Bybit’s North Korea case shows how hard it is to turn traced crypto into recovered funds
Bybit’s civil action tied to the North Korea-linked hack lays out a broad recovery framework built on RICO claims, John Doe defendants, emergency injunctions and sanctions coordination. But the article argues that a legal strategy, even a sophisticated one, does not mean stolen assets are already recoverable. At the time Bybit disclosed the lawsuit, it said about $48.4 million in stolen assets had been recovered and another roughly $30.5 million had been frozen at more than 28 exchanges and custodians, for a combined $78.9 million, or about 5.3% of the initial $1.5 billion loss. The piece separates tracing, control, proof of ownership and final return as four different stages, each with its own failure points.
It also highlights limits created by asset commingling, cross-chain transfers, mixers, peer-to-peer transactions and third-party claims. One example involved Australian citizen Joseph F. Corrigan, who challenged an attempt to include a Nexo wallet holding about $39,000 in crypto in a preliminary injunction. The second half of the article then turns to lessons for Web3 firms: build joint response systems before an incident, prepare freeze-request templates and contact networks in advance, preserve chain data in a form courts can use, map real-world control points over assets, and tier recovery efforts across jurisdictions, sanctions exposure and expected value.