NewsCryptoBybit Secures US Court Backing to Trace Funds From $1.5B North Korea-Linked Hack

Bybit Secures US Court Backing to Trace Funds From $1.5B North Korea-Linked Hack

Author: CoinLineup·

Key Takeaways

  • Bybit obtained US court backing to trace approximately $1.5 billion in stolen funds from a February 2025 hack that the FBI officially attributed to North Korea.
  • The exchange filed a lawsuit naming both North Korea and the Lazarus Group as responsible parties, advancing its earlier legal action over the breach.
  • The Lazarus Group has been linked by US authorities and UN monitors to numerous major cryptocurrency thefts, with the UN reporting that North Korea uses stolen digital assets to help fund its weapons programs.
  • Court-authorised tracing is considered essential because stolen cryptocurrency is frequently routed through mixers and cross-chain bridges designed to conceal its origin.
  • The court backing represents a procedural step rather than confirmed recovery, as seizing and returning stolen funds remains the most challenging phase of the process.
Bybit Secures US Court Backing to Trace Funds From $1.5B North Korea-Linked Hack

Bybit has obtained US court backing to trace funds connected to the approximately $1.5 billion hack of the exchange attributed to North Korea, providing a formal legal foundation for pursuing the stolen assets. The February 2025 breach, one of the largest cryptocurrency thefts on record, underscores the growing scale of state-linked cyber operations targeting digital asset platforms. The court-supported initiative strengthens the exchange's recovery and investigative efforts as the case advances through the US legal system.

US Court Backing Establishes Legal Framework

The court backing grants Bybit a legal basis to monitor the movement of stolen assets and pursue them through judicial proceedings, rather than depending on informal tracing methods alone. This supports the exchange's broader case against North Korea and the actors it holds responsible for the breach.

Bybit filed its claims in a US court in an action naming the Democratic People's Republic of Korea, according to the case docket. The exchange has also detailed its legal strategy and asset-freezing efforts in its own account of the case.

Bybit had previously moved to sue North Korea and the Lazarus Group over the hack, and the court backing advances that same effort. The Lazarus Group, a cyber unit tied to North Korea's intelligence apparatus, has been linked by US authorities and UN monitors to a string of major cryptocurrency heists over several years. A UN panel of experts has reported that North Korea has used stolen cryptocurrency to help fund its weapons programs, placing cases like Bybit's at the intersection of cybercrime and international security.

Tracing Stolen Funds Central to the Case

Tracing the assets remains critical even when immediate recovery is uncertain. Following the funds on-chain enables investigators to map their movement, which can subsequently support freezing orders or claims against parties who received the assets. Stolen cryptocurrency is frequently moved through mixers and cross-chain bridges designed to obscure its origin, making court-authorised tracing a key tool for keeping pace with laundering attempts.

The reported $1.5 billion scale of the theft significantly raises the stakes for this monitoring. The US government attributed the breach to North Korea in an FBI alert on the incident, which reinforces the enforcement interest in tracking the outflow.

Tracing, attribution, and recovery are distinct phases. Following the funds reveals their path; attribution establishes responsibility; and recovery—the most challenging step—depends on reaching assets that can actually be seized. Thefts at this scale have demonstrated why recovery remains so difficult even when the trail is visible.

Implications for Exchanges and Regulatory Oversight

A US court-backed tracing effort signals a firmer legal pathway for large-scale cryptocurrency investigations. If the approach succeeds, it could offer other exchanges a template for pursuing stolen funds through the courts rather than relying solely on voluntary cooperation.

A breach of this magnitude also carries significant implications for exchange risk management and incident response, testing how rapidly platforms can identify, freeze, and pursue assets following a major intrusion. The North Korea connection places the case within a broader context of international concern, including calls from G7 leaders for joint action on North Korea crypto theft.

At this stage, the court backing represents a procedural step rather than a confirmed recovery. Any declaration of success would depend on funds actually being returned, which the available record does not yet establish.