TLDR
A US federal court has backed Bybit's effort to freeze some of the crypto stolen in a 1.5 billion dollar hack tied to North Korea, but most funds remain unrecovered.
- The court issued orders that let Bybit trace and freeze hack linked assets across many exchanges and custodians while its lawsuit proceeds.
- So far about 78.9 million dollars has been recovered or frozen, showing how effective Lazarus Group laundering is at making the bulk of funds unreachable.
- The case may become a legal template for future mega hacks and is likely to tighten compliance, tracing and freezing practices across the crypto ecosystem.
Deep Dive
1. Court Orders And Scope
Bybit filed a civil case in the US District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, the Lazarus Group, and unnamed holders of the stolen funds. A judge granted expedited discovery and temporary restraining orders, followed by a partial preliminary injunction that freezes identified assets while the case is litigated.
These orders compel exchanges and custodians to disclose account information and block transfers of wallets linked to the February 21 2025 hack, which the FBI attributed to North Korean actors known as TraderTraitor. This gives Bybit more leverage to trace and preserve whatever part of the stolen ether is still visible on compliant platforms.
2. Recovery Versus Laundering Reality
Bybit reports about 48.4 million dollars recovered and another 30.5 million dollars frozen across more than 28 platforms, roughly 78.9 million dollars in assets secured against a theft near 1.5 billion dollars. As of June 2026, about 90 percent of the stolen funds were already untraceable due to laundering through mixers, cross chain bridges and over the counter networks.
Analysis of recent hacks shows a fairly standard laundering cycle where most movement happens in the first 45 days using DeFi protocols, mixing services and low KYC venues, after which only a small fraction is ever recovered. In Bybit's case, less than 5 percent of funds have been secured despite aggressive technical and legal efforts.
For ordinary users, large exchange hacks are more about prevention and venue security than realistic expectations of getting stolen funds back later.
3. Wider Impact And What To Watch
The Bybit litigation and US court freezes put more pressure on infrastructure involved in laundering, including bridges, mixers and lightly regulated exchanges that touch US facing platforms or major stablecoins. Future orders could expand freezes as more wallets are identified, and other hacked exchanges may copy this combined incident response plus civil litigation strategy.
At the same time, attackers are adapting by pushing more value into assets and venues that are harder to freeze or sanction, which keeps the cat and mouse dynamic alive. For crypto users, key signals to watch are further court actions on mixers and cross chain services, and exchange security practices and insurance coverage for custodial funds.
Conclusion
The frozen slice of Bybit's 1.5 billion dollar hack shows that courts and compliance teams can meaningfully limit damage, but they only capture a small fraction once sophisticated actors start laundering. The main takeaway for crypto participants is that robust security, careful venue choice and understanding how frozen assets and sanctions work matter far more than hoping legal action will fully reverse a major exploit.
