Bybit’s North Korea case shows how hard it is to turn traced crypto into recovered funds

Bybit’s North Korea case shows how hard it is to turn traced crypto into recovered funds

N
News Editor
2026-09-02 09:59:09
Bybit’s civil action tied to the North Korea-linked hack lays out a broad recovery framework built on RICO claims, John Doe defendants, emergency injunctions and sanctions coordination. But the article argues that a legal strategy, even a sophisticated one, does not mean stolen assets are already recoverable. At the time Bybit disclosed the lawsuit, it said about $48.4 million in stolen assets had been recovered and another roughly $30.5 million had been frozen at more than 28 exchanges and custodians, for a combined $78.9 million, or about 5.3% of the initial $1.5 billion loss. The piece separates tracing, control, proof of ownership and final return as four different stages, each with its own failure points. It also highlights limits created by asset commingling, cross-chain transfers, mixers, peer-to-peer transactions and third-party claims. One example involved Australian citizen Joseph F. Corrigan, who challenged an attempt to include a Nexo wallet holding about $39,000 in crypto in a preliminary injunction. The second half of the article then turns to lessons for Web3 firms: build joint response systems before an incident, prepare freeze-request templates and contact networks in advance, preserve chain data in a form courts can use, map real-world control points over assets, and tier recovery efforts across jurisdictions, sanctions exposure and expected value.

Author: Zhang Qianwen

How much money can this strategy actually recover?

RICO, John Doe defendants, emergency injunctions and sanctions coordination have created a broad recovery framework. That does not mean the stolen assets are already in a recoverable state.

When Bybit disclosed the lawsuit, it said about $48.4 million in stolen assets had already been recovered. Another roughly $30.5 million had been frozen at more than 28 exchanges and custodians. Together, that comes to about $78.9 million, or 5.3% of the initial $1.5 billion loss. If recovered assets and temporarily frozen assets are separated, the actual cash-back ratio is lower still.

Those figures point to four stages that are often blurred together in digital-asset recovery: assets that can be seen on-chain, assets that can be controlled in the real world, assets that can be proven in legal proceedings, and assets that are finally returned in practice.

A break at any one of those stages can keep clearly visible on-chain assets from ever making their way back to Bybit.

First threshold: how much traceable value can reach a controllable node?

As discussed earlier in the series, visible on-chain does not equal controllable in the real world. For recovery rates, the core question is not how many addresses an analytics firm can label. It is how much of that value reaches an exchange, custodian, stablecoin system or fiat off-ramp where intervention is possible. If assets remain in the attacker’s self-custodied wallets, even full transparency on address balances may still leave no practical path to freeze them.

Through splitting, cross-chain movement, mixers and peer-to-peer trading, Lazarus stretches out the path and disperses balances. The direct effect is to narrow the window in which assets pass into controllable nodes and to keep raising the cost of pursuing each transfer.

Once investigation costs, litigation costs and cross-border enforcement costs exceed the expected amount that might be recovered from a specific asset pool, it may stop making commercial sense to keep going, even if the funds are still visible.

Second threshold: how much controllable value can survive proof-of-ownership challenges?

Even after assets reach a controllable node, Bybit still has to turn chain-tracing results into ownership evidence that can stand up in adversarial proceedings. It must show that the original assets were under its lawful control, that they were moved without authorization, that the property now being claimed is reliably linked to the stolen assets, and that the scope of the freeze matches the assets that can actually be traced.

Each conversion, bridge transfer, liquidity-pool transaction or platform consolidation adds another layer of dispute over both tracing methods and the proper scope of return.

Third threshold: how much of what is frozen can actually be returned?

A freeze only preserves assets for the moment. It does not decide final ownership. Bybit still has to complete valid service, prove the source of the assets, obtain a final judgment or return order, and address objections from account holders and other interested parties.

If the assets are subject to U.S. sanctions rules, a return may also require Office of Foreign Assets Control, or OFAC, licensing. If the assets sit on an offshore platform, a U.S. court order may need local judicial assistance, recognition proceedings or fresh preservation measures before anything happens in practice.

That is why the roughly $30.5 million in frozen assets cannot be treated as money already recovered. Those assets have only entered a state where return is possible. The final amount and timeline still depend on ownership proof, sanctions requirements and cross-border enforcement procedures.

Commingling and third-party claims can shrink the recovery pool

After multiple transfers, stolen assets may end up with third parties who were unaware of the hack. They may also become commingled with legitimate assets belonging to other users. Once a third-party objection appears, or once the disputed assets can no longer be clearly separated from other property, the range of assets that Bybit can continue to freeze and seek to recover may narrow.

In this case, an Australian citizen living in Southeast Asia, Joseph F. Corrigan, filed his own objection in court. He claimed to be the lawful owner of about $39,000 in crypto held in a wallet on Nexo and opposed having that wallet included in the scope of a preliminary injunction. Bybit disputed Corrigan’s description of the facts, but because his identity had been established, the amount at issue was relatively limited, and he could still be added later as a named defendant, Bybit agreed to temporarily exclude the wallet from the preliminary injunction request. The court therefore did not issue a preliminary injunction against that wallet, while also not making a final determination that the assets belonged to Corrigan.

The episode shows why the amount of on-chain associated assets is not the same thing as the amount that can ultimately be recovered. Once a third party raises an independent claim with at least some foundation, Bybit may have to step back from emergency freezing of those assets and move into later litigation to show that its claim is superior.

Commingling creates a separate limit. If stolen ETH enters an exchange omnibus wallet and mixes with other users’ assets, Bybit is unlikely to freeze the entire omnibus wallet simply because some of the funds are tied to the attack. It would need to identify the relevant accounts more precisely and show that the scope of its claim matches assets that can still be traced or reasonably separated.

If every wallet that had any indirect contact with stolen assets were permanently treated as tainted, the freeze perimeter would keep expanding along the transaction chain and affect many users with no connection to the attack. The opposite extreme is also a problem. If a single transfer or any commingling destroyed recoverability altogether, an attacker could cut off tracing too easily. Different jurisdictions therefore have to decide, under their own rules on bona fide acquisition, asset tracing and commingling, how far Bybit can continue to trace, how much can be frozen and how much can be returned.

The bottom line is narrow but important: Bybit’s ultimate recovery amount does not depend only on how much has been traced or frozen. It also depends on how much survives third-party rights challenges and how much can still be reasonably identified within commingled property. The figures for associated assets, temporarily frozen assets and finally returned assets may decline step by step.

Why sue if a huge judgment may still be far from real recovery?

The first part of the series explained that civil RICO can support treble damages. Even so, a theoretical claim of about $4.5 billion is still a long way from actual collections.

North Korea is highly unlikely to comply voluntarily with a U.S. judgment. Even if Bybit overcomes sovereign-immunity issues and wins, the enforcement stage still requires it to locate specific property attributable to the relevant defendants, within reach of enforcement, and not shielded by execution immunity or competing rights. Assets blocked under OFAC rules do not automatically become property available to satisfy Bybit’s claim.

What determines actual recovery is not the number printed in the judgment. It is how much of the disputed property can enter real-world nodes that are identifiable, controllable, provable and enforceable.

Even so, the lawsuit still has practical value.

  • First, the loss base is large enough at $1.5 billion that even a modest recovery percentage could still cover a meaningful share of investigation and cross-border litigation costs.
  • Second, digital-asset recovery is not a one-off event. Some funds may sit dormant on-chain for years and move into exchanges or fiat off-ramps only after outside attention fades. Continued tracing and preservation of legal rights help keep future control opportunities alive.
  • Third, litigation can produce records that private investigators may struggle to obtain. Through subpoenas and cross-border judicial assistance, Bybit may gain access to exchange KYC records, login records, account-linkage material and banking information. Those records may help recover current assets and identify broader laundering or support networks.
  • It also raises the attacker’s monetization costs. Even if the full amount cannot be recovered immediately, ongoing address labeling, account investigations and liability claims against facilitators can make it harder to move stolen assets into the regulated financial system.
  • Finally, Bybit has a market-trust problem to address. For a platform built around custody of user assets, the quality of the post-attack response is part of its commercial credibility. Continued tracing, industry coordination and federal litigation send a message to users, regulators and counterparties that the platform will not simply write off the loss and move on.

By that measure, the success of the lawsuit cannot be judged only by whether Bybit gets the full $1.5 billion back. Other benchmarks matter too: how much was actually recovered or frozen, how many anonymous controllers were identified, whether key platform records were obtained, whether new laundering nodes were found, whether parallel measures were triggered in other jurisdictions, and whether the case produced a recovery path that can be reused.

Seen this way, the most important outcome may not be a massive default judgment against North Korea. It may be whether Bybit can convert at least part of a pool of assets that initially had only on-chain coordinates and no real-world identity into property that can be actually controlled, supported by evidence, protected by judicial measures and ultimately returned.

For other Web3 firms, the main question is not only how much Bybit may eventually recover. It is whether a company already has the ability, when an attack really happens, to turn on-chain data quickly into evidence, freezing measures and cross-border recovery action.

