Bybit Sues North Korea Over $1.5B Lazarus Group Crypto Hack in U.S. Court

Daily Feed
Bybit Sues North Korea Over $1.5B Lazarus Group Crypto Hack in U.S. Court

Bybit has taken its $1.5 billion hack to U.S. federal court, naming North Korea, its Reconnaissance General Bureau, and the Lazarus Group in a civil case tied to the largest recorded crypto theft.

  • Bybit filed in U.S. District Court for the District of Columbia
  • The case centers on the Feb. 21, 2025 theft of more than 400, 000 ETH and staked ETH
  • A judge granted a preliminary injunction freezing certain identified assets
  • The civil suit runs alongside separate U.S. criminal investigations

Bybit filed the lawsuit after a Feb. 21, 2025 breach drained more than 400, 000 Ether and staked Ether from the exchange. At the time, the stolen assets were valued at about $1.5 billion, and the attack has widely been described as the largest recorded cryptocurrency theft, as covered in North Korea’s Lazarus Group Orchestrates Record $1.5B Bybit.

The legal move is plain enough, even if the recovery path is anything but. Bybit is trying to recover stolen assets and pin liability on the parties it says were behind the heist, while U.S. authorities continue their own criminal and sanctions-related work in parallel. In crypto crime, the money can move faster than the paperwork, which is exactly why Bybit sues North Korea over $1.5B Lazarus hack matters.

The defendants named in the filing are North Korea, the Reconnaissance General Bureau, and the Lazarus Group. The FBI attributed the attack to North Korea shortly after the breach and said U.S. authorities track the actors under the name TraderTraitor. That label matters because it ties the laundering operation to a broader pattern of North Korea-linked cyber theft, not just a one-off exchange exploit.

Ben Zhou, Bybit co-founder and CEO, said the exchange had worked with investigators, regulators, other trading platforms and law enforcement agencies since the attack.

“Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable, ”

Bybit’s lawsuit is only part of the response. A federal judge also issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants. A preliminary injunction is a temporary court order. It does not decide who ultimately owns the funds, but it can stop assets from being transferred, sold or otherwise moved while the case proceeds.

That kind of order is one of the few practical tools available when stolen crypto is already in motion. Once funds are split across wallets, bridged between chains or pushed through laundering services, the trail gets ugly fast. The point of the injunction is to lock down what can still be identified before it disappears into the usual swamp of hops, swaps and deniability, much like the laundering trail described in Lazarus Group’s $1.4B Bybit Hack: 62, 200 ETH Moved, Full.

That also explains why the FBI urged exchanges, validators and blockchain firms to block transactions tied to addresses identified in the laundering operation. The agency’s message was blunt: if you see these funds, don’t pretend they’re somebody else’s problem.

Bybit said the civil case is separate from ongoing U.S. criminal investigations. That distinction matters. Civil litigation is about recovery and liability. Criminal probes are about prosecution, seizures and enforcement. They can overlap, but they do not move at the same speed, and they do not always end with the same outcome.

The tracing picture has also shifted over time. In March 2025, crypto.news reported that 88.87% of the stolen funds remained traceable, 7.59% had gone dark, and 3.54% had been frozen. By April 2025, Zhou said 27.6% of the stolen funds could no longer be tracked. Those numbers show how quickly the picture degrades once laundering tools get involved.

For readers less familiar with the jargon: cross-chain protocols move assets between different blockchains, which can make the trail harder to follow when funds jump networks. Crypto mixers blend transaction flows to obscure where assets came from and where they ended up. Neither tool is automatically criminal, but both are very handy when the goal is to make stolen funds harder to trace. North Korea’s interest in abusing that stack has been documented before, including in North Korea’s Lazarus Group Targets Crypto Devs via npm.

Bybit also had to keep its own business functioning after the breach. The exchange covered the shortfall through Ether purchases, loans and deposits from industry counterparties so customer withdrawals could continue. That is the part of these incidents that gets lost in the headline rush: the damage is not just the missing assets, but the chaos an exchange must absorb to stop users from being collateral damage.

The North Korea angle is not a side note. Chainalysis data previously covered by crypto.news estimated North Korean groups stole $2.02 billion in cryptocurrency during 2025, with the Bybit attack accounting for most of that amount. The country’s estimated cumulative crypto theft reached about $6.75 billion. That is an ugly record, and it shows why the industry keeps running into the same adversary: state-linked cyber theft is a revenue model, not a hobby.

There is also a broader lesson here for the crypto crowd that likes to pretend all risk is “market noise.” The same open, permissionless plumbing that makes digital assets useful can also be abused at industrial scale when the surrounding ecosystem is sloppy, fragmented, or slow to act. Bitcoin’s base layer is not built for the kind of laundering games that flourish across the wider multichain stack, but bridges, tokens, mixers and weak compliance are very much part of the problem. Blaming the tech for every crime is lazy. Pretending the abuse surface is tiny is even dumber.

Bybit is now seeking permanent relief and trying to recover the assets covered by the injunction. The court has not issued a final judgment yet, so the case is far from over. The practical questions are the ones that always matter in crypto theft cases: how much remains identifiable, who is holding it, and whether those entities will actually comply when the lawyers come knocking.

And yes, the hard truth is that blockchain tracing is useful but not magical. It can help map movement. It cannot, by itself, force thieves to hand back the funds once they have been split, bridged, mixed and dispersed. That’s the ugly reality behind the clean dashboards.

Key takeaways

  • Why did Bybit sue North Korea?
    Bybit is trying to recover losses from the Feb. 21, 2025 hack and hold the alleged North Korea-linked actors accountable in U.S. court.

  • What was stolen?
    More than 400, 000 Ether and staked Ether, worth about $1.5 billion at the time.

  • What does the injunction do?
    It temporarily freezes certain identified assets linked to the hack so they cannot be transferred or sold while the case continues.

  • How were the funds obscured?
    According to the reporting, Lazarus-linked wallets used cross-chain protocols and crypto mixers to make tracing harder.

  • Has Bybit recovered everything?
    No. Some assets were frozen, some remained traceable, and more of the trail went dark as laundering progressed.

  • Is the case finished?
    No final judgment has been issued, and recovery still depends on tracing, enforcement and compliance with court orders.

The takeaway is simple: crypto can move value without permission, but that same freedom is exactly what thieves and state operators try to exploit. The industry can either build harder defenses and back them with real enforcement, or keep acting shocked when the same wallets keep showing up in the wreckage.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog