Bybit v. North Korea: How to convert on-chain tracking into asset control

CN
2 hours ago
Three practical issues must first be resolved: how to initiate a lawsuit without knowing the defendant's name, how to preserve assets before the attacker learns of the lawsuit, and how to ensure court orders have real effects through trading platforms, custodians, and sanction systems.

Written by: Zhang Qianwen

The previous article discussed why Bybit chose RICO, as well as how an overseas digital asset attack entered the United States federal court. However, entering the court is only the starting point for recovery. With the attacker’s identity unknown and assets still circulating on the chain, even if the court is willing to intervene, three practical issues must first be resolved: how to initiate a lawsuit without knowing the defendant's name, how to preserve assets before the attacker learns of the lawsuit, and how to ensure court orders have real effects through trading platforms, custodians, and sanction systems.

IV. How Anonymous Defendants Enter Lawsuits: John Doe, Identity Investigation, and Alternative Service of Process

Traditional litigation usually first identifies the defendant and then completes the prosecution and service of process. However, in digital asset cases, victims can often see assets on the chain but do not know who controls the wallets—

Wallet addresses do not display the names, nationalities, or contact information of their controllers. An address may belong to an attacker, a collection wallet of a trading platform, a custodial service address, an OTC trader's trading address, or even just an ordinary user who has conducted normal transactions involving the funds in question. If one must wait until all the identities behind the address holders are ascertained before filing a lawsuit, the stolen assets may have already been further split, transferred across chains, or cashed out.

The John Doe mechanism provides an exit for this dilemma: it allows lawsuits to be initiated when the defendant's identity is unknown.

1. John Doe: Reserving Legal Standing for Anonymous Parties

"John Doe" is the term used in U.S. litigation for defendants whose identities are temporarily unknown, allowing plaintiffs to reserve legal standing for relevant parties when they possess partial behavioral and asset clues but cannot confirm a true name at the moment. This arrangement changes the sequence of litigation in digital asset cases: Bybit does not need to wait until all controllers behind every address are identified to take action but can first initiate cases with existing on-chain evidence and subsequently replace anonymous defendants with real names or add named defendants based on information obtained later.

Of course, it does not mean that plaintiffs can sue any unknown party without any clues; plaintiffs usually need to explain to the court: that there is indeed a party that implemented the relevant actions or controlled the relevant property; that its identity cannot currently be determined through reasonable investigation; that the plaintiff possesses sufficient information to identify its actions, accounts, or property; and that as the litigation progresses, this identity is likely to be confirmed through the civil discovery process.

In the Bybit case, the anonymous defendants are primarily identified by wallet addresses and the flow of funds. Bybit temporarily cannot tell the court, "What is the defendant's name," but can demonstrate which addresses received or transferred the stolen assets and why these addresses may be related to theft or money laundering activities. This makes wallet addresses a temporary "identity coordinate": they cannot replace the true identity of the defendants but can help Bybit define the investigative targets, describe relevant behaviors and assets, and provide a starting point for subsequent identity investigations and preservation applications.

2. From Wallet Addresses to Real Identities: How Anonymous Defendants Are Identified

Public blockchain records can show transaction times, asset quantities, incoming and outgoing addresses, and fund transfer paths, but they do not directly reveal the individuals or institutions behind the addresses. To trace the real identity of John Doe, Bybit still needs to complete the transformation from "wallet address" to "real entity." This process can be roughly divided into three steps:

The first step is on-chain analysis. Based on the source of funds, transaction times, gas fee payment addresses, the methods of fund splitting, cross-chain paths, and historical interaction relationships, it assesses whether multiple wallets could be controlled by the same party and identify recurring transaction patterns. For example, if multiple addresses receive funds around the same time, use gas fees from the same source, split assets in similar proportions, and concentrate funds into the same platform account, this may indicate a common control relationship among these addresses. However, this analysis typically provides only investigative leads, not final identity conclusions.

The second step is to search for centralized nodes. When funds enter centralized exchanges, custodial platforms, stablecoin issuance systems, or fiat exchange channels, anonymous addresses may begin to connect with real identities. These institutions may hold customer KYC data, login IPs, device information, withdrawal addresses, bank accounts, transaction records, and internal risk investigation results.

Of course, this information is usually subject to contractual, privacy, and data protection obligations, meaning that relevant institutions may not be able to disclose it directly based solely on a letter from Bybit, especially when information crosses different jurisdictions, requiring subpoenas, requests for judicial assistance, or other formal legal bases.

