What to know:
- US court approved subpoenas, but 90% of funds linked to Lazarus Group are already laundered.
- Part of a 2024-2025 wave flagged by Chainalysis and TRM Labs, driving more exchange-law enforcement cooperation.
- Expect stricter KYC, Travel Rule, and proof-of-reserves audits affecting exchanges, investors, and developers.

Bybit, with the permission of the US court, managed to freeze assets involved in a $1.5B hack attributed to hackers who are presumed to be affiliated with North Korea.
The court order allows the Dubai-registered cryptocurrency exchange to pursue asset recovery in other places, but on-chain data shows that almost 90% of the hacked funds have already been washed or disguised and are Because of this not trackable anymore.
Court Backs Bybit’s Hunt for $1.5B Hack Funds
In February 2025, there was a cyberattack at Bybit, which the company estimated cost it $1.5B of crypto assets. Authorities in the US gave Bybit the go-ahead to serve subpoenas to request information about wallet clusters from other cryptocurrency exchanges and service providers.
Key parties are Bybit, blockchain investigators, the US judiciary and those in the country that are the main target of the hackers, as the hackers are linked to a North Korea-related Lazarus Group, which in the past has been found by US agencies to be responsible for similar hacks.
Also Read: Bybit Launches in Indonesia Under OJK Oversight, Boosting Crypto Competition
Laundering Outpaces Tracing
Given that around 90% of the stolen funds were dispersed via various mixing services and cross-chain swaps, the probability of tracing them back is very low; this makes it harder for centralizers like exchanges to implement the necessary measures for instant monitoring.


Source: Pinterest
Regulators have already started using this situation for pushing more strict regulations on travelers’ rules, plus wallet-screening in stablecoins and custodians affecting investors institutions as well as developers working on Ethereum, Solana, and Bitcoin networks.
Also Read: Bybit Appoints Peter Loo as CLO to Lead 2026 Compliance
State Hack Wave Pushes Tighter KYC and Exchange Cooperation
The attack is a fit example of a new wave which is being rolled out through 2024-2025 by state-sponsored cybercriminals to compromise crypto infrastructures. This has been already pointed out by Chainalysis and TRM Labs. That means, KYC regulations are expected to become stricter.


On top of that, audits of proof-of-reserves will be enhanced. Apart from law enforcement, exchanges will also be working together.
Also Read: Bybit to Limit Global Platform Services for EEA Users Under Regulatory Shift





Be the first to comment