NewsCryptoBybit Secures U.S. Court Orders to Trace and Freeze Assets Tied to $1.5 Billion Hack

Bybit Secures U.S. Court Orders to Trace and Freeze Assets Tied to $1.5 Billion Hack

Author: CoinLineup·

Key Takeaways

  • The FBI attributed the February 2025 theft of approximately $1.5 billion in Ethereum from Bybit's cold wallet to North Korea's Lazarus Group under its "TraderTraitor" designation.
  • Bybit filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group in the U.S. District Court for the District of Columbia on June 18, 2026.
  • U.S. court orders granted Bybit expedited discovery, a temporary restraining order renewed on July 16, and a partial preliminary injunction on July 30, 2026, to trace and freeze stolen assets held by unidentified defendants.
  • As of the June 18, 2026 filing, only approximately 5.3% of the stolen assets—about $75.5 million—had been frozen or recovered, while 90.2% had become untraceable.
  • The case establishes a civil-litigation template for crypto exchanges pursuing recovery from state-linked cybercrime, operating in parallel with FBI criminal investigations initiated after attribution.
Bybit Secures U.S. Court Orders to Trace and Freeze Assets Tied to $1.5 Billion Hack

Bybit has secured U.S. court orders authorizing it to trace and freeze assets connected to the approximately $1.5 billion hack of its exchange in 2025, marking a major escalation in a landmark civil recovery effort targeting North Korea and the Lazarus Group.

The Bybit Hack Case

On August 7, 2026, Bybit announced that it had filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, according to a press statement from the exchange.

The FBI stated on February 26, 2025, that North Korea was responsible for the theft of approximately $1.5 billion in virtual assets from Bybit on or around February 21, 2025. The bureau attributed the activity under the designation "TraderTraitor" in an official alert. The heist — which targeted Ethereum held in Bybit's cold wallet — ranks among the largest cryptocurrency thefts on record, surpassing prior industry-defining breaches such as the 2022 Ronin Network attack, also attributed to Lazarus.

The move into the U.S. legal system transforms a security breach into one of the largest crypto asset-recovery cases to date, building on Bybit's earlier decision to sue North Korea and the Lazarus Group over the theft. Suing a nation-state in a U.S. civil court is rare but not unprecedented in the crypto domain; Bybit's case follows a pattern in which victims of state-linked cybercrime have turned to civil litigation after attribution, leveraging judicial tools such as expedited discovery to compensate for the limits of criminal enforcement against sovereign actors.

Scope of the U.S. Court Orders

According to court records summarized by Cointelegraph, Bybit filed the lawsuit under seal on June 18, 2026. The court granted expedited discovery the following day, enabling the exchange to trace the movement of allegedly stolen funds across multiple platforms.

The same court reporting indicates that Bybit obtained a temporary restraining order on June 19, 2026, which was renewed on July 16, 2026. On July 30, 2026, the court issued a partial preliminary injunction freezing identified assets held by unidentified John Doe defendants while the case proceeds.

These legal mechanisms are significant in cross-platform crypto cases, where stolen funds can move rapidly through numerous venues. Expedited discovery compels exchanges and custodians to disclose wallet links, while freeze orders preserve assets that might otherwise be withdrawn during an extended legal battle.

"Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable." — Ben Zhou, Bybit CEO, in Bybit's statement.

Implications for Crypto Security and Enforcement

A court-backed freeze in a case of this magnitude signals stronger legal coordination around digital-asset recovery, operating in parallel with criminal investigations the FBI initiated following its TraderTraitor attribution. The case also draws renewed attention to the role of decentralized finance infrastructure — including cross-chain bridges and privacy tools — that state-sponsored actors have repeatedly exploited to obscure fund flows. U.N. sanctions monitors have documented that North Korea has channeled billions in stolen cryptocurrency toward its weapons programs, making civil recovery efforts not just a commercial concern but a component of broader counterproliferation efforts.

The recovery figures, however, underscore the challenges. Bybit reported that approximately US$48.4 million has been recovered and over US$30.5 million frozen across more than 28 exchanges and custodians — a combined figure representing only a fraction of the total loss.

Court filings further illustrate the difficulty: as of the June 18, 2026 filing, 90.2% of the stolen assets had become untraceable, 9.8% remained tied to identifiable wallets, and 5.3% of the total — approximately $75.5 million — had been frozen or recovered.

This breakdown demonstrates why recovery in billion-dollar crypto hacks remains so difficult, even with judicial support: most funds are laundered before legal orders can take effect, and a freeze cannot restore assets already routed through mixers and untraceable wallets.

For exchanges, the case establishes a template for integrating incident response with civil litigation, while placing renewed scrutiny on compliance and transaction monitoring at the venues through which stolen funds pass. While recovery is not guaranteed, the sealed-case timeline demonstrates how swiftly civil remedies can be deployed following a major breach. How effectively Bybit's legal strategy translates into measurable recoveries — and whether other hacked exchanges adopt a similar playbook — will be closely watched across the digital-asset industry.