What does the Bybit case teach Web3 companies?

The Bybit case is unusual in obvious ways: a $1.5 billion loss, an attack attributed by the U.S. government to a North Korea-backed cyber actor, federal litigation in the United States, RICO claims, and asset tracing that runs across multiple blockchains and jurisdictions. Most Web3 companies will not face that exact combination.

Still, the risk-response logic has broader value. Companies should build a mechanism before an attack happens, not after, so that on-chain anomalies can be turned quickly into evidence, freezing measures and cross-border recovery action.

Once funds leave a company wallet, the event stops being just a technical-security issue. It immediately becomes a matter of asset ownership, evidence preservation, platform coordination, sanctions screening, criminal reporting and cross-border litigation. If technical, legal and compliance teams move one after another on separate timelines, the business may miss the most important preservation window before its internal process is even complete.

Move from a technical response to a joint response

After an attack, a Web3 company usually starts by suspending withdrawals, patching vulnerabilities, confirming losses and publishing a notice. Those steps can stop the loss from growing, but they do not solve the problem of how to recover assets that are already gone.

A complete response has to run several tracks at once. Technical teams need to confirm the attack path and preserve system logs. Wallet and finance teams need to verify assets, permissions and accounting impact. On-chain analysts need to trace and label funds. Lawyers need to assess ownership, evidence and freezing routes. Compliance teams need sanctions and anti-money-laundering reviews. Management needs to decide on service suspension, reporting to authorities, external disclosure and cross-border recovery.

Those tasks should not be lined up in simple sequence. A technical fix may overwrite critical logs. A communications team that discloses suspect addresses or tracing paths too early may alert the attacker and prompt fresh transfers. A business team that closes accounts before records are preserved may damage later investigations. The point of a joint response is to keep every team working from the same factual record and the same order of priorities.

Companies also need a pre-set emergency authorization structure. Who can suspend wallet operations? Who can send freeze requests to exchanges? Who contacts law enforcement and outside counsel? At what loss threshold do senior management or the board step in? Those questions should not wait for a live incident.

External communications belong inside the same framework. Public notices should distinguish between confirmed facts and assessments still under review, between attribution by governments or third parties and final court findings, and between assets already recovered and assets only temporarily frozen. Too little disclosure may deepen market suspicion. Too much may reveal investigative paths and planned preservation measures.

Companies with cyber insurance, crime coverage or digital-asset insurance should also notify insurers promptly and define in advance the evidence standard, how litigation costs are handled, subrogation rights and how recovered proceeds will be allocated. Delay or inaccurate statements during the response can affect coverage outcomes.

Secure the early recovery window after an attack

In digital-asset recovery, the most important period is often not the final judgment. It is the first hours and the first few days after the attack.

The earlier tracing begins, the easier it is to build a full initial flow of funds, identify the moment assets reach exchanges or other centralized nodes, and ask for freezes before the money has been repeatedly split, bridged and commingled.

That is why companies should not start researching basic questions only after an incident occurs: which chain-analysis firm to call, which entity in the corporate group should report the crime and assert rights, who will coordinate with exchanges and custodians, where emergency measures are available, and whether users, regulators and insurers need to be notified.

Those resources and decision paths should already be written into the incident-response plan. At a minimum, a company should have a contact network ready for major exchanges, custodians, stablecoin issuers, chain-analysis firms, law-enforcement agencies and outside counsel, together with freeze-request templates that can be completed and sent at speed.

An effective emergency freeze request usually needs to identify the victim entity, summarize the incident, provide the original transaction hash, identify the relevant addresses, describe the key fund flows and specify the transactions through which the assets entered the platform in question. The company should also ask the platform to preserve KYC records, login IPs, device records, trading records and withdrawal records, and confirm whether a police request, court order or other materials are needed to extend the freeze period.

The first notice is mainly about creating awareness, preserving the status quo and saving evidence that might otherwise disappear. Without that first window, later reporting, litigation and return procedures may have nothing practical to attach to.

Build an on-chain evidence system that can go into court

A company should not wait until litigation begins to convert chain data into courtroom evidence. Original transaction data, collection time, block height, transaction hash, the personnel who extracted the data, the analysis tools used and the review process should all be recorded from the start of the incident.

It is also important to separate objective facts, expert inferences and risk ratings. For example, “100 ETH moved from address A to address B” is an on-chain fact. “Addresses A and C may be controlled by the same actor” is an analytical conclusion. “That actor is Lazarus Group” requires government attribution or off-chain evidence.