The third step is to use the civil discovery process to request information. Once the case is initiated, Bybit can, if it meets legal requirements, apply for subpoenas or other investigative orders to retrieve information from third parties holding relevant data and then compare and cross-verify platform account information, login data, and fund records with on-chain addresses.

This forms a relatively complete investigative path: determining the flow of funds through on-chain analysis, discovering real identities via centralized institutions' records, and connecting the two through court procedures.

3. The Evidence Threshold to Cross from Identity Identification to Liability Determination

Even if Bybit identifies the actual controller of a wallet through the aforementioned path, it cannot simply conclude that this person is a member of Lazarus or involved in the criminal network alleged by RICO based merely on the fact that this wallet received the disputed assets; there remains a significant evidentiary distance.

A specific asset entering a given address can have multiple explanations: that address might be directly controlled by an attacker, belong to an intermediary assisting in the transfer of funds; might be a collection wallet for a trading platform or custodial institution, or could merely be an ordinary user that accidentally received the disputed assets during normal transactions; in some cases, funds might briefly pass through an address due to automated execution via a smart contract.

Therefore, the correlation of funds on-chain can primarily only prove how assets move. To translate this correlation into legal liability, Bybit must, at a minimum, prove three levels of issues: first, that the relevant assets indeed originate from this attack; second, that the addresses in question and related transactions can be attributed to a specific entity; third, that this entity was aware of the source of the funds and actively participated in the attack, transfer, concealment, or cash-out activities.

Among these, the source of the assets primarily relies on on-chain tracing; address control needs to be combined with platform account information, login IPs, device information, and other off-chain data; subjective awareness and actual participation usually require a comprehensive judgment based on evidence such as behavioral pattern analyses, for example: whether the entity repeatedly received funds from the same theft event, whether it used evidently evasive patterns for splitting, mixing coins, or cross-chain operations, whether it interacted extensively with known Lazarus addresses, whether it processed assets at a unified pace, and whether communications, remuneration arrangements, or other evidence of knowledge concerning the source of the funds but still assisting in the transfer existed.

This illustrates the boundary of the John Doe mechanism. It allows Bybit to start litigation and investigations even when the defendant's identity is not yet fully clarified but does not reduce its ultimate burden of proof. A wallet address can serve as a lead and procedural identifier for the defendants but cannot directly substitute for proof of the defendant's identity, specific actions, subjective knowledge, and legal liability.

4. The Service of Process Challenge for Anonymous Defendants

Even if Bybit describes the anonymous defendant through wallet addresses, another procedural issue still needs to be solved: how to inform the controller behind the addresses that they have been sued?

Service is not simply about sending out litigation documents; it is to ensure the defendant receives reasonable notification and an opportunity to respond. Without lawful service, any judgment made by the court against an anonymous defendant could be questioned in subsequent proceedings and may affect the recognition and enforcement of the judgment.

Traditional personal service or postal delivery is difficult to apply to defendants only identified by on-chain addresses. In similar digital asset cases, plaintiffs may request the court to approve alternative service methods, such as sending notifications to known email addresses or social media accounts, delivering through internal messaging of the trading platform accounts, publishing litigation documents on designated websites, or sending on-chain messages containing links to the litigation notice to wallet addresses.

In this case, Bybit sent an NFT to the relevant wallet, stating the temporary restraining order, objection deadlines, and providing links to the complaint and court orders. The court recognized that this notice met the procedural requirements for the preliminary injunction stage when approving the preliminary order.

However, this determination must be understood within the context of specific procedural stages. The distinction between "notification" and "service of process" in U.S. courts carries different legal implications at different stages of litigation.

At the preliminary injunction stage, under Rule 65(a)(1) of the Federal Rules of Civil Procedure (Fed. R. Civ. P. 65(a)(1)), the court cannot issue a preliminary injunction without notifying the adverse party. The notification here need not meet the formal service standards outlined in Rule 4, but it must reasonably inform the relevant parties about the proceedings in the specific context and provide them with an opportunity to object. In this case, after Bybit’s notification through the NFT, one of the wallet's controllers raised an objection, indicating that the notice did indeed reach the relevant parties.

