US Court Backs Bybit to Trace $1.5B North Korea Hack

Add as a preferred source on Google

A US court authorized Bybit to subpoena exchanges to trace assets from its $1.5B February 2025 hack, allegedly by North Korea’s Lazarus Group. Yet 90% of funds were laundered via mixers and cross-chain swaps, prompting calls for stricter KYC, proof-of-reserves audits, and tighter crypto regulation.

Bybit, with the permission of the US court, managed to freeze assets involved in a $1.5B hack attributed to hackers who are presumed to be affiliated with North Korea.

The court order allows the Dubai-registered cryptocurrency exchange to pursue asset recovery in other places, but on-chain data shows that almost 90% of the hacked funds have already been washed or disguised and are Because of this not trackable anymore.

Court Backs Bybit’s Hunt for $1.5B Hack Funds

In February 2025, there was a cyberattack at Bybit, which the company estimated cost it $1.5B of crypto assets. Authorities in the US gave Bybit the go-ahead to serve subpoenas to request information about wallet clusters from other cryptocurrency exchanges and service providers.

Key parties are Bybit, blockchain investigators, the US judiciary and those in the country that are the main target of the hackers, as the hackers are linked to a North Korea-related Lazarus Group, which in the past has been found by US agencies to be responsible for similar hacks.

Also Read: Bybit Launches in Indonesia Under OJK Oversight, Boosting Crypto Competition

Laundering Outpaces Tracing

Given that around 90% of the stolen funds were dispersed via various mixing services and cross-chain swaps, the probability of tracing them back is very low; this makes it harder for centralizers like exchanges to implement the necessary measures for instant monitoring.

Bybit

Source: Pinterest

Regulators have already started using this situation for pushing more strict regulations on travelers’ rules, plus wallet-screening in stablecoins and custodians affecting investors institutions as well as developers working on Ethereum, Solana, and Bitcoin networks.

Also Read: Bybit Appoints Peter Loo as CLO to Lead 2026 Compliance

State Hack Wave Pushes Tighter KYC and Exchange Cooperation

The attack is a fit example of a new wave which is being rolled out through 2024-2025 by state-sponsored cybercriminals to compromise crypto infrastructures. This has been already pointed out by Chainalysis and TRM Labs. That means, KYC regulations are expected to become stricter.

Korea

On top of that, audits of proof-of-reserves will be enhanced. Apart from law enforcement, exchanges will also be working together.

Also Read: Bybit to Limit Global Platform Services for EEA Users Under Regulatory Shift

Ananthyka J

Ananthyka J

Ananthyka J is a market reporter at Tronweekly, reporting on cryptocurrency news. She covers cryptocurrency markets, blockchain technology, and digital asset regulation, focusing on Bitcoin, Ethereum, DeFi, altcoins, and crypto policy. Her reporting emphasizes clear and accurate market coverage, including crypto market movements, regulatory developments, and blockchain adoption. She holds a BA in Journalism and Mass Communication and an MA in Communication and Media Studies. She has also completed multiple media internships, follows strict editorial and fact-checking standards, and discloses potential conflicts of interest when reporting.

Articles: 808