When hiring a chain-analysis firm, the company should confirm whether the firm can preserve underlying data, explain its clustering method and margin of error, and produce an expert report or support testimony if needed.

Companies should also map legal ownership of assets in advance. In a large Web3 group, brand operations, website services, wallet management, customer contracts and accounting records may sit with different entities. After an attack, courts and platforms will press further: who controlled the compromised wallet, did the assets belong to the company or its users, which entity bears the payout obligation, who suffered the legally relevant loss, and who has authority to report the case, seek a freeze and file suit?

If a company cannot answer those questions clearly in ordinary operations, even a clean on-chain flow may not be enough. Recovery can be delayed by uncertainty over the plaintiff entity, asset ownership and loss allocation.

In the end, an on-chain evidence system must connect two ends of the problem: transaction hashes, wallet addresses and fund flows on one side, and corporate entities, customer contracts, accounting records and asset rights on the other. Only when those two ends match can visible on-chain money become property a court can actually process.

Map real-world control points over assets before they matter

Companies should document in advance who holds private keys, account permissions, smart-contract administrative rights or fiat off-ramp access for different assets, then build an asset-control map around that information.

At minimum, that map should cover issuers, custody structure, wallet permissions, redemption paths, emergency contract functions, major trading venues, relevant jurisdictions and emergency contacts. After an incident, it should help answer a short set of practical questions: where is the asset sitting, who can technically stop it from moving, and which court or regulator can influence that party?

For DeFi projects, this means reviewing whether contracts can be upgraded, whether there are admin keys, pause functions or governance multisigs, and who controls infrastructure such as the frontend or oracles. An asset-control map does not mean every protocol should include freeze features. It means a company should know where real control exists.

Build a layered system for freezes, sanctions response and cross-border recovery

Digital assets can pass through platforms in several countries within minutes. One court, one agency or one legal team is unlikely to handle all of it. Companies need to tier recovery targets based on where the funds are, how controllable they are and what recovery value they may justify.

The first tier covers large-value assets with clear flows that have already entered compliant exchanges or custodians. Those assets should be prioritized for freeze notices and evidence-preservation requests, followed quickly by an assessment of whether criminal reporting, emergency injunctions or local judicial measures are needed.

The second tier covers assets still sitting in self-custodied wallets that cannot yet be controlled but remain highly traceable. A company can keep monitoring those addresses and escalate the response as soon as the funds enter an exchange, a stablecoin system or a fiat off-ramp.

The third tier covers smaller amounts, heavily commingled assets or funds that have moved into jurisdictions that do not cooperate. Those transfers may still be recorded, but the company has to weigh investigative cost, litigation cost and enforcement probability before deciding whether separate legal action is justified.

Sanctions screening should also use risk tiers rather than checking only whether a deposit address appears directly on an OFAC list. If assets directly hit a listed wallet, or there is strong basis to conclude they are owned or controlled by a sanctioned person, applicable rules may require blocking and reporting. If there is a short transactional distance to a high-risk address or some other strong association, the transaction may need to be paused and investigated further. If the contact is remote and there are no other risk indicators, a permanent freeze based only on historical chain association may be hard to justify.

For cross-border recovery, companies should identify key jurisdictions in advance around major exchanges, custodians, stablecoin issuers and fiat off-ramps. They need to know whether local law recognizes digital assets as property, whether suits can be filed against unknown defendants, whether without-notice freezing orders are available, whether a platform can be required to disclose KYC records, and how foreign court orders are recognized and enforced.

None of that means every attack requires lawsuits around the world.

A rational recovery target is not to chase every single token at any cost. It is to spend limited budget and time first on assets with a higher probability of control, larger value and a clearer legal path.

In the end, a company needs a digital-asset recovery playbook that can be activated immediately. At a minimum, it should cover lists of assets, wallets and permissions; internal incident tiers and emergency authorization rules; standards for preserving chain data and system logs; external contact networks; templates for freeze requests and evidentiary attachments; sanctions and anti-money-laundering risk-tier rules; emergency measures in priority jurisdictions; and communication procedures for users, regulators, insurers and the media.

The central lesson from the Bybit case is not treble damages under RICO, and not whether a U.S. court can ultimately adjudicate North Korea. It is the shape of a complete legal architecture for digital-asset recovery. Only when technical tracing, evidence preservation, asset protection, sanctions compliance and cross-border enforcement are designed as one system can a company avoid merely watching funds move on-chain and instead regain real chances to act whenever those assets reach a centralized platform, reveal a real-world identity or approach a fiat exit.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.