Bybit sues North Korea and Lazarus Group in U.S. court over $1.5 billion crypto theft

Bybit sues North Korea and Lazarus Group in U.S. court over $1.5 billion crypto theft

N
News Editor
2026-08-11 12:22:10
Crypto exchange Bybit has filed suit in the U.S. District Court for the District of Columbia against the North Korean government, the Reconnaissance General Bureau, and the Lazarus Group over the theft of about $1.5 billion in digital assets in February 2025. The complaint, recently unsealed, seeks roughly $1.5 billion in compensatory damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, along with treble punitive damages. The case stands out because it is described as the first time a crypto exchange has used the U.S. federal court system to pursue civil recovery directly against a sovereign state and state-backed hackers. The court has already issued a preliminary injunction freezing related wallets and platform funds. Bybit said it has recovered about $48.4 million so far, while more than $30.5 million has been frozen by 28 exchanges and custodians worldwide. Even so, tracing the stolen funds remains difficult: 90.2% of the assets are now hard to track after moving through mixers, cross-chain bridges, and OTC channels, while only 9.8% can still be traced to specific wallet addresses. At the same time, Bybit is facing regulatory pressure in several jurisdictions, including Singapore, Malaysia, Canada, the United States, China, and Hong Kong.

Crypto exchange Bybit has sued the North Korean government, North Korea’s Reconnaissance General Bureau (RGB), and the Lazarus Group in the U.S. District Court for the District of Columbia, accusing them of responsibility for the theft of about $1.5 billion in crypto assets in February 2025.

Bybit sues North Korea and Lazarus Group in U.S. court over $1.5 billion crypto theft 2

The case is described as the first time a crypto exchange has directly used the U.S. federal court system to pursue civil recovery against a sovereign state and state-backed hackers. A preliminary injunction has already been issued, freezing related wallets and platform funds.

Bybit seeks $1.5 billion and treble punitive damages

According to the recently unsealed complaint, Bybit quietly filed the lawsuit in June against the North Korean government, the RGB, and 20 unidentified defendants. The exchange is seeking about $1.5 billion in compensatory damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, or RICO, along with treble punitive damages.

Bybit said it has already recovered about $48.4 million in stolen assets. Another more than $30.5 million has been frozen by 28 exchanges and custodians around the world.

Most of the stolen funds remain difficult to trace

Tracing the stolen assets on-chain remains highly challenging. Tracking data cited in the report shows that 90.2% of the stolen funds became extremely difficult to follow after passing through mixers, cross-chain bridges, and over-the-counter, or OTC, brokers. Only 9.8% can still be traced to specific wallet addresses.

Bybit CEO Ben Zhou said the company’s objective has not changed: recover user funds as fully as possible and hold those behind the attack accountable. He said the incident hit more than Bybit and posed a direct threat to trust across the crypto industry.

Safe{Wallet} supply-chain compromise cited in forensic review

In what the report calls the largest crypto theft on record, blockchain security firm Elliptic attributed the attack to North Korea’s Lazarus Group. Elliptic said the group has stolen more than $6 billion since 2017 to fund North Korea’s missile program.

After the incident, Bybit hired third-party cybersecurity firm Sygnia to conduct a forensic investigation. The report said the attackers compromised a Safe{Wallet} developer device, injected malicious code into a repository hosted on AWS S3, altered transaction content in the front-end interface, and tricked multisig signers into approving a malicious contract.

Safe{Wallet} later said its smart contracts themselves were not compromised. Binance founder Changpeng Zhao, known as CZ, publicly questioned that explanation at the time, including why multiple signers were deceived during the hardware-wallet verification stage, leaving unresolved questions around supply-chain security.

Regulatory scrutiny continues across multiple markets

Bybit’s legal action comes as the exchange also faces mounting compliance pressure in several jurisdictions. The Monetary Authority of Singapore, or MAS, placed Bybit on its investor alert list in June, saying the company did not hold the required local financial services license.

Bybit responded that it moved its headquarters from Singapore to Dubai in 2022, had excluded Singapore IP addresses from its service scope, and was not providing services there.

The report also said Bybit is barred from offering services in Canada, the United States, China, and Hong Kong. In Malaysia, the Securities Commission took enforcement action over unregistered operations and ordered related local platforms to shut down.

Even under that regulatory pressure, Bybit is trying to use a U.S. federal court ruling to set a precedent for recovering assets from state-backed hacking groups.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
520

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.