When the case further moves to the merits hearing, especially if Bybit hopes to obtain a final judgment in the absence of the defendant, it must satisfy the strict requirements of Fed. R. Civ. P. 4 regarding methods of service. The premise for a default judgment is that the defendant has been lawfully served and still fails to respond, and lawful service must comply with statutory form, verifiability, and defensibility standards. Whether an NFT can independently serve as a method of service before a final judgment requires Bybit to file a separate application and obtain court approval.

Therefore, the procedural value of the NFT in this case should be accurately defined: it addresses how to send procedural notifications to anonymous parties during the emergency preservation phase but has yet to resolve how to complete lawful service in the final judgment stage.

Moreover, the service pathways for different defendants also need to be discussed separately. The aforementioned NFT notice primarily targets anonymous wallet controllers; for North Korea, a foreign state defendant, Bybit must complete service under the progressive procedures specified by Fed. R. Civ. P. 4(j)(1) and FSIA § 1608(a); non-state defendants like Lazarus Group and its members should apply delivery rules such as Fed. R. Civ. P. 4(f)(h) according to their nature and location. In other words, even if the NFT is eventually approved as a method of alternative service for some anonymous defendants, it does not necessarily resolve the service issues for all defendants.

5. The Real-World Boundaries of the John Doe Strategy

The John Doe strategy reserves legal standing for Bybit and gains a time window but cannot eliminate the difficulties of anonymity and cross-border investigations.

If the attacker continues to use non-custodial wallets, peer-to-peer trading, and offshore services that do not implement KYC, Bybit may never be able to confirm their true identity. Additionally, subpoenas issued by U.S. courts may not be able to directly bind all offshore platforms, and Bybit might still need to seek judicial assistance locally and apply the restrictions of data protection, banking secrecy, and evidence rules relevant in those countries.

At the same time, notifying defendants may carry new risks. Once the lawsuit information becomes public, anonymous controllers may quickly split or transfer still traceable assets. Thus, Bybit must resolve an even more urgent timing issue: how to obtain a court asset preservation order before the attacker learns of the lawsuit?

V. The Time Battle for Asset Preservation: Sealed Lawsuits, Emergency Injunctions, and Centralized Nodes

Traditional litigation progresses on a timeline of "days" and "weeks," while on-chain assets move in "seconds" and "minutes." Once the complaint becomes public, wallet controllers can quickly transfer funds into channels that are harder to identify and control.

Therefore, Bybit has adopted a phased asset preservation arrangement: first, initiate a sealed lawsuit to temporarily avoid public disclosure of the complaint, wallet addresses, and investigative pathways, seeking an information and time advantage; then apply for a TRO and preliminary injunction to restrict relevant parties from disposing of identified disputed assets; and finally, leverage trading platforms, custodial institutions, and stablecoin issuers as real control nodes to ensure that court orders can be translated into actual limitations.

1. Public Lawsuits May Expose Tracking and Preservation Targets

After the attack in February 2025, Lazarus and related fund controllers displayed highly specialized asset transfer capabilities. The stolen ETH was quickly split, exchanged, and transferred across chains, aiming to increase tracking difficulties and break free from the control of trading platforms, stablecoin issuers, and law enforcement.

If Bybit publicly discloses the lawsuit before obtaining preservation measures, the complaint and attachments may expose three key pieces of information to the attacker: which wallet addresses have been locked, which funding paths have entered the investigation scope, and which assets are about to face legal restrictions.

This information could serve as a warning for the attacker to transfer assets; they can change addresses, adjust money laundering paths, or transfer funds into services that lack KYC and freezing capabilities. By the time the court completes legal notification, hearings, and rulings, the assets that could have been controlled may have already vanished.

This presents a procedural paradox in digital asset recovery: lawsuits should generally be public and notify defendants, but premature disclosure and notification could ultimately result in a loss of enforceable property in litigation. Bybit must find a balance between procedural legitimacy and the urgency of asset preservation.

2. Utilizing Sealing Procedures to Secure Asset Preservation Windows

U.S. federal court filings are generally open to the public, but if premature disclosure might lead to asset transfer, hinder investigations, or expose sensitive information, parties can request to seal the case or specific materials for a certain period.

Sealing a lawsuit does not mean that the court can conduct secret trials and directly issue final judgments. It is usually just a phased procedural arrangement aimed at temporarily limiting the public disclosure of the complaint, wallet addresses, and investigation paths, allowing the court to review emergency relief applications before the attacker learns of any actions.

