A US court has granted Bybit expedited discovery in its effort to trace funds stolen in the roughly $1.5 billion hack attributed to North Korea earlier this year, according to Cointelegraph. The order lets the exchange move faster than a normal lawsuit timeline allows, seeking account identities, balances, and transaction histories connected to wallets that handled the stolen crypto.
The February 2026 breach ranks as one of the largest single thefts in crypto history. Investigators tied it to North Korea-linked actors, the same cluster of state-backed groups responsible for a string of exchange and bridge attacks over the past several years. The attackers moved the funds through mixers, cross-chain bridges, and a fan-out of intermediary wallets designed to break the on-chain trail.
The legal mechanism that matters here
Expedited discovery is the practical core of the story. In a standard case, discovery, the phase where a party can compel documents and records, comes months into litigation. Courts grant an accelerated version only when waiting would cause real harm, such as evidence disappearing or assets being moved beyond reach. Stolen crypto is a textbook fit: every hour, laundering software can push funds through another hop.
The order gives Bybit a court-backed path to demand identifying information from the services that touched the money. That means the platforms, custodians, or counterparties holding the relevant accounts can be compelled to hand over who controls them, what balances sit inside, and how funds moved in and out. On a public blockchain, anyone can watch coins move between addresses. The hard part is attaching a real name to an address, and that is exactly what discovery can force.
From blockchain forensics to courtroom leverage
Tracing stolen crypto has always been a two-layer problem. The first layer is technical: following the money across chains and through mixing services using blockchain analytics. The second layer is legal: converting an on-chain lead into a name, a frozen account, or a returned balance. Analytics firms have gotten good at the first layer. The second has lagged, because it depends on courts and exchanges cooperating across borders.
This ruling strengthens the second layer. It signals that a US court will treat a large exchange hack as grounds for aggressive, fast-moving evidence collection rather than a slow civil grind. For an industry that has watched hundreds of millions of dollars vanish into obfuscation over the years, a judicial green light to compel account records is a meaningful shift in the recovery playbook.
There are limits worth stating plainly. A discovery order is not the same as recovering the money. North Korea-linked laundering operations are sophisticated, and a large share of stolen funds in past incidents has passed through services outside the reach of any single court. Sanctioned mixers and non-cooperative jurisdictions can still swallow the trail. The order improves Bybit's odds of identifying who received the funds; it does not guarantee the coins come back.
The custody lesson underneath the headline
The Bybit incident is, at its root, a story about where crypto sits and who controls the keys. Centralized exchanges pool enormous balances, which makes them the highest-value targets on the network. When one is breached, users depend entirely on the exchange's ability to absorb the loss and pursue recovery. That counterparty exposure is the same reason some users hold assets in self-custody wallets and spend from cards tied to their own keys rather than an exchange balance.
None of that makes centralized platforms avoidable for most people, and Bybit's response, moving quickly to court, is the kind of institutional muscle a self-custody setup cannot offer. But the tradeoff is worth naming: convenience and deep liquidity on one side, single points of failure on the other. The recurring pattern of state-backed attacks on exchanges is a reminder that the security of the network as a whole is only as strong as the custody choices at its largest chokepoints.
Overview
A US court has granted Bybit expedited discovery to trace the roughly $1.5 billion stolen in the February 2026 North Korea-linked hack, allowing the exchange to compel account identities, balances, and transaction histories from services that handled the funds. The ruling accelerates evidence collection and pairs blockchain forensics with courtroom leverage, though it stops short of guaranteeing recovery given the sophistication of state-backed laundering. For users, it underscores the counterparty risk built into large custodial platforms and the reason self-custody remains part of the security conversation.



