Bybit has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau, and the Lazarus Group, which has been identified as a North Korea-linked hacking organization. According to CoinDesk, the case centers on the theft of about $1.5 billion in crypto assets from the exchange in February 2025.
The court, in granting a preliminary temporary restraining order, said Bybit had shown it was likely to succeed on the merits. In addition to the lawsuit, Bybit also secured a preliminary injunction freezing part of the stolen assets held by unidentified individuals and entities listed in the case as John Doe defendants. The order bars those parties from transferring or selling the assets while the case is being heard. Bybit said it will continue seeking further relief from the court and stressed that the civil suit is separate from an ongoing criminal investigation by U.S. law enforcement.
How the attack happened
On Feb. 21, 2025, Lazarus Group exploited Safe’s multisig wallet supply chain. During a transfer from a Bybit cold wallet to a warm wallet, the attackers tampered with the transaction interface, took control of the multisig process, and redirected about 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH to hacker-controlled addresses. The assets were worth about $1.46 billion at the time.
The stolen ETH amounted to roughly 0.42% of Ethereum’s total supply. The report said the hackers briefly became the world’s 14th-largest ETH holder, with holdings exceeding those of Fidelity and Ethereum co-founder Vitalik Buterin.
More than half washed in a week
The laundering operation began quickly after the attack. Data tracked by Spot On Chain showed that within one week, about 266,309 ETH, or 53.3% of the stolen total, had already been washed. Most of it was swapped into BTC through THORChain, with an average daily pace of about 48,420 ETH.
By early March 2025, on-chain analyst Ember said the full laundering process had taken about 10 days. During that period, ETH fell about 23%, and about 90.2% of the stolen funds had become untraceable. The report said the hackers relied mainly on THORChain for laundering, generating about $5.9 billion in trading volume and roughly $5.5 million in fee income for the platform.
Recovery and freezes remain limited
So far, Bybit, working with blockchain analytics firms, multiple exchanges, and international law enforcement agencies, has recovered about $48.4 million in stolen assets and frozen about $30.5 million more across over 28 exchanges and custodians. Together, that totals about $78.9 million, or roughly 5% of the stolen amount.
The Federal Bureau of Investigation has identified Lazarus Group as the actor behind the attack. Follow-up enforcement actions involved German authorities dismantling the crypto exchange eXch, which was tied to the case, while authorities in Germany and Switzerland jointly shut down the mixer Cryptomixer.io.
Why most of the money may not come back
Even with those actions, most of the stolen funds have already moved beyond practical tracing through cross-chain bridges, mixers, and over-the-counter channels. The injunction in the lawsuit applies only to identifiable on-chain assets. Once funds have been mixed, bridged, and transferred to entities or individuals outside cooperation with judicial freeze orders, recovery becomes far more difficult.
The report added that ETH was trading at about $2,730 when the theft happened and around $1,920 at present, a drop of about 30%. That means even if some assets are identified later, their realized value would be much lower than at the time of the theft.
Lazarus and its broader record
Lazarus Group is described as a North Korean state-backed cyber threat cluster under the Reconnaissance General Bureau. Its sub-groups include UNC4736, also known as AppleJeus or Citrine Sleet, and TraderTraitor. Chainalysis has estimated that North Korean hackers, through Lazarus and related clusters, have stolen about $6.75 billion in crypto in total, with more than $2 billion taken in 2025 alone.
The report listed a series of major attacks attributed to the group or its affiliated clusters: the 2014 Sony Pictures Entertainment disruption, the 2016 theft of $81 million from Bangladesh Bank, the 2017 WannaCry ransomware outbreak, the 2022 hacks of Ronin Bridge and Harmony Horizon Bridge for $620 million and $100 million respectively, and the 2023 attacks on Atomic Wallet and Stake.
It also pointed to more recent incidents. In October 2024, UNC4736 attacked Radiant Capital and stole $50 million. In February 2025, TraderTraitor stole a record $1.5 billion from Bybit. In April 2026, the group carried out a $285 million attack on Drift Protocol.

