NewsCryptoBybit Wins U.S. Court Backing to Trace $1.5 Billion Hack as Most Stolen Funds Become Untraceable

Bybit Wins U.S. Court Backing to Trace $1.5 Billion Hack as Most Stolen Funds Become Untraceable

Author: Hokanews·

Key Takeaways

  • The FBI formally attributed the Bybit theft to North Korean actors operating under what it calls the TraderTraitor campaign, with security researchers linking the attack to the Lazarus Group.
  • Approximately 90% of the $1.5 billion in stolen cryptocurrency has become untraceable after being rapidly converted and dispersed across thousands of addresses and multiple blockchain networks.
  • The U.S. court order enables Bybit to seek account records and transaction data from American companies, potentially helping investigators identify stolen funds that remain recoverable.
  • The attackers compromised a single Ethereum cold wallet by exploiting the signing process surrounding a Safe multisignature wallet during what should have been a routine transfer.
  • Bybit CEO Ben Zhou publicly confirmed that customer assets remained fully backed and the exchange stayed solvent following the incident, calming concerns about a potential liquidity crisis.
Bybit Wins U.S. Court Backing to Trace $1.5 Billion Hack as Most Stolen Funds Become Untraceable

Bybit Wins U.S. Court Backing to Trace $1.5 Billion Hack as Most Stolen Funds Become Untraceable

Bybit has secured support from a U.S. court to pursue information that could help trace cryptocurrency stolen in the exchange's $1.5 billion hack, giving the company another legal tool in its effort to recover assets linked to the massive cyberattack.

The development comes more than a year after the February 2025 attack, which resulted in one of the largest cryptocurrency thefts ever recorded. The scale of the Bybit theft surpassed previous major industry incidents, including the 2022 Ronin Network hack linked to Axie Infinity, in which approximately $625 million was stolen, and the 2021 Poly Network exploit, which involved roughly $611 million before the funds were ultimately returned. According to the latest reports, approximately 90% of the stolen funds have now become difficult or impossible to trace after being moved through a complex network of blockchain addresses and transactions.

The court action could allow Bybit to seek information from U.S.-based platforms that may have interacted with the stolen assets, potentially providing investigators with additional clues about where some of the funds moved and whether any portion can still be frozen or recovered.

The case highlights both the transparency and the limitations of blockchain technology. While cryptocurrency transactions are permanently recorded on public ledgers, sophisticated laundering strategies can make it extremely difficult to connect blockchain addresses to real-world individuals or organizations.

The Federal Bureau of Investigation previously attributed the Bybit theft to North Korea, identifying the activity as part of what it calls the TraderTraitor campaign. The agency said the attackers quickly converted and dispersed the stolen assets across thousands of addresses and multiple blockchains.

Source: X Post

Bybit's $1.5 Billion Hack Remains a Major Crypto Security Case

The February 2025 Bybit attack shocked the cryptocurrency industry because of the sheer size of the theft. Bybit said a single Ethereum cold wallet was compromised during what should have been a routine transfer. The exchange later detailed that approximately $1.46 billion worth of assets were taken from the wallet, including ETH and several Ethereum-based liquid staking tokens.

The stolen assets were rapidly moved away from the original addresses — a speed that became one of the defining characteristics of the incident. Investigators tracking the stolen funds faced a constantly changing network of wallets as the attackers moved assets between addresses and blockchain networks. Once cryptocurrency is transferred, the transaction itself remains visible on-chain, but identifying who controls a particular address presents a separate challenge.

U.S. Court Order Opens Another Route for Investigators

The latest court development is significant because blockchain analysis alone cannot always provide enough information to identify the people behind a wallet. A court-backed legal process can potentially give Bybit access to information held by companies operating within the United States, including account records, transaction histories, or other data that may help investigators connect blockchain addresses with specific services or entities.

The goal is not necessarily to recover the entire $1.5 billion. Instead, investigators are trying to identify whatever portion of the stolen funds may still be accessible. Even a relatively small recovery could provide valuable evidence about the laundering network and the entities that interacted with the stolen assets.

Around 90% of the Funds Are Reportedly Untraceable

The biggest obstacle facing Bybit is the speed at which the stolen assets were moved. Recent reports indicate that roughly 90% of the stolen cryptocurrency has become untraceable. That does not necessarily mean the assets have disappeared from the blockchain — rather, investigators can no longer reliably determine where the funds are being controlled or how they are connected to the original theft.

