NewsCryptoUS Court Grants Bybit Authority to Trace $1.5B in Stolen Funds Linked to North Korea

US Court Grants Bybit Authority to Trace $1.5B in Stolen Funds Linked to North Korea

Author: Tron Weekly·

Key Takeaways

  • A US court has authorized Bybit to freeze assets and serve subpoenas on other cryptocurrency exchanges to investigate wallet clusters linked to the $1.5 billion theft.
  • Approximately 90% of the stolen funds have already been laundered through mixing services and cross-chain swaps, making them largely untraceable.
  • Bybit has filed a lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group over the February 2025 cyberattack.
  • United Nations and US Treasury assessments have documented that North Korea systematically uses stolen cryptocurrency to fund its nuclear and ballistic missile programs.
  • The incident is driving regulators and exchanges toward stricter KYC requirements, enhanced proof-of-reserves audits, and greater inter-exchange cooperation.
US Court Grants Bybit Authority to Trace $1.5B in Stolen Funds Linked to North Korea

Bybit has secured permission from a US court to freeze assets connected to a $1.5 billion cyberattack attributed to hackers affiliated with North Korea. The court order authorizes the Dubai-registered cryptocurrency exchange to pursue asset recovery across additional jurisdictions. However, on-chain data indicates that approximately 90% of the stolen funds have already been laundered or obfuscated, rendering them largely untraceable. The February 2025 incident ranks among the largest cryptocurrency thefts on record, underscoring the scale of the challenge facing both Bybit and the broader industry.

Court Backs Bybit's Hunt for $1.5B in Hacked Funds

In February 2025, Bybit suffered a cyberattack that the company estimates resulted in the loss of $1.5 billion in crypto assets. US authorities have now granted Bybit approval to serve subpoenas requesting information about wallet clusters from other cryptocurrency exchanges and service providers.

BYBIT SUED NORTH KOREA! Bybit Technology Limited v. Democratic People's Republic of Korea et al., filed under seal June 18, 2026 IS NOW PUBLIC. Here's your breakdown of what's going on. Plaintiffs name the DPRK, its Reconnaissance General Bureau, the Lazarus Group, and 20 John… pic.twitter.com/uMH37LoyCo — Ariel Givner (@GivnerAriel) August 8, 2026

The key parties involved include Bybit, blockchain investigators, the US judiciary, and entities tied to the hackers' primary target country. The attackers have been linked to the North Korea–associated Lazarus Group, which US agencies have previously identified as responsible for similar cyber intrusions, including the $620 million Ronin Bridge theft in 2022. United Nations panels and US Treasury assessments have documented that North Korea has systematically used stolen cryptocurrency to fund its nuclear and ballistic missile programs, making the Bybit case part of a recurring pattern of state-aligned financial crime rather than an isolated incident.

Laundering Outpaces Tracing

With approximately 90% of the stolen funds having been dispersed through various mixing services and cross-chain swaps, the likelihood of successfully tracing them is very low. This significantly complicates the ability of centralized platforms such as exchanges to implement the real-time monitoring measures necessary to detect and intercept illicit flows.

Regulators have already begun leveraging this incident to push for stricter regulations around travel rules and wallet screening in stablecoins and custodial services. These measures stand to affect investors, institutions, and developers working across Ethereum, Solana, and Bitcoin networks.

State-Sponsored Hack Wave Drives Tighter KYC and Exchange Cooperation

The attack exemplifies a broader wave of state-sponsored cybercriminal activity that unfolded throughout 2024 and 2025, targeting cryptocurrency infrastructure. This trend has been documented by Chainalysis and TRM Labs, both of which reported record levels of North Korea-linked crypto theft during this period. As a result, KYC regulations are expected to become more stringent.

Additionally, proof-of-reserves audits are anticipated to be enhanced. Beyond law enforcement efforts, exchanges are also expected to deepen mutual cooperation in responding to such threats.