NewsCryptoBybit Sues North Korea and Lazarus Group Over $1.5 Billion Hack, Secures Court Order Freezing Stolen Assets

Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Hack, Secures Court Order Freezing Stolen Assets

Author: Decrypt·

Key Takeaways

  • Bybit filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group over the $1.5 billion theft that occurred in February 2025.
  • A federal judge granted a preliminary injunction barring the transfer of identified stolen assets and determined that Bybit is likely to succeed on the merits of its case.
  • The attackers drained approximately 500,000 ETH from a Bybit cold wallet by manipulating a signing interface to display correct destination addresses while altering the wallet's underlying logic.
  • Approximately $48.4 million has been recovered and $30.5 million has been frozen across more than 28 exchanges and custodians, together representing roughly 5% of the total stolen amount.
  • North Korea's designation as a state sponsor of terrorism provides a legal avenue under certain U.S. statutes for Bybit to pursue claims against the sovereign nation in federal court.
Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Hack, Secures Court Order Freezing Stolen Assets

Cryptocurrency exchange Bybit has filed a civil lawsuit against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau, and the Lazarus Group in the U.S. District Court for the District of Columbia over the theft of $1.5 billion from the exchange in February 2025. Unidentified individuals and entities holding or moving the stolen funds are named as John Doe defendants.

A judge granted a preliminary injunction barring the transfer or dissipation of identified stolen assets while the case proceeds, and found Bybit likely to succeed on the merits, the exchange said on Friday. In granting an earlier temporary restraining order, the court characterized the theft as among the biggest the crypto industry has seen.

The Lazarus Group is the state-linked hacking outfit that U.S. authorities blame for the attack. The group has been tied to a string of major cryptocurrency heists, including the $620 million Ronin Network breach in 2022, and United Nations Panel of Experts reports have documented Pyongyang's growing reliance on cryptocurrency theft to circumvent international sanctions and fund weapons programs.

"It was an attack on trust in our industry," Bybit co-founder and CEO Ben Zhou said in a statement Thursday, adding that the exchange had worked with investigators, exchanges, regulators, and law enforcement before turning to the courts.

Bybit said that approximately $48.4 million has been recovered and about $30.5 million frozen across more than 28 exchanges and custodians, together representing roughly 5% of the total amount stolen.

How the Attack Unfolded

Attackers drained roughly 500,000 ETH from a Bybit cold wallet in February 2025 after manipulating a signing interface that displayed the correct destination address to approvers while altering the wallet's underlying logic. Zhou said at the time that the exchange remained solvent and could cover the loss.

By April, Zhou reported that approximately 69% of the proceeds remained traceable, 28% had gone dark, and 4% had been frozen. Most of the stolen Ethereum had been converted to Bitcoin via Thorchain and routed through mixers including Wasabi, Tornado Cash, and Railgun. Cross-chain swaps through decentralized protocols and privacy mixers have become a standard laundering pathway for stolen crypto, fragmenting funds across multiple blockchains and making recovery dependent on cooperation from venues scattered across jurisdictions.

In June, Greek authorities traced a portion of the funds to a wallet on a domestic exchange and issued a seizure order.

Ongoing Cooperation

Bybit said the civil case runs alongside criminal investigations and that it continues to share blockchain intelligence with agencies including the FBI. The exchange pointed to Germany's takedown of the eXch exchange and the disruption of Cryptomixer.io by German and Swiss authorities as evidence of that cooperation.

Suing a sovereign nation in U.S. federal court for cryptocurrency theft is uncommon, though the DPRK's designation as a state sponsor of terrorism creates a legal avenue for such claims under certain U.S. statutes.

The proceedings are ongoing.