Regulatory Action
Bybit Secures U.S. Court Support to Trace and Freeze Assets from $1.5 Billion Hack
Crypto.news reported that Bybit secured U.S. court orders to trace and freeze assets linked to its $1.5 billion hack, with reports of $48.4 million recovered and $30.5 million frozen, though these figures are not officially confirmed.

Legal Framework and Court Orders
According to reporting by Crypto.news, Bybit has made significant progress within the United States court system in its ongoing efforts to recover assets stemming from a massive February 2025 security breach. A federal judge reportedly granted the exchange expedited discovery powers along with a partial preliminary injunction. This legal maneuver allows the platform to formally request account identities, balances, and historical transaction data from various entities with operations in the United States that may hold information pertinent to the misappropriated funds. The initial legal filing was submitted under seal in the U.S. District Court for the District of Columbia, naming North Korea, its Reconnaissance General Bureau, the Lazarus Group, and numerous unidentified defendants.
Court documents cited by Crypto.news indicate that temporary restraints commenced in mid-June, followed by a preliminary injunction granted by Judge John D. Bates at the end of July. This judicial intervention is designed to preserve identified assets while the broader civil litigation moves forward. Legal representatives for the exchange argued that the court found a likelihood of success on the merits, though industry analysts emphasize that this represents an interim procedural finding rather than a definitive final judgment regarding all allegations contained within the original complaint. The proceedings continue to unfold as the platform attempts to leverage domestic judicial authority to reach intermediaries and service providers connected to the laundering network.
Asset Tracking and Traceability Challenges
Crypto.news reported that tracing the stolen funds has proven exceedingly difficult due to the complex laundering techniques employed by the perpetrators. At the time of the initial June filing, the exchange stated that an overwhelming majority of the misappropriated assets had become untraceable after passing through multiple cryptographic mixers, cross-chain bridges, and decentralized over-the-counter dealers. Only a small fraction of the stolen cryptocurrency remained directly connected to identifiable wallets at that juncture. The utilization of these advanced obfuscation methods significantly hampers traditional blockchain forensic analysis, necessitating the acquisition of offchain records and subscriber identities that only formal legal discovery processes can potentially uncover from centralized service providers.
The reporting highlights a dramatic shift in traceability metrics over time. While executives previously indicated that a higher percentage of the funds could be monitored in the immediate aftermath of the incident, subsequent laundering activities rapidly dispersed the capital across thousands of distinct addresses on multiple blockchains. The newly acquired discovery authority granted by the U.S. court aims to bridge this intelligence gap by compelling relevant platforms to surrender customer identification logs and transaction histories. However, industry observers note that transforming these legal authorizations into actual monetary recoveries remains a formidable challenge, especially given the decentralized and cross-border nature of the underlying digital infrastructure utilized during the laundering process.
Recovery Figures and Unconfirmed Status
According to figures published in the exchange's recent updates, approximately forty-eight million four hundred thousand dollars in stolen assets have been successfully recovered, while more than thirty million five hundred thousand dollars remains frozen across more than twenty-eight independent exchanges and custodians globally. While these numbers suggest tangible progress in asset containment, it is important to note that these specific recovery and freeze figures are not officially confirmed by independent regulatory authorities or neutral third-party auditors. The frozen portion of the capital has not yet been repatriated or returned to the platform, meaning the ultimate financial outcome of these containment measures remains subject to further legal determinations and international cooperation.
Crypto.news noted that the ongoing civil litigation seeks comprehensive financial remedies, including the return of the stolen assets, compensatory damages, punitive damages, and treble damages under specialized federal racketeering statutes. Nevertheless, these aggressive monetary demands are merely claims for relief put forward within the complaint. The presiding court has not yet entered a final judgment awarding these extensive damages against the named defendants. Consequently, the reported recovery and freeze metrics represent interim milestones within a complex international legal battle rather than a conclusive resolution of the financial losses incurred during the February 2025 breach.
