Bybit Sues North Korea and Lazarus Group Over $1.5 Billion Crypto Hack, Secures Asset Freeze
Key Takeaways
- β’Bybit filed a lawsuit against North Korea and the Lazarus Group on August 7, 2026, approximately 18 months after the February 2025 breach that resulted in a $1.5 billion cryptocurrency theft.
- β’The FBI attributed the hack to North Korean cyber actors in a public service announcement dated February 26, 2025, providing official law-enforcement corroboration of the exchange's claims.
- β’Bybit has already obtained a judicial asset freeze, shifting the focus from identifying suspect wallets to preserving funds for potential recovery claims.
- β’Chainalysis linked the attack to North Korea and reported that asset-seizure efforts became a central component of the recovery response beyond standard transaction tracing.
- β’United Nations expert panels have repeatedly documented that North Korea uses stolen cryptocurrency to finance its weapons programs, contextualizing the case within a broader international security landscape.

Bybit has filed a lawsuit against North Korea and the Lazarus Group in connection with a $1.5 billion cryptocurrency theft, escalating the largest known exchange hack on record into a formal legal battle over accountability and asset recovery. The Lazarus Group is North Korea's primary state-sponsored cyber-espionage unit, previously linked by U.S. authorities to billions of dollars in stolen cryptocurrency including the $620 million Ronin Bridge theft in 2022.
According to CoinDesk, Bybit initiated the legal action on Aug. 7, 2026, roughly 18 months after the February 2025 breach, and has already secured an asset freeze through the courts. The exchange alleges that North Korea and the Lazarus Group were responsible for carrying out the theft and is now seeking to lock down assets that may still be reachable.
Official Law-Enforcement Backing
The allegations carry substantial official support. A FBI public service announcement dated Feb. 26, 2025 attributed the Bybit theft to North Korean cyber actors and published Ethereum addresses linked to the laundering effort. This provides law-enforcement corroboration that extends well beyond the exchange's own assertions.
Bybit has maintained a public security incident timeline documenting the breach and the company's response.
Chainalysis Findings
Chainalysis tied the attack to North Korea in its February 2025 analysis, establishing the incident as more than a routine exchange breach. The blockchain analytics firm later reported that frozen funds and asset-seizure efforts had become a central component of the recovery response, noting that efforts had moved beyond simple transaction tracing toward actively preserving assets for potential claims.
International and Policy Dimensions
The cross-border nature of the case underscores how stolen cryptocurrency can move through numerous wallets and jurisdictions before recovery teams can intervene. When the alleged perpetrator is state-linked, exchange security becomes both an international enforcement issue and a customer-protection concern. United Nations panels of experts have repeatedly documented that North Korea uses stolen cryptocurrency to fund its weapons programs, making cases like Bybit's part of a broader security landscape rather than an isolated incident.
North Korea-linked crypto theft has drawn broader policy attention. As previously reported, G7 leaders urged joint action on North Korean cryptocurrency theft.
The legal action also comes as Bybit continues to expand its broader business operations, including securing an Austrian EMI license for EU payments.
Recovery Outlook
The FBI alert and the two Chainalysis reports converge on a key practical finding: early wallet tagging, rapid coordination among exchanges and authorities, and timely asset freezes can materially improve recovery prospects even following a major theft. CoinDesk's report that Bybit secured a judicial asset freeze suggests the focus has shifted from merely identifying suspect wallets to preserving funds for potential claims. Suing a nation-state presents an unusual legal strategy, but securing a freeze order establishes a formal claim pathway that could influence how courts and exchanges handle state-linked crypto theft going forward.