Bybit sealed its lawsuit on June 18, 2026, and only after the court took temporary measures and rendered decisions on the preliminary injunction did the relevant case files get partially unsealed on August 6; Bybit then publicly announced the case the next day. This timeline reflects Bybit's strategic focus: first, use the sealed procedure to prevent premature disclosure of investigative information while applying for urgent relief during that time; once the court has taken phased measures, publicly disclose the case and promote broader platform cooperation.

3. Two-Tier Emergency Relief: From TRO to Preliminary Injunction

The urgent relief requested by Bybit primarily includes a temporary restraining order and a preliminary injunction, with each solving different phases of the issue.

A temporary restraining order, or TRO, is primarily used to address extremely urgent situations. If waiting for full notification and a hearing could cause irreparable harm, the court may take short-term measures under strict conditions to maintain the status quo.

In digital asset cases, Bybit needs to explain that assets are continuing to be transferred, and early notification could render the preservation purpose void; if these still identifiable and traceable assets enter uncontrolled channels, its requests for asset recovery and related equitable relief may lose their realistic basis.

The TRO's role is similar to pressing the "pause" button, buying time for the subsequent service, investigations, and hearings. However, it typically has a short duration and cannot replace formal review in the long term.

If Bybit wants the relevant restrictions to continue during the litigation, it must also secure a preliminary injunction. Compared with a TRO, a preliminary injunction may last until the court issues further orders or the case enters substantive hearings; thus, the court generally needs to conduct a more comprehensive review of the plaintiff's potential success on the merits, the presence of irreparable harm, the balance of interests of both parties, and public interest factors.

On July 30, 2026, the court partially approved Bybit's preliminary injunction request, prohibiting related anonymous defendants from transferring, selling, or dissipating identified assets in question.

Of course, whether it is a TRO or a preliminary injunction, the range of assets that the court can restrict has clear boundaries. In principle, the court cannot freeze all of the defendant's properties indefinitely just to secure future monetary damages judgments. Concerns that the defendant may transfer assets or that there will not be enough property available to enforce a monetary judgment usually do not support a blanket asset freeze.

Therefore, Bybit needs to clearly link emergency relief with specific disputed assets, traceable proceeds, recovery requests, or other equitable relief. The injunction should target those assets that can be reasonably identified and related to this attack, rather than all property controlled by anonymous defendants.

4. Court Orders ≠ Technical Freezing: How Injunctions Affect Digital Assets

The Ethereum network does not recognize U.S. court case numbers, nor will it automatically deny transaction packaging due to a federal court order. What courts can constrict is not the blockchain protocol itself but the behavior of relevant parties regarding the disposal of the disputed assets.

According to Fed. R. Civ. P. 65(d)(2), the scope of injunctions includes parties to the case, their agents and employees, and other parties that actively cooperate with them after becoming aware of the injunction. The court can order relevant defendants not to transfer the disputed assets and hold those subject to the injunction accountable if they knowingly assist in the transfer of assets.

Under the aforementioned regulatory scope, trading platforms, custodians, and stablecoin issuers are not automatically bound. Nevertheless, court orders can still serve as important bases for these parties to conduct freezing reviews, preserve information, or take other risk disposal measures based on their user agreements, internal compliance procedures, and local laws.

Regarding the effectiveness of injunctions, whether court orders can truly stop asset flows largely depends on at which node the assets are at that time.

• If ETH remains in a non-custodial wallet controlled by the attacker with the private key, the court can prohibit the relevant defendant from transferring assets but cannot alter blockchain rules or technically prevent them from continuing to sign transactions.

• If the assets have already entered centralized exchanges or custodial institutions, the platform may stop the assets from continuing to flow out by limiting transactions and withdrawals.

• If the disputed assets have been exchanged for stablecoins with address freezing capabilities, the issuer may also restrict the movement or redemption of those tokens when complying with legal and technical conditions.

This demonstrates the critical role of centralized nodes in asset recovery. Attackers may not voluntarily comply with court orders, but during the process of transferring, holding, or cashing out, they will typically interact with trading platforms, custodians, stablecoin issuers, and payment service providers. These parties control accounts, private keys, or tokens, enabling them to convert court’s legal orders into actual measures like account freezes, withdrawal restrictions, data preservation, and risk disposal.

