Key Points
- The cryptocurrency exchange initiated legal proceedings in US federal court targeting North Korea, the Reconnaissance General Bureau, and Lazarus Group following the February 2025 breach
- The court approved expedited discovery measures, enabling the exchange to track stolen cryptocurrency through platforms operating in the United States
- Approximately 90.2% of the stolen digital assets have disappeared from traceable channels following their movement through mixing services and cross-chain protocols
- Court orders have resulted in the freezing of certain stolen holdings linked to unnamed defendants
- Recovery efforts have successfully frozen or retrieved just 5.3% of total stolen funds, approximately $75.5 million
The Dubai-based cryptocurrency platform has initiated civil proceedings in the US District Court for the District of Columbia against North Korea, along with its Reconnaissance General Bureau and the notorious Lazarus Group. The legal action stems from the devastating breach on February 21, 2025, which resulted in the theft of more than 400,000 Ether tokens, valued at approximately $1.5 billion during the incident.
Federal investigators officially linked the breach to North Korean operatives on February 26, 2025. American authorities have designated the group as TraderTraitor and have called on cryptocurrency platforms and blockchain companies to prevent transactions involving addresses associated with the money laundering scheme.
Federal Judge Authorizes Critical Legal Measures
Bybit submitted the complaint under confidential seal on June 18, 2026. The presiding federal judge authorized expedited discovery procedures one day later. This legal mechanism empowers the exchange to obtain account holder information, balance records, and complete transaction logs from any platform maintaining US-based operations.
On June 19, the court enacted a temporary restraining order targeting unnamed defendants, prohibiting them from moving identifiable assets. This protective measure received an extension on July 16, followed by a partial grant of preliminary injunction on July 30.
The preliminary injunction functions as an interim measure rather than a conclusive judgment. Its purpose is to safeguard remaining assets during ongoing litigation.
Majority of Stolen Cryptocurrency Lost to Tracking
According to the June 18 court submission, the exchange confirmed that 90.2% of the stolen digital assets had vanished from traceable networks. The perpetrators employed mixing protocols, cross-chain transfer mechanisms, and private over-the-counter exchanges to eliminate the digital footprint.
The balance of 9.8% had been successfully tracked to known wallet addresses. From this portion, 5.3% of the overall amount—roughly $75.5 million—had been successfully frozen or retrieved.
This represents a dramatic decline from initial recovery prospects. Chief Executive Ben Zhou stated over twelve months ago that 68.57% of the stolen funds remained traceable. By April 2025, this percentage had plummeted to 27.6%.
The security breach occurred after attackers gained unauthorized access to Safe Wallet’s cloud systems using authentication credentials stolen from a Safe developer. The perpetrators inserted malicious code that facilitated the extraction of funds.
The exchange maintained that it fulfilled all customer withdrawal requests following the incident by acquiring Ether, securing loans, and receiving deposits from partner institutions. Platform operations remained uninterrupted throughout the crisis.
Through this litigation, the platform is pursuing the complete recovery of stolen digital assets, compensatory damages totaling approximately $1.5 billion, punitive damages, and treble damages pursuant to the US Racketeer Influenced and Corrupt Organizations Act.
North Korean groups are believed to have stolen roughly $2.02 billion in digital currencies throughout 2025, based on research from Chainalysis. The attack on this exchange represented the largest single incident within that timeframe, elevating North Korea’s estimated total cryptocurrency theft to approximately $6.75 billion. During April 2026, attacks attributed to Lazarus reportedly extracted an additional $577 million from Drift Protocol and KelpDAO.
The exchange emphasizes that this civil litigation operates independently from continuing US criminal proceedings. The platform has indicated its intention to pursue additional legal remedies as the case advances.





