a court order was issued.

Bybit Says 90% of Stolen Funds Are Now Untraceable#

Bybit also secured a temporary restraining order on June 19 that barred the unidentified defendants from transferring certain traceable assets. The court extended the order on July 16 and partially approved Bybit’s request for a preliminary injunction on July 30. Some exhibits and additional court records remain under seal.

Stay in the loop

Get crypto news before the market moves

Join thousands of investors who read our daily briefing.

No spam. Unsubscribe anytime.

As of the June 18 filing, Bybit reported that 90.2% of the stolen assets had become difficult to trace after moving through mixers, cross-chain bridges and over-the-counter dealers. The remaining 9.8% was linked to identifiable wallets, including 5.3% of the total, worth roughly $75.5 million, which had been frozen or recovered.

The figures represent a significant decline from more than a year earlier, when Bybit CEO Ben Zhou said that 68.57% of the stolen funds remained traceable.

The hack occurred on Feb. 21, 2025, after attackers compromised Safe Wallet’s infrastructure. Forensic investigators said the attackers used compromised credentials belonging to a Safe developer to inject malicious code into the company’s cloud infrastructure. On Feb. 26, 2025, the FBI attributed the theft to North Korea.

The lawsuit indicates that Bybit is seeking the recovery of the stolen assets, around $1.5 billion in compensatory damages, punitive damages and treble damages under the US Racketeer Influenced and Corrupt Organizations Act.