Thus, "freezing digital assets" does not mean stopping the blockchain from processing transactions but means constraining relevant parties through legal orders and leveraging actual nodes that control accounts, private keys, or tokens to prevent assets from continuing to flow out. The federal district court for the District of Columbia provides a legal fulcrum for continuous asset recovery, but not a global passport, as U.S. court injunctions do not necessarily have enforceability in local jurisdictions just because they are sent to offshore platforms. If necessary, Bybit may still need to seek judicial assistance or recognition for relevant orders in other countries or regions, or to regain local asset preservation measures.

VI. Dual-Track Coordination of Sanctions and Litigation

Before Bybit filed the lawsuit, North Korea, the North Korean Reconnaissance General Bureau, and the Lazarus Group were already under the U.S. sanctions system. Since transactions with sanctioned entities have already been severely restricted, why does Bybit still need to initiate a civil lawsuit and request a judicial injunction?

In fact, sanctions and civil litigation address different levels of issues. Sanctions aim at national security and foreign policy, primarily restricting sanctioned entities and their property from entering the financial and commercial systems subject to U.S. jurisdiction; civil litigation, on the other hand, revolves around specific assets in a case, requiring further judgments about where the assets come from, who controls them, what rights Bybit has over them, and what remedies the court can provide.

1. The Functional Boundaries of Sanctions

The economic sanctions imposed by the U.S. on North Korea and related entities are mainly implemented by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC). The related rules can prohibit U.S.-jurisdiction subjects from engaging in transactions with specific targets and require Americans to block any sanctioned property they hold or control.

However, blockchain protocols do not read the OFAC list. As long as attackers still hold the private key, they can sign transactions from non-custodial wallets—sanctions restrict the ability of assets to enter compliant trading platforms, custodial institutions, and fiat export capabilities, but do not technically cancel transfer functions.

Moreover, when attackers frequently change addresses and hide the sources of funds through splitting, cross-chain transfers, mixing, and OTC transactions, platforms must further assess whether "this layer of assets still comes under the control of sanctioned entities." Thus, while sanctions can elevate the circulation and realization difficulty of assets, they cannot solely resolve on-chain identification issues based on lists.

More importantly, sanctions only answer "which transactions are prohibited," not "who ultimately owns the assets": the property cannot be transferred without authorization, but that does not mean it will automatically be returned to Bybit. Whether assets remain traceable to the attack after multiple cross-chain transfers, how much of mixed funds comes from stolen assets, how to distinguish assets after they are mixed with other users' properties, whether third parties unknowingly acquire assets, and whether frozen properties should ultimately be disposed of by the government or returned to victims—these questions have entered the territories of property rights and evidence assessment, which cannot be solely addressed by sanction rules.

2. The Supplementary Function of Civil Litigation: Identifying Assets, Claiming Rights, and Obtaining Remedies

Civil litigation primarily complements the sanctions mechanism in three ways:

First, litigation implements the general risks against sanctioned entities into specific assets related to this attack. OFAC sanctions are generally based on the country, organization, or individual being sanctioned, limiting the property they own or control; Bybit's litigation starts from the assets transferred on February 21, 2025, tracing wallet addresses, platform accounts, and current balances along the on-chain transaction paths.

Second, litigation provides a procedure for Bybit to claim asset rights. Bybit needs to prove a verifiable connection between the relevant assets and this attack, what rights it holds over these assets, and whether they are still recoverable after being exchanged, transferred across chains, or mingled. OFAC's designated sanctions and list information can signal a higher risk concerning relevant subjects or transactions, but they cannot independently prove that specific assets originate from the attack, nor can they substitute for Bybit's proofs regarding asset ownership and recovery requests.

Finally, litigation can provide judicial remedies like asset preservation, data disclosure, cessation of disposition, and final return. Compared to private freezing requests made by Bybit based on industry cooperation, court orders offer clearer procedural bases for obligated parties to take measures and can provide more substantial references for other platforms to conduct internal investigations, preserve information, and assess whether to continue processing relevant assets.

However, civil judgments do not automatically lift sanctions. Even if the court ultimately supports Bybit’s claims for rights, if the assets intended for return belong to property frozen under OFAC rules and the relevant release or transfer actions are restricted by U.S. sanction rules, the court's judgment itself will not automatically unfreeze those assets. Actual returns must still comply with applicable OFAC general licenses or obtain special licenses issued by OFAC. Court judgments address "who has the right to acquire assets," while OFAC permits address "whether those assets can be released or transferred under the sanction framework"; both may need to work together.