The assets may have passed through numerous wallets, decentralized services, cross-chain bridges, and other mechanisms designed to make transaction histories harder to follow. The U.S. Treasury Department's Office of Foreign Assets Control previously sanctioned cryptocurrency mixing service Tornado Cash in 2022 for its role in laundering illicit proceeds, including funds stolen by North Korean actors. Such tools create a significant difference between seeing a transaction and understanding it. Blockchain records can show that funds moved, but they do not automatically reveal who controls every address involved.

North Korea and the Lazarus Group Connection

The U.S. government has formally attributed the Bybit theft to North Korea. In February 2025, the FBI said North Korean actors were responsible for the theft of approximately $1.5 billion in virtual assets from Bybit. The agency referred to the activity as TraderTraitor and warned that the stolen assets were being rapidly converted and dispersed. The FBI also said the attackers were expected to continue laundering the assets and eventually convert some of them into fiat currency.

Security researchers and blockchain investigators have linked the attack to the Lazarus Group, a hacking operation widely associated with North Korea. Lazarus has been linked to numerous cryptocurrency thefts and other cyber operations over the years. Bybit itself previously described the stolen funds as connected to activity attributed to Lazarus Group and launched initiatives aimed at tracking and recovering the assets.

United Nations panel reports have estimated that North Korea has generated billions of dollars in revenue from cryptocurrency theft over several years, with the funds reportedly used to support the country's weapons programs. The Bybit incident demonstrated the scale that such operations can reach. A theft exceeding $1 billion is not simply a cryptocurrency security incident — it has implications for international sanctions, cybercrime investigations, and national security.

Why Tracking Crypto Remains Difficult

Cryptocurrency is often described as transparent because transactions are publicly recorded. That description is technically correct but incomplete. On a public blockchain, investigators can see transactions between addresses, but the challenge is determining who owns those addresses.

If stolen assets remain in one wallet, investigators may be able to monitor them. The situation becomes much more complicated when funds are divided across hundreds or thousands of addresses, and complexity increases further when assets move between different blockchain networks. Investigators must then reconstruct multiple transaction histories and determine whether seemingly unrelated addresses are connected.

The FBI said the stolen assets were converted into Bitcoin and other virtual assets and dispersed across multiple blockchains. Cross-chain activity can make tracing more difficult because investigators must follow funds through different networks with different transaction structures. Cryptocurrency mixers and other privacy-enhancing services can also make investigations more challenging, as these systems are designed to break obvious links between deposits and withdrawals.

Blockchain analytics firms such as Chainalysis, TRM Labs, and Elliptic work alongside law enforcement agencies to trace illicit cryptocurrency flows, but sophisticated actors continue to adapt. The faster funds are dispersed, the harder it becomes for exchanges and investigators to freeze them.

The First Hours After a Hack Are Critical

One of the most important lessons from the Bybit incident is the importance of speed. When a major exchange is hacked, investigators immediately begin identifying the attacker's addresses. Exchanges and blockchain infrastructure companies can then attempt to flag or freeze transactions connected to those addresses. The window for intervention can be extremely short — once stolen assets enter a large network of addresses and services, recovering them becomes significantly more difficult.

Bybit Says Customer Funds Remained Backed

The size of the hack raised immediate concerns about Bybit's ability to remain solvent. The exchange's leadership said shortly after the incident that customer assets remained fully backed and that the company could absorb the loss. Bybit's own timeline states that its CEO, Ben Zhou, publicly reassured customers that the exchange remained solvent even if the stolen funds could not be recovered. That response helped calm concerns about a potential liquidity crisis. The incident nevertheless demonstrated how a single compromised wallet can create enormous financial exposure.

Cold Wallets and Multisignature Security Face New Challenges

The attack raised questions about the security assumptions surrounding cold storage. Cold wallets are generally considered safer because private keys are kept away from online systems. But the Bybit incident demonstrated that the security of the signing process and the surrounding infrastructure is just as important as the physical storage of the keys. According to Bybit's account, attackers exploited the process surrounding a Safe multisignature wallet during a routine transaction.

Many large crypto companies use multisignature systems to prevent a single individual from controlling funds, requiring multiple approvals before a transaction can be executed. However, attackers do not necessarily need to steal every private key — they may instead attempt to compromise the interface, signing process, or personnel involved in approving transactions. Security teams must therefore protect not only private keys but also the systems surrounding them.

The Legal Battle Could Take Time

The court-backed tracing effort does not guarantee that stolen funds will be recovered. Legal proceedings can take time, some platforms may not hold useful information, and other assets may already have moved outside jurisdictions where U.S. courts can easily compel cooperation. There is also the possibility that some funds have already been converted into other assets or fiat currencies.

