US Court Backs Bybit’s Bid to Trace $1.5B North Korea Hack Funds

A U.S. court has granted Bybit permission to conduct expedited discovery as the exchange seeks to trace funds allegedly linked to a $1.5 billion North Korea-related crypto hack. The order enables Bybit to request account identities, balances, and transaction histories from platforms with operations in the United States.

Court grants expedited discovery

The ruling authorizes Bybit to rapidly obtain limited records that could identify where disputed funds were moved and who controls related accounts. Expedited discovery is a tool courts sometimes allow in cases involving digital asset theft to prevent evidence from being lost and to facilitate asset tracing before funds are further dispersed.

Scope of information Bybit can seek

  • Account identities associated with suspected transfers
  • Account balances relevant to the traced funds
  • Transaction histories across implicated accounts

The requests may be directed to platforms with U.S. operations, including crypto exchanges and other intermediaries, subject to applicable legal process.

Why it matters

North Korea-linked hacking groups have been tied by international authorities to large-scale crypto thefts, with stolen assets often routed through multiple intermediaries. The court’s order could help Bybit map fund flows and identify counterparties, a critical step toward potential asset recovery and future enforcement actions. The move also underscores growing cooperation between crypto firms and U.S. courts in addressing cross-border cybercrime.

What comes next

Bybit is expected to issue targeted subpoenas to relevant platforms to obtain the authorized records. Respondents may seek to narrow or challenge requests, and the court will oversee compliance and scope. No timeline for further proceedings has been disclosed.

×