United States court records reveal that a federal judge granted Bybit expedited discovery in its case over a $1.5 billion crypto theft. The order allows the exchange to request account identities, balances and transaction histories from platforms with operations in the United States.
Bybit says those records could help locate assets linked to the February 2025 attack. The exchange seeks the data before account records or balances change.
Bybit filed the lawsuit under seal on June 18 in the District Court for the District of Columbia. It named North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants. The court approved expedited discovery the next day, while several exhibits and other case records stayed under seal.
The discovery order gives Bybit a legal path to seek records from exchanges and service providers within the court’s reach. In its complaint, Bybit alleged that some stolen funds entered platforms operating or maintaining infrastructure in the United States. Some platforms had indicated that they would cooperate after receiving a court order, the filing says.
The court also issued a temporary restraining order on June 19. That order barred the unidentified defendants from transferring certain traceable assets. A judge renewed it on July 16 and partially granted Bybit’s preliminary injunction request on July 30. Bybit says the order aims to preserve identified assets while the lawsuit proceeds.
Bybit told the court that 90.2% of the stolen assets had become untraceable by June 18. The exchange said the funds passed through mixers, cross-chain bridges and over-the-counter dealers. Those routes can move assets between networks or parties, making the transaction trail harder to follow.
However, Bybit traced 9.8% of the total to identifiable wallets. Its complaint says 5.3% of the stolen funds, worth about $75.5 million, had reached frozen accounts or returned to recovery channels. The figure marks a steep change from 2025, when CEO Ben Zhou said 68.57% of the funds were still traceable.
The February attack drained more than 400,000 ETH and staked ETH from the Dubai-based crypto exchange. Investigators linked the breach to compromised Safe Wallet infrastructure and credentials belonging to a Safe developer. The FBI attributed the theft to North Korea on February 26, 2025, under an operation it calls TraderTraitor.
The lawsuit seeks the return of stolen assets and approximately $1.5 billion in compensatory damages. Bybit also requests punitive damages and triple damages under the United States Racketeer Influenced and Corrupt Organizations Act. The civil case runs separately from criminal investigations led by United States law enforcement agencies.
Bybit CEO Ben Zhou said the company’s focus was to “protect our users first” and recover available funds. He also said the exchange wants those responsible held accountable. Meanwhile, Bybit plans to request more judicial relief. It will also share blockchain records with investigators, exchanges, custodians and regulators during the case.
The exchange alleges that the Lazarus Group carried out the theft for the North Korean government. North Korea has not publicly responded to the lawsuit in the available court record. The defendants have not yet presented a defense in the unsealed filings. Parts of the proceedings also remain unavailable to the public.
Also Read: SpaceX Share Shortfall Forces Binance, Bybit and Bitget to Refund Users