If investigators identify stolen cryptocurrency held by a regulated platform, they may be able to freeze the assets. Recovery can then depend on additional legal proceedings. Frozen assets are not automatically returned to the victim — courts and law enforcement authorities may need to establish ownership and determine how the assets should be handled, a process that can take considerably longer than simply identifying a blockchain address.

North Korea's Broader Crypto Theft Campaign

The Bybit hack fits into a broader pattern of cryptocurrency theft attributed to North Korean actors. U.S. authorities have repeatedly warned that North Korea uses cybercrime and cryptocurrency theft to generate revenue. The FBI has encouraged private-sector companies, including exchanges, blockchain infrastructure providers, and analytics firms, to identify and block transactions connected to North Korean laundering activity. The scale of the activity has turned cryptocurrency theft into an international security concern, with successive U.S. administrations imposing sanctions on individuals and entities linked to North Korean cyber operations.

The Importance of Inter-Exchange Cooperation

The fight against large-scale cryptocurrency theft increasingly requires cooperation between exchanges. A stolen asset rarely stays on the platform where it was taken — it can move to another exchange, a decentralized protocol, or a different blockchain. If companies share intelligence quickly, they may have a better chance of freezing funds before they disappear into a larger laundering network. The Bybit case demonstrated how important that cooperation can be.

Blockchain Transparency Is Both a Strength and a Weakness

There is an important paradox at the center of cryptocurrency security. Blockchains make transactions visible, but visibility does not necessarily equal accountability. Investigators can see where funds move without knowing who controls every address. At the same time, that permanent transaction history can provide valuable evidence long after an attack occurs. A wallet that appears inactive today could potentially become relevant years later if investigators identify its owner or connect it to another known address.

The fact that approximately 90% of the stolen assets are reportedly untraceable does not necessarily mean recovery efforts are finished. Blockchain addresses do not expire, and transactions remain recorded. If an exchange, payment provider, or other regulated business eventually identifies one of the stolen addresses, authorities could potentially intervene. New analytical techniques may also allow investigators to connect transactions that previously appeared unrelated, meaning the recovery process could continue for years.

What the Court Development Means for Bybit

For Bybit, the U.S. court's backing represents an opportunity to expand the investigation beyond blockchain analysis. Access to information from U.S.-based companies could potentially help identify accounts and transaction pathways that are difficult to establish from public blockchain records alone. The information could also help determine whether additional stolen assets remain recoverable. However, the process is unlikely to produce an immediate solution, and the majority of the stolen funds may already be beyond practical recovery.

Implications for Exchange Security and Investors

The Bybit case is a reminder that cryptocurrency security is no longer a niche technical issue. As the value of cryptocurrency increases, criminal groups have greater incentives to target exchanges, custodians, and infrastructure providers. Security teams must defend against phishing, malware, compromised credentials, insider threats, and attacks on transaction infrastructure. The industry must continue investing in stronger wallet architecture, better transaction monitoring, improved employee security, and faster cooperation between companies.

The case is also relevant to cryptocurrency investors who keep assets on centralized exchanges. The Bybit hack demonstrates that exchange security remains a critical consideration even when companies use sophisticated custody systems. Investors should understand the difference between exchange custody and self-custody and consider the risks associated with each.

Final Outlook

Bybit has gained a new legal avenue in its effort to trace cryptocurrency stolen during the $1.5 billion hack that struck the exchange in February 2025. The court-backed process could allow the exchange to seek information from U.S.-based platforms that may have interacted with the stolen assets, potentially helping investigators identify funds that remain recoverable.

The development comes as reports indicate that roughly 90% of the stolen assets have already become untraceable. The FBI previously attributed the theft to North Korean actors and warned that the stolen assets were rapidly converted and dispersed across thousands of addresses and multiple blockchains.

The public nature of blockchain transactions means the investigation does not necessarily have an expiration date. Every movement of the stolen funds leaves a permanent record. If investigators can eventually connect those transactions to identifiable individuals, companies, or financial platforms, some portion of the assets could potentially be recovered.

The Bybit case also illustrates a broader transformation in cryptocurrency crime. Hackers are no longer simply stealing digital assets — they are developing increasingly sophisticated methods to move, convert, and conceal those assets across a global financial network. For exchanges, the lesson is clear: protecting cryptocurrency requires more than securing private keys; it requires defending the entire transaction ecosystem. For law enforcement, the case demonstrates why blockchain analysis, legal authority, and cooperation with private companies must work together.

The $1.5 billion Bybit hack may have happened more than a year ago, but the investigation is far from over.