Crypto exchange Bybit has sued the North Korean government, North Korea’s Reconnaissance General Bureau (RGB), and the Lazarus Group in the U.S. District Court for the District of Columbia, accusing them of responsibility for the theft of about $1.5 billion in crypto assets in February 2025.

The case is described as the first time a crypto exchange has directly used the U.S. federal court system to pursue civil recovery against a sovereign state and state-backed hackers. A preliminary injunction has already been issued, freezing related wallets and platform funds.
Bybit seeks $1.5 billion and treble punitive damages
According to the recently unsealed complaint, Bybit quietly filed the lawsuit in June against the North Korean government, the RGB, and 20 unidentified defendants. The exchange is seeking about $1.5 billion in compensatory damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, or RICO, along with treble punitive damages.
Bybit said it has already recovered about $48.4 million in stolen assets. Another more than $30.5 million has been frozen by 28 exchanges and custodians around the world.
Most of the stolen funds remain difficult to trace
Tracing the stolen assets on-chain remains highly challenging. Tracking data cited in the report shows that 90.2% of the stolen funds became extremely difficult to follow after passing through mixers, cross-chain bridges, and over-the-counter, or OTC, brokers. Only 9.8% can still be traced to specific wallet addresses.
Bybit CEO Ben Zhou said the company’s objective has not changed: recover user funds as fully as possible and hold those behind the attack accountable. He said the incident hit more than Bybit and posed a direct threat to trust across the crypto industry.
Safe{Wallet} supply-chain compromise cited in forensic review
In what the report calls the largest crypto theft on record, blockchain security firm Elliptic attributed the attack to North Korea’s Lazarus Group. Elliptic said the group has stolen more than $6 billion since 2017 to fund North Korea’s missile program.
After the incident, Bybit hired third-party cybersecurity firm Sygnia to conduct a forensic investigation. The report said the attackers compromised a Safe{Wallet} developer device, injected malicious code into a repository hosted on AWS S3, altered transaction content in the front-end interface, and tricked multisig signers into approving a malicious contract.
Safe{Wallet} later said its smart contracts themselves were not compromised. Binance founder Changpeng Zhao, known as CZ, publicly questioned that explanation at the time, including why multiple signers were deceived during the hardware-wallet verification stage, leaving unresolved questions around supply-chain security.
Regulatory scrutiny continues across multiple markets
Bybit’s legal action comes as the exchange also faces mounting compliance pressure in several jurisdictions. The Monetary Authority of Singapore, or MAS, placed Bybit on its investor alert list in June, saying the company did not hold the required local financial services license.
Bybit responded that it moved its headquarters from Singapore to Dubai in 2022, had excluded Singapore IP addresses from its service scope, and was not providing services there.
The report also said Bybit is barred from offering services in Canada, the United States, China, and Hong Kong. In Malaysia, the Securities Commission took enforcement action over unregistered operations and ordered related local platforms to shut down.
Even under that regulatory pressure, Bybit is trying to use a U.S. federal court ruling to set a precedent for recovering assets from state-backed hacking groups.