If sanctions are likened to a "security gate," they mainly prevent sanctioned entities and their property from entering the compliant financial system; civil litigation goes a step further to clarify the specific assets outside the gate, their origins, ownership, and how they should ultimately be handled.

3. Multiple Risks Are Transmitted to Peripheral Service Networks

North Korea and the Lazarus Group have always been highly isolated from the U.S. financial system. Adding a civil lawsuit or court injunction may not directly change their behaviors. What really might reassess the risks are the peripheral service networks still reliant on the global financial system.

These subjects may include centralized trading platforms and custodians, OTC traders and fiat exchange channels, stablecoin issuers, payment and settlement institutions, banks, and individuals and companies providing support for accounts, identities, or fund transfers.

They may not be located in the U.S., nor may they directly participate in the initial hacking attack, but many still rely on U.S.-dollar settlements, international banking networks, business licenses, investment institutions, or global compliance relationships. When the same funds are targeted by an FBI announcement, OFAC sanctions risk alerts, Bybit tracking notices, and court injunctions simultaneously, continuing to process that assets may impose multiple risks.

The first layer is the sanctions risk. If a platform subject to U.S. sanction rules continues to provide trading, custodial, or transfer services for assets owned or controlled by sanctioned entities, it may trigger relevant prohibitive provisions. OFAC sanctions typically apply strict liability standards, meaning that they do not depend on whether the platform actually knows the source of the assets (of course, in enforcement practice, OFAC usually considers whether the platform received risk alerts, whether it took reasonable compliance measures, whether it voluntarily disclosed and cooperated with investigations, and other factors). Nonetheless, continuing to process relevant assets after receiving clear risk alerts can significantly increase the risk of enforcement actions faced by the platform.

The second layer is the anti-money laundering and licensing risk. If platforms ignore evidently high-risk funding paths, they may be investigated by their local regulatory authorities, and it may also affect their banking relationships and license continuity.

The third layer is civil liability risk. If evidence shows that certain entities continued to knowingly assist in the transfer, concealment, or cashing out of assets after receiving government announcements, victim notifications, or court orders, such facts may be used to support RICO conspiracy, tortious assistance, or other liability claims (of course, merely receiving notifications or handling the disputed assets does not automatically make a platform a member of the criminal network; Bybit still needs to prove actual awareness, level of involvement, and specific behaviors).

Thus, the collaboration between sanctions and litigation primarily may not compel North Korea, already detached from the U.S. financial system, to change behavior, but raises the costs for peripheral service networks to continue processing the assets in question: more platforms may refuse to accept funds, more accounts may enter internal investigations, and subjects who knowingly assist in transferring assets may face higher civil and regulatory risks.

4. Litigation Evidence Supports Sanctions and Enforcement

Sanctions and enforcement records can provide the national attribution and risk context for Bybit’s lawsuit; conversely, new information obtained by Bybit in civil litigation, on-chain investigations, and cross-platform collaborations may also lead to subsequent sanctions or enforcement actions.

Through on-chain tracing and evidence disclosure, Bybit may identify previously undisclosed wallet addresses, trading platform accounts, device information, sources of funds, or real controllers. If this information indicates that certain subjects knowingly assisted Lazarus in transferring or laundering assets for a long time, Bybit can submit the relevant leads to the FBI, U.S. Department of Justice, OFAC, and regulatory and enforcement agencies in other countries.

Relevant agencies may investigate based on their own authority and evidentiary standards to decide whether to add sanctioned targets or associated addresses, propose money laundering or sanction evasion charges, request criminal forfeiture, or take account freezing and licensing regulatory measures against relevant platforms.

This forms a two-way information chain: there are sanctions and government attributions that provide context for Bybit's identification of high-risk subjects and assets; Bybit, through on-chain tracing, platform collaborations, and civil discovery, obtains new evidence that may drive new sanctions, criminal investigations, and asset forfeiture.

Thus, RICO, John Doe, sealed procedures, emergency injunctions, and the sanctions system together constitute a litigation path from liability tracing to asset preservation, forming a closed loop for Bybit's main litigation strategy.

However sophisticated the strategy design, it ultimately returns to a real question: how much of the $1.5 billion in stolen assets, after undergoing long-term splitting, cross-chain transfers, and laundering, can this set of litigation strategies actually recover? Of the funds "visible" on-chain, how much can genuinely be seized, proven, executed, and ultimately returned to Bybit?

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink