How Much of the $1.5 Billion Can Be Recovered? The Realistic Boundaries and Industry Insights of Bybit's Lawsuit Against North Korea
The most important takeaway from the Bybit case for Web3 companies is not the triple damages under RICO, nor whether a U.S. court can ultimately rule against North Korea, but rather a comprehensive legal framework for asset recovery.
Written by: Zhang Qianwen
How Much Can This Strategy Actually Recover?
RICO, John Doe, emergency injunctions, and sanctions have collaboratively built a network for asset recovery, but a complete legal pathway does not equate to the stolen assets being in a recoverable state.
As of the time Bybit announced the lawsuit, it disclosed that approximately $48.4 million of stolen assets had been recovered, with another $30.5 million frozen across more than 28 exchanges and custodians. The total amounts to about $78.9 million, which is roughly 5.3% of the initial loss of $1.5 billion. If we further differentiate between "already recovered" and "temporarily frozen," the actual recovery rate is even lower.
These figures reveal four often-confused stages in digital asset recovery: visible on-chain, controllable in reality, legally provable, and completed return in reality. Any disruption in one of these links may prevent a clearly visible on-chain asset from actually returning to Bybit.
1. The First Threshold: How Much of the Traceable Assets Can Enter Control Nodes
As discussed in the previous article, visibility on-chain and control in reality are two different matters. For recovery rates, the key is not how many addresses the institution can tag, but how many of those assets will enter intervention nodes such as trading platforms, custodians, stablecoin systems, or fiat currency exits. Assets still residing in the attackers' non-custodial wallets, even if the addresses and balances are completely transparent, may lack a realistic path for executing a freeze.
Lazarus extends paths, disperses balances through splitting, cross-chain transactions, mixing, and peer-to-peer trading, effectively compressing the time window for these assets to enter controllable nodes and continuously increasing the cost of each recovery attempt.
When the costs of investigation, litigation, and cross-border enforcement exceed the expected recovery amount of an asset, even if the funds remain "visible," continuing the pursuit may lose commercial viability.
2. The Second Threshold: How Much of the Controllable Assets Can Be Proven by Ownership
Even if assets enter controllable nodes, Bybit still needs to convert the on-chain tracking results into ownership evidence that can withstand scrutiny: proving that the original assets were legally controlled by it, that the assets were transferred without authorization, and that there is a reliable connection between the claimed property and the stolen assets, while ensuring that the scope of the freeze matches the traceable assets.
Every time an asset undergoes a conversion, cross-chain transaction, liquidity pool trade, or platform aggregation, the tracking methods and return scope add another layer of dispute.
3. The Third Threshold: How Much of the Frozen Assets Can Be Returned
Freezing merely temporarily retains assets and does not determine final ownership. Bybit still needs to complete legal service, prove the source of the assets, obtain a final judgment or return order, and address objections from account holders and other stakeholders.
If the assets are subject to U.S. sanctions rules, returning them may also need to meet OFAC licensing requirements; if the assets are on foreign platforms, U.S. court orders may also require local judicial assistance, recognition procedures, or new preservation measures to be enforced.
Thus, the approximately $30.5 million in frozen assets cannot be directly viewed as already recovered funds. They merely enter a state of "potential return," with the final amount and timing still dependent on ownership, sanctions, and cross-border enforcement procedures.
4. Asset Confusion and Third-Party Claims Further Limit Recovery Scope
After being stolen, assets may pass through multiple hands, potentially entering the possession of unaware third parties or becoming mixed with other users' legitimate assets. Once a third party raises an objection, or if the involved assets cannot be clearly distinguished from other properties, the range of assets Bybit can continue to freeze and request return for may correspondingly shrink.
In this case, an Australian citizen residing in Southeast Asia, Joseph F. Corrigan, independently raised an objection in court, claiming to be the legitimate rights holder of approximately $39,000 worth of crypto assets in a wallet on the Nexo platform, opposing the court's inclusion of that wallet in the preliminary injunction. Although Bybit disagreed with Corrigan's description of the facts, considering his identity was clear, the amount involved was relatively limited, and he could still be added as a named defendant to assert rights later, Bybit agreed to temporarily exclude that wallet from the preliminary injunction. Consequently, the court did not issue a preliminary injunction against that wallet, but it has not yet definitively determined that the assets belong to Corrigan.
This episode illustrates that the amount of associated assets shown on-chain cannot be directly equated to the final recoverable amount. Once a third party raises a well-founded independent claim, Bybit may need to temporarily forgo the emergency freeze on the relevant assets and instead prove its superior rights through subsequent litigation.
Asset confusion can also limit the recovery scope. For example, if stolen ETH enters a collection wallet on a trading platform and mixes with other users' assets, Bybit may find it difficult to freeze the entire collection wallet based solely on a portion of the funds being related to this attack, and will need to further identify the involved accounts and prove that the scope of its claims corresponds to assets that can be continuously tracked or reasonably distinguished.
If all wallets that have indirectly interacted with the stolen assets are permanently regarded as "contaminated addresses," the scope of freezing will continuously expand along the transaction chain, affecting a large number of users unrelated to the attack; conversely, if funds lose recoverability after just one transfer or mixing, attackers can easily sever the pursuit. Therefore, different jurisdictions need to determine how far Bybit can continue to pursue, how much to freeze, and how much to return based on their rules regarding good faith acquisition, asset tracking, and handling of confusion.
Thus, it is evident that the amount Bybit can ultimately recover depends not only on how many assets are tracked and frozen but also on how many are not challenged by third-party rights and can be reasonably identified from mixed properties. The relationship between "on-chain associated amount---temporarily frozen amount---final return amount" is likely to decrease step by step.
5. The Large Judgment and the Gap with Actual Recovery: Why It Is Still Worth Suing
As previously mentioned, civil RICO may lead to triple damages, but there is still a long way between the theoretical request scale of approximately $4.5 billion and actual recovery.
North Korea is almost impossible to voluntarily comply with U.S. judgments; even if Bybit overcomes sovereign immunity and wins, the enforcement phase still requires finding specific properties belonging to the relevant defendants that are within the enforceable scope and not subject to enforcement immunity or other rights restrictions. Assets blocked by OFAC will not automatically convert into Bybit's settlement properties.
Therefore, what truly determines recovery is not the numbers on the judgment but how many involved assets can enter identifiable, controllable, provable, and enforceable real nodes.
Nevertheless, this lawsuit still holds practical value.
First, the loss base of $1.5 billion is substantial enough. Even if the final recovery rate is low, the absolute amount may cover a significant portion of investigation and cross-border litigation costs.
Second, digital asset recovery is not a one-time action. Some funds may remain dormant on-chain for years, only to enter trading platforms or fiat currency exits after external attention wanes. Continuous tracking and retaining legal rights can provide a foundation for future control opportunities.
Third, lawsuits can obtain information that private investigations may find difficult to access. Through court subpoenas and cross-border judicial assistance, Bybit may acquire KYC, login records, account associations, and banking information from trading platforms. This information not only aids in recovering current assets but may also identify a broader money laundering and assistance network.
Additionally, lawsuits can increase the attackers' monetization costs. Even if all funds cannot be immediately recovered, continuously tagging addresses, pushing for account investigations, and holding accomplices accountable will compress the space for stolen assets to enter compliant financial systems.
Finally, Bybit also needs to restore market trust. For trading platforms that center on custodial user assets, the ability to handle incidents after an attack is part of their commercial reputation. Continuous tracking, industry collaboration, and federal lawsuits convey the message to users, regulators, and partners: the platform will not simply write off losses but will continue to pursue recovery through technical and legal means.
Therefore, evaluating whether this lawsuit is successful cannot solely depend on whether Bybit can recover the entire $1.5 billion. A more reasonable standard includes: how much actual assets were recovered and frozen, how many anonymous controllers were identified, whether key platform records were obtained, whether new money laundering nodes were discovered, whether other jurisdictions were prompted to take parallel measures, and whether a reusable digital asset recovery pathway was established.
From this perspective, the most important outcome of this case may not be a massive default judgment against North Korea, but whether Bybit can gradually transform a portion of assets that originally only had on-chain coordinates and no real identity into properties that can be actually controlled, supported by evidence, guaranteed by judicial measures, and ultimately returned to Bybit.
For other Web3 companies, the most noteworthy aspect of this case is not just how much Bybit can ultimately recover, but whether the company is already equipped to swiftly convert on-chain data into evidence, freezing measures, and cross-border recovery actions when an attack truly occurs.
What Insights Does the Bybit Case Bring to Web3 Companies?
The Bybit case has obvious particularity: a loss of $1.5 billion, an attack attributed by the U.S. government to state-sponsored cyber actors from North Korea, a federal lawsuit in the U.S., RICO claims, and asset tracking spanning multiple blockchains and jurisdictions are not scenarios that every Web3 company will encounter.
However, the risk management logic revealed by this case has universal significance: companies should establish a mechanism that can rapidly convert on-chain anomalies into evidence, freezing measures, and cross-border recovery actions before an attack occurs.
Once funds leave the company wallet, the incident is no longer just a technical security issue; it simultaneously involves asset ownership, evidence preservation, platform collaboration, sanctions screening, criminal reporting, and cross-border litigation. If the technical, legal, and compliance teams continue to act sequentially at their own pace, the company may miss the most critical asset preservation window before internal processes are completed.
1. Upgrading from Technical Response to Joint Response
The first reaction of Web3 companies after an attack is usually to suspend withdrawals, fix vulnerabilities, verify losses, and issue announcements. These measures can prevent further losses but do not address how to recover the already stolen assets.
A complete incident response should initiate multiple workstreams simultaneously: the technical team confirms the attack vector and saves system logs; the wallet and finance teams verify assets, permissions, and accounting impacts; on-chain analysts track and tag funds; lawyers assess ownership, evidence, and freezing pathways; the compliance team conducts sanctions and anti-money laundering evaluations; and management is responsible for deciding on major matters such as service suspension, reporting to authorities, external disclosures, and cross-border recovery.
These tasks cannot simply be arranged sequentially. For instance, the technical team may overwrite critical logs while fixing the system; if the public relations team prematurely discloses involved addresses and tracking paths, it may alert attackers to move assets; if the business team closes accounts without saving data, it could affect subsequent investigations. The significance of a joint response is to ensure all teams advance in sync around the same factual record and action priorities.
Companies should also establish an emergency authorization mechanism in advance. Who has the authority to suspend wallet operations, who can send freeze requests to trading platforms, who is responsible for contacting law enforcement and external lawyers, and at what loss threshold management or the board needs to intervene should not be discussed step by step after an attack occurs.
External communication should also be included in the joint response. Announcements need to distinguish between confirmed facts and pending investigations, government or third-party attributions and final court determinations, recovered assets and those only temporarily frozen. Insufficient disclosure may exacerbate market suspicion, while excessive disclosure may expose investigation paths and freezing plans.
For companies insured against cybersecurity, crime, or digital asset risks, timely notification to insurers is essential, along with clarifying evidence requirements, litigation cost responsibilities, subrogation claims, and recovery fund distribution mechanisms in advance. Otherwise, delays or improper statements during the disposal process may further impact insurance claims.
2. Seizing the Asset Recovery Window After an Attack
The most critical time for recovering digital assets is often not when the court makes a final judgment, but in the initial hours and days following an attack. The sooner tracking is initiated, the easier it is for companies to establish a complete initial flow of funds, identify when assets enter trading platforms or other centralized nodes, and submit freeze requests before the funds are repeatedly split, cross-chain, or mixed.
Therefore, companies should not wait until after an incident to temporarily study a series of fundamental issues: which on-chain analysis agency to contact, which entity within the group should report and assert rights, who is responsible for liaising with trading platforms and custodians, in which jurisdiction emergency measures can be applied, and whether to notify users, regulators, and insurers.
These resources and decision paths should be written into the incident response plan in advance. At a minimum, a contact network for key trading platforms, custodians, stablecoin issuers, on-chain analysis agencies, law enforcement, and external lawyers should be prepared, along with a template for freeze requests that can be quickly filled out and sent.
An effective emergency freeze request typically needs to specify the victim entity, the event timeline, the original transaction hash, involved addresses, key funding paths, and specific transaction information regarding assets entering relevant platforms. Companies should also request that platforms preserve KYC, login IPs, devices, transaction, and withdrawal records, and confirm whether the platform requires police letters, court orders, or other materials to extend the freeze period.
The primary goal of the first notification is to make the platform aware of the risk, temporarily maintain the status quo, and preserve potentially lost evidence. Only by securing this window can subsequent reporting, litigation, and return procedures have a realistic target.
3. Establishing an On-Chain Evidence System for Court
Companies cannot wait until litigation begins to convert on-chain fund flows into evidence. Original transaction data, acquisition times, block heights, transaction hashes, withdrawal personnel, analysis tools, and review processes should be comprehensively recorded from the onset of the incident. It is also essential to clearly distinguish between objective facts, professional inferences, and risk ratings. For example, "100 ETH transferred from address A to address B" is an on-chain fact; "addresses A and C may be controlled by the same entity" is an analytical conclusion; "this entity belongs to the Lazarus Group" requires government attribution or off-chain evidence support.
When hiring on-chain analysis agencies, companies should also confirm whether they can preserve underlying data, explain clustering methods and error ranges, and provide expert reports or cooperate with court examinations when necessary.
Companies should also clarify the legal ownership of assets in advance. In large Web3 groups, brand operations, website services, wallet management, customer contracts, and accounting records may belong to different companies. After an attack, courts and trading platforms will further inquire: who controls the stolen wallet, whether the assets belong to the company or users, which entity bears the obligation to pay, who has suffered legal losses, and who has the right to report, apply for freezing, and initiate litigation.
If companies cannot clearly answer these questions in their daily operations, even if the on-chain fund paths are very clear, they may delay recovery due to unclear plaintiff entities, asset ownership, and loss attribution.
The on-chain evidence system must ultimately connect both ends: one end is transaction hashes, wallet addresses, and funding paths, while the other end is company entities, customer contracts, accounting records, and asset rights. Only when both correspond can the on-chain "visible money" become property that the court can handle.
4. Pre-Draw Asset Control Maps
Companies should pre-record who holds the private keys, account permissions, smart contract management rights, or fiat currency exports for different assets, and based on this, draw asset control maps.
This map should at least cover issuers, custody methods, wallet permissions, redemption paths, emergency functions of contracts, major trading venues, relevant judicial jurisdictions, and emergency contacts, and quickly answer after an attack: where the assets are located, who can technically prevent their movement, and which court or regulatory agency can influence that entity.
For DeFi projects, specific examination of whether contracts can be upgraded, whether there are administrator keys, pause functions, or governance multi-signatures, and who controls the front-end, oracles, and other infrastructure is also necessary. The asset control map does not require all protocols to set freezing functions but helps companies accurately identify real control points.
5. Establishing Layered Freezing, Sanction Responses, and Cross-Border Recovery Mechanisms
Digital assets can pass through multiple platforms in minutes across several countries. A single court, law enforcement agency, or lawyer team is unlikely to complete all recovery work. Companies need to layer recovery targets based on the nodes where funds are located, the degree of control, and the expected recovery value.
The first layer consists of assets with larger amounts, clear funding paths, and that have already entered compliant trading platforms or custodians. These assets should be prioritized for freeze and evidence preservation requests, and quickly assessed for the need to report, apply for emergency injunctions, or take local judicial measures.
The second layer includes assets still in non-custodial wallets, temporarily uncontrollable but highly traceable. Companies can continuously monitor addresses and immediately escalate actions when assets enter trading platforms, stablecoin systems, or fiat currency exits.
The third layer consists of smaller amounts that have been severely mixed or entered non-cooperative judicial jurisdictions. These assets can still retain tracking records, but it is necessary to assess whether it is worth taking separate legal action based on investigation costs, litigation expenses, and enforcement probabilities.
Sanction screening should also adopt risk grading, rather than just checking whether recharge addresses directly appear on the OFAC list. For situations where companies or related transactions are subject to U.S. sanction rules, if assets directly hit wallet addresses on the sanction list, or there is sufficient evidence indicating they are owned or controlled by sanctioned entities, blocking and reporting measures should be taken according to applicable rules; for transactions with short funding paths or other high correlations with high-risk addresses, processing can be suspended and investigations strengthened; for general historical contacts that are distant and lack other risk indicators, permanent freezing should not be based solely on on-chain associations.
In terms of cross-border recovery, companies should identify key judicial jurisdictions in advance around commonly used trading platforms, custodians, stablecoin issuers, and fiat currency exits, and understand whether local laws recognize the property attributes of digital assets, whether lawsuits can be filed against anonymous defendants, whether non-notice freezing measures can be applied, whether platforms can be required to disclose KYC information, and how to recognize and enforce foreign court orders.
Of course, this does not mean that every attack requires litigation on a global scale. Reasonable recovery targets are not about recovering every token at any cost, but rather prioritizing resources within limited budgets and time to control assets that are more likely to be recovered, of larger amounts, and with relatively clear legal paths.
Ultimately, companies need to form a digital asset recovery manual that can be directly initiated. This should at least cover lists of assets, wallets, and permissions, internal incident grading and emergency authorization mechanisms, standards for preserving on-chain data and system logs, external agency contact networks, templates for freeze requests and evidence attachments, sanctions and anti-money laundering risk grading rules, emergency measures for key judicial jurisdictions, and communication mechanisms with users, regulators, insurers, and the media.
The most important lesson from the Bybit case for Web3 companies is not the triple damages under RICO, nor whether U.S. courts can ultimately judge North Korea, but a complete legal framework for asset recovery—only by designing a unified system for technical tracking, evidence preservation, asset protection, sanctions compliance, and cross-border enforcement can companies avoid merely watching funds move on-chain and regain opportunities to take action each time assets enter centralized platforms, expose real identities, or approach fiat currency exits.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Strikes on Iran: What Impact on Bitcoin, Stocks, Oil, and Gold?

Why is Grouping LP Better than PvP under Robinhood Chain's High Fees?

Bitcoin leads Ethereum and Solana in decentralization, ARK finds

NVIDIA, Tesla or AMD? 10 Stocks to Watch in WEEX Stock Spot 2.0

Can On-Chain Rollbacks Recover Stolen Assets?

South Korea's Cryptocurrency Market: Latest Guide for the Second Half of 2026

Solana's Nakamoto coefficient at 19, higher than Bitcoin and Ethereum

Important News from Last Night and This Morning (September 1 - September 2)

Strategy Opposes MSCI Index Exclusion Proposal

Guatemala Implements Anti-Money Laundering Control for Cryptocurrency Exchanges Starting September 2026

DEX vs CEX: Decentralized Exchanges Hit a Record

US PMI Falls in August: What This Means for Interest Rates and Investments

The number of payments on XRPL has reached 658,600

HINC Launches Loopscale, Qualified Investors Can Stake to Borrow USDG

Ireland: The new tax-free investment account closes its doors to crypto

Blockworks Discloses Employees' Personal Crypto Assets and Conflicts of Interest

Bitcoin: The Number of Addresses Holding Over One Million Dollars Soars in August

Latest Holdings of AllianceDAO and FOMO Founders: 70% in US Stocks, Only BTC and Zcash in Crypto

From NET to CRWD: Is Money Flowing into Cybersecurity Companies in the AI Second Half?

LeapNode Secures Investment from DraperDragon to Build AI-Web3 Infrastructure

Latest Non-Farm Payroll Forecast: Job Growth May Slow, Fed Faces Complex Choices

$40 Trillion U.S. Debt Alarm Sounds, BlackRock Unexpectedly Bullish on Bitcoin and Gold

Russia opens regulated crypto trading as new law takes effect

What is liquidation? The trading minute

Crypto: The Clarity Act has only a 13% chance of being adopted

KuCoin Ventures Weekly Report: Waller Strengthens Rate Hike Expectations, ETF Funds Significantly Flow Back, RWA Narrative and Attention Assets Reshape the Crypto Market

Every Major Correspondent Bank Will Support Stablecoin Tracks in Ten Years

IOSG: Reg CA is not the switch for a bull market in token issuance, but a 'graduation exam' for existing tokens

SEC and CFTC Delay Hedge Fund Disclosure Requirements to July 1