FBI Attribution and Broader Investigations
The security incident, which took place on February 21, 2025, quickly drew the attention of federal law enforcement agencies. Five days after the breach occurred, the United States Federal Bureau of Investigation formally attributed the cyberattack to North Korean threat actors, designating the tracked activity under the moniker TraderTraitor. Law enforcement assessments indicated that the attackers systematically converted portions of the stolen cryptocurrency into Bitcoin and distributed the funds across a vast network of addresses spanning multiple blockchain ecosystems. The bureau actively urged virtual asset service providers, bridges, and blockchain analytics firms to block transactions interacting with the identified laundering addresses.
Crypto.news reported that Bybit maintains that its civil legal proceedings operate independently from ongoing criminal investigations being conducted by U.S. authorities. The exchange continues to share valuable blockchain intelligence and forensic data with federal investigators. Additionally, the broader enforcement landscape has benefited from international coordination, including actions taken by German authorities against illicit mixing services such as eXch and the joint German-Swiss disruption of Cryptomixer.io. These separate international law enforcement actions complement the civil litigation in Washington by systematically dismantling key laundering routes utilized by the threat actors following the initial theft.
Infrastructure Compromise and Response Strategy
Forensic investigations conducted in the aftermath of the attack traced the initial vector to compromised infrastructure connected to Safe Wallet. Independent reviews revealed that a compromised developer machine associated with Safe enabled the attackers to successfully propose a disguised malicious transaction. In response to these findings, Safe publicly clarified that subsequent internal reviews identified no structural vulnerabilities within its core smart contracts or underlying source code. The organization implemented remediation measures by completely rebuilding its affected infrastructure and rotating administrative credentials to prevent recurrence.
To bolster its own recovery efforts, the exchange instituted a dedicated bounty program shortly after the hack occurred, encouraging independent security researchers, forensic investigators, and digital asset platforms to assist in identifying and freezing illicitly obtained funds. The federal lawsuit represents an escalation of this multifaceted recovery strategy, equipping the platform with formal judicial discovery tools and injunctive relief mechanisms to compel cooperation from intermediaries operating within the reach of United States legal jurisdiction. This combination of private bounty incentives and public judicial enforcement forms the core of the ongoing asset retrieval campaign.
Conclusion and Outlook
In conclusion, Crypto.news reported that Bybit has achieved notable legal traction by securing U.S. court orders for expedited discovery and partial preliminary injunctions related to its $1.5 billion North Korea-linked hack. The affected entity, Bybit, along with affected platform users, navigates an environment where roughly forty-eight million four hundred thousand dollars has been reported recovered and over thirty million five hundred thousand dollars remains frozen across numerous global custodians. These figures, alongside the underlying allegations and recovery claims, are not officially confirmed by independent authorities. What changes now is that the exchange possesses formal judicial mechanisms to compel record production and restrain identified assets, shifting the focus toward enforcing discovery requests and identifying anonymous John Doe defendants.
The next action for Bybit involves processing responses from service providers to link blockchain addresses to real-world identities, while monitoring further judicial rulings on its pending damage claims. Observers must separate reported legal milestones from unconfirmed financial recovery amounts as the litigation progresses through the U.S. District Court for the District of Columbia. Stakeholders should continue evaluating platform risk based on verified disclosures and maintain awareness that further asset repatriations remain contingent upon successful enforcement of international and domestic court orders against uncooperative or anonymous actors.
Cexvia conclusion
Judicial Proceedings Continue Amid Unconfirmed Recovery Claims
Crypto.news reported that a U.S. federal judge granted Bybit expedited discovery and a partial preliminary injunction in its lawsuit concerning a $1.5 billion hack, though the allegations and recovery figures are not officially confirmed.
- Risk meaning
- The legal proceedings highlight the ongoing challenges exchanges face when attempting to recover substantial stolen digital assets after threat actors utilize advanced laundering techniques across multiple blockchain networks and cross-chain bridges.
- User action
- Users should maintain vigilance regarding platform security postures and monitor official announcements from relevant exchanges regarding legal developments and asset recovery statuses.

