NewsCryptoBybit Sues North Korea and Lazarus Group Over $1.5 Billion Crypto Theft, Secures Preliminary Injunction

Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Crypto Theft, Secures Preliminary Injunction

Author: Cryptopolitan·

Key Takeaways

  • Bybit filed a civil complaint in the US District Court for the District of Columbia naming North Korea, its Reconnaissance General Bureau, the Lazarus Group, and unidentified wallet holders as defendants.
  • The $1.5 billion theft from Bybit's Ethereum cold wallet surpasses the previous record $620 million Ronin Network hack of 2022, an incident also attributed to North Korean hackers.
  • Approximately $48.4 million has been recovered and an additional $30.5 million frozen, while 90.2% of the stolen assets had been laundered beyond traceability through mixers, cross-chain bridges, and over-the-counter dealers.
  • Bybit is seeking the return of stolen funds along with punitive and treble damages under the US Racketeer Influenced and Corrupt Organizations Act (RICO), a statute typically associated with organized crime prosecutions.
  • German authorities dismantled the exchange eXch and, together with Swiss authorities, disrupted Cryptomixer.io, both of which were used to launder the stolen proceeds.
Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Crypto Theft, Secures Preliminary Injunction

Bybit has filed a civil lawsuit in a US court against North Korea and the Lazarus Group over the February 2025 theft of $1.5 billion in cryptocurrency. The exchange has already secured a preliminary injunction freezing stolen funds that investigators can still trace. The theft, which targeted Bybit's Ethereum cold wallet, ranks as the largest cryptocurrency heist on record, surpassing the $620 million stolen from the Ronin Network in 2022, an incident also attributed to North Korean hackers.

Details of the Complaint

The complaint was filed in the US District Court for the District of Columbia and names the Democratic People's Republic of Korea, its Reconnaissance General Bureau, and the Lazarus Group as defendants, according to Bybit's press statement. Unidentified individuals and entities holding or moving the stolen funds are also named as John Doe defendants.

Suing a sanctioned state such as North Korea presents enforcement challenges, as there is no mechanism to compel compliance with any judgment. Bybit addressed this by including anonymous wallet holders and intermediaries as defendants, creating a legal pathway to identify them and recover traceable assets. The Lazarus Group, a North Korean state-sponsored hacking unit designated by the US Treasury's Office of Foreign Assets Control, has been linked to a string of major crypto heists in recent years, and the United Nations has reported that Pyongyang uses stolen digital assets to fund its weapons of mass destruction programs.

Bybit stated that the court found "Bybit has demonstrated a likelihood of success on the merits." The court also described the incident as "one of the largest cryptocurrency thefts in history" when granting a temporary restraining order.

Ben Zhou, Bybit's co-founder and CEO, described the incident as an industry-wide concern, stating: "The Lazarus attack wasn't just an attack on Bybit. It was an attack on trust in our industry." He added that the exchange has collaborated "with investigators, exchanges, regulators, law enforcement, and now the courts."

Recovery Efforts

According to Bybit, approximately $48.4 million in stolen assets has been recovered, and an additional $30.5 million has been frozen across more than 28 exchanges and custodians pending further action. The exchange acknowledged that these amounts represent a small fraction of the total $1.5 billion stolen.

In its June filing, Bybit reported that 90.2% of the stolen assets had gone dark after being laundered through mixers, cross-chain bridges, and over-the-counter dealers. Only 9.8% was traced to identifiable wallets, with roughly $75.5 million frozen or recovered at that time. Zhou had previously stated that close to 69% of the funds remained traceable, but subsequent filings indicate that the window for recovery has been closing rapidly. The speed at which the funds were dispersed reflects tactics documented by blockchain analytics firms, who have tracked North Korean operators' increasing use of automated laundering pipelines to obscure fund trails within days of a breach.

Laundering Infrastructure and Legal Timeline

The lawsuit represents the culmination of a sustained legal effort. According to unsealed court records, Bybit initially filed under seal on June 18, obtained a temporary restraining order and expedited discovery on June 19, had the order renewed on July 16, and won a partial preliminary injunction on July 30.

The complaint seeks the return of the stolen funds along with punitive and treble damages under the US Racketeer Influenced and Corrupt Organizations Act (RICO). The deployment of RICO, a statute more commonly associated with organized crime prosecutions, signals an expanding legal toolkit for pursuing state-sponsored crypto theft, where criminal enforcement alone has often proven insufficient.

Portions of the recovery resulted from law enforcement actions targeting the laundering infrastructure. Bybit credited German authorities with dismantling the exchange eXch and both German and Swiss authorities with disrupting the service Cryptomixer.io, both of which were used to move illicit proceeds. eXch had been accused of enabling the hackers to cash out, with more than $90 million funneled through the platform in the weeks following the breach.

The FBI publicly attributed the Bybit theft to North Korea on February 26, 2025, designating the activity under the label "TraderTraitor" and warning that the perpetrators were converting stolen Ether to Bitcoin across thousands of addresses.

Bybit stated that its civil case proceeds in parallel with ongoing criminal investigations and that it continues to share blockchain intelligence with agencies including the FBI.