Bybit sues North Korea and Lazarus in U.S. court after $1.5 billion crypto theft

Bybit sues North Korea and Lazarus in U.S. court after $1.5 billion crypto theft

N
News Editor
2026-08-10 09:25:49
Bybit has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau, and the Lazarus Group over the February 2025 theft of roughly $1.5 billion in crypto assets. The court granted a temporary restraining order and a preliminary injunction covering part of the stolen assets held by unidentified defendants listed as John Doe, finding that Bybit is likely to succeed on the merits of the case. The exchange said the civil action is separate from an ongoing criminal investigation by U.S. law enforcement. The filing follows one of the largest crypto thefts on record. According to the report, the attackers compromised Safe’s multisig wallet supply chain and altered the transaction interface while funds were being moved from a Bybit cold wallet to a warm wallet, allowing them to take control of the signing flow. Stolen assets included 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH. Bybit has so far recovered about $48.4 million and frozen another $30.5 million across more than 28 exchanges and custodians, but that still accounts for only about 5% of the total. Most of the funds are believed to have become untraceable after moving through cross-chain bridges, mixers, and OTC channels.

Bybit has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau, and the Lazarus Group, which has been identified as a North Korea-linked hacking organization. According to CoinDesk, the case centers on the theft of about $1.5 billion in crypto assets from the exchange in February 2025.

Bybit sues North Korea and Lazarus in U.S. court after $1.5 billion crypto theft 2

The court, in granting a preliminary temporary restraining order, said Bybit had shown it was likely to succeed on the merits. In addition to the lawsuit, Bybit also secured a preliminary injunction freezing part of the stolen assets held by unidentified individuals and entities listed in the case as John Doe defendants. The order bars those parties from transferring or selling the assets while the case is being heard. Bybit said it will continue seeking further relief from the court and stressed that the civil suit is separate from an ongoing criminal investigation by U.S. law enforcement.

How the attack happened

On Feb. 21, 2025, Lazarus Group exploited Safe’s multisig wallet supply chain. During a transfer from a Bybit cold wallet to a warm wallet, the attackers tampered with the transaction interface, took control of the multisig process, and redirected about 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH to hacker-controlled addresses. The assets were worth about $1.46 billion at the time.

The stolen ETH amounted to roughly 0.42% of Ethereum’s total supply. The report said the hackers briefly became the world’s 14th-largest ETH holder, with holdings exceeding those of Fidelity and Ethereum co-founder Vitalik Buterin.

More than half washed in a week

The laundering operation began quickly after the attack. Data tracked by Spot On Chain showed that within one week, about 266,309 ETH, or 53.3% of the stolen total, had already been washed. Most of it was swapped into BTC through THORChain, with an average daily pace of about 48,420 ETH.

By early March 2025, on-chain analyst Ember said the full laundering process had taken about 10 days. During that period, ETH fell about 23%, and about 90.2% of the stolen funds had become untraceable. The report said the hackers relied mainly on THORChain for laundering, generating about $5.9 billion in trading volume and roughly $5.5 million in fee income for the platform.

Recovery and freezes remain limited

So far, Bybit, working with blockchain analytics firms, multiple exchanges, and international law enforcement agencies, has recovered about $48.4 million in stolen assets and frozen about $30.5 million more across over 28 exchanges and custodians. Together, that totals about $78.9 million, or roughly 5% of the stolen amount.

The Federal Bureau of Investigation has identified Lazarus Group as the actor behind the attack. Follow-up enforcement actions involved German authorities dismantling the crypto exchange eXch, which was tied to the case, while authorities in Germany and Switzerland jointly shut down the mixer Cryptomixer.io.

Why most of the money may not come back

Even with those actions, most of the stolen funds have already moved beyond practical tracing through cross-chain bridges, mixers, and over-the-counter channels. The injunction in the lawsuit applies only to identifiable on-chain assets. Once funds have been mixed, bridged, and transferred to entities or individuals outside cooperation with judicial freeze orders, recovery becomes far more difficult.

The report added that ETH was trading at about $2,730 when the theft happened and around $1,920 at present, a drop of about 30%. That means even if some assets are identified later, their realized value would be much lower than at the time of the theft.

Lazarus and its broader record

Lazarus Group is described as a North Korean state-backed cyber threat cluster under the Reconnaissance General Bureau. Its sub-groups include UNC4736, also known as AppleJeus or Citrine Sleet, and TraderTraitor. Chainalysis has estimated that North Korean hackers, through Lazarus and related clusters, have stolen about $6.75 billion in crypto in total, with more than $2 billion taken in 2025 alone.

The report listed a series of major attacks attributed to the group or its affiliated clusters: the 2014 Sony Pictures Entertainment disruption, the 2016 theft of $81 million from Bangladesh Bank, the 2017 WannaCry ransomware outbreak, the 2022 hacks of Ronin Bridge and Harmony Horizon Bridge for $620 million and $100 million respectively, and the 2023 attacks on Atomic Wallet and Stake.

It also pointed to more recent incidents. In October 2024, UNC4736 attacked Radiant Capital and stole $50 million. In February 2025, TraderTraitor stole a record $1.5 billion from Bybit. In April 2026, the group carried out a $285 million attack on Drift Protocol.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
530

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.