Bybit’s $1.5 billion hack, attributed to North Korea’s Lazarus Group, was among the largest crypto thefts on record. Recovering stolen crypto after the fact is usually close to impossible once it’s been laundered through mixers and cross-chain bridges. This week, Bybit took its case to a US court — and got two rulings that give it real tools to chase the money, even though the attacker itself is a state-linked group with no intention of appearing to defend the case.
CoinDesk reported that Bybit sued North Korea and Lazarus Group directly and secured a preliminary injunction freezing assets connected to the hack. Cointelegraph separately reported that a US court granted Bybit’s request for expedited discovery, allowing the exchange to demand account identities, balances and transaction histories from platforms with US operations.
What the court actually granted
It’s worth separating what happened from what it guarantees, because “sues North Korea” and “wins the money back” are very different things.
- A preliminary injunction freezing assets — a court order that locks down specific funds tied to the hack so they can’t be moved or cashed out while the case proceeds, reported by CoinDesk.
- Expedited discovery — a court order, reported by Cointelegraph, letting Bybit compel US-connected platforms to disclose account identities, balances and transaction histories on an accelerated timeline rather than the normal pace of litigation.
Neither ruling recovers the $1.5 billion. Both are procedural weapons aimed at the same problem: stolen crypto that has likely already been split, swapped and moved across multiple platforms and chains, some of which touch US-regulated exchanges even if the attacker never does.
Why sue an attacker who won’t show up in court
North Korea and Lazarus Group are not going to send a lawyer to a US courtroom. That’s normal in cases like this, and it doesn’t make the lawsuit pointless. The practical value isn’t in getting Pyongyang to answer a complaint — it’s in creating a US legal basis to compel American and US-connected platforms to freeze, trace and disclose information about funds that touch their systems.
Laundering stolen crypto usually means running it through a chain of intermediaries: mixers, cross-chain bridges, and eventually exchanges where it can be converted to spendable value. Every one of those hops that touches a platform with US operations becomes something a US court order can reach, even when the original attacker is untouchable. That’s the mechanism this lawsuit is built around.
What this signals for exchange hack response
Large-scale crypto hacks have historically ended one of two ways: total loss, or informal negotiation with the attacker for a partial return. A formal US lawsuit with a preliminary asset freeze and expedited discovery is a more aggressive third path, and it’s notable that Bybit pursued it this fast and this publicly rather than working quietly through blockchain-forensics firms alone.
If courts continue to grant these tools quickly, it changes the calculus for attackers too. Layering funds through platforms with any US nexus becomes riskier when a freeze order and compelled disclosure can follow within weeks rather than years.
Bottom line
Bybit hasn’t recovered its $1.5 billion, and nothing in these rulings guarantees it will. What it has is a legal framework — an asset freeze and expedited discovery — built to chase laundered funds through the US-connected platforms that eventually touch them, even though the named attacker will never appear in court. For an industry that has mostly treated major hacks as unrecoverable losses, that’s a meaningfully different playbook.
Advertisement
Sources and review
This article was checked against the primary or authoritative sources below .
Frequently asked questions
According to CoinDesk, Bybit secured a preliminary injunction freezing assets tied to the hack. Cointelegraph separately reported that a US court granted Bybit's request for expedited discovery, letting it seek account identities, balances and transaction histories from platforms with US operations.
Not necessarily, and not yet. An asset freeze and discovery order are legal tools to trace and lock down funds tied to specific accounts — they are steps toward recovery, not a guarantee of it, especially against a state-linked actor with no presence in US courts to appear and contest the case.
Lawsuits against state-linked hacking groups typically proceed as in rem or default-style actions targeting the traceable assets and the US-based platforms holding or processing them, rather than depending on the named defendant appearing to defend itself.
Expedited discovery lets Bybit compel platforms with US operations to hand over account identities, balances and transaction histories faster than normal litigation timelines allow — useful against attackers actively trying to move or launder stolen funds before they can be traced.
Advertisement