In brief
- Bybit has sued North Korea, its Reconnaissance General Bureau and the Lazarus Group in U.S. federal court over the $1.5 billion theft from the exchange in February 2025.
- A judge granted a preliminary injunction freezing identified stolen assets and found Bybit likely to succeed on the merits, according to the exchange.
- Some $48 million has been recovered and $31 million frozen across more than 28 exchanges and custodians.
Crypto exchange Bybit has filed a civil lawsuit against North Korea over the theft of $1.5 billion from the exchange in February 2025, and secured a court order freezing stolen assets that investigators have identified.
The suit, filed in the U.S. District Court for the District of Columbia, names the Democratic People's Republic of Korea, its Reconnaissance General Bureau and the Lazarus Group, the state-linked hacking outfit U.S. authorities blame for the attack. Unidentified individuals and entities holding or moving the funds are named as John Doe defendants.
A judge granted a preliminary injunction barring the transfer or dissipation of identified assets while the case proceeds, and found Bybit likely to succeed on the merits, the exchange said on Friday. In granting an earlier temporary restraining order, the court characterized the theft as among the biggest the industry has seen.
"It was an attack on trust in our industry," the firm's co-founder and CEO Ben Zhou said in a statement Thursday, adding that Bybit had worked with investigators, exchanges, regulators and law enforcement before turning to the courts.
Bybit said that around $48.4 million has been recovered and about $30.5 million frozen across more than 28 exchanges and custodians, together amounting to approximately 5% of what was taken.
Where the money went
Attackers drained roughly 500,000 ETH from a Bybit cold wallet in February 2025, after manipulating a signing interface that showed approvers the correct destination address while altering the wallet's underlying logic. Zhou said at the time that the exchange was solvent and could cover the loss.
By April, Zhou said some 69% of the proceeds remained traceable, 28% had gone dark and 4% had been frozen, with most of the stolen Ethereum converted to Bitcoin via Thorchain and pushed through mixers including Wasabi, Tornado Cash and Railgun. In June, Greek authorities traced a portion of the money to a wallet on a domestic exchange and issued a seizure order.
Bybit said the civil case runs alongside criminal investigations, and that it continues to share blockchain intelligence with agencies including the FBI. It pointed to Germany's takedown of the eXch exchange and the disruption of Cryptomixer.io by German and Swiss authorities as evidence of that cooperation. The proceedings are ongoing.
Facts Only
* Bybit sued North Korea, its Reconnaissance General Bureau, and the Lazarus Group in U.S. federal court over a $1.5 billion theft in February 2025.
* A judge granted a preliminary injunction freezing identified stolen assets.
* The court found Bybit likely to succeed on the merits.
* $48.4 million has been recovered, and $30.5 million has been frozen across over 28 exchanges and custodians.
* Attackers drained approximately 500,000 ETH from a Bybit cold wallet in February 2025 via manipulation of a signing interface.
* Stolen Ethereum was converted to Bitcoin through mixers including Wasabi, Tornado Cash, and Railgun.
* Greek authorities traced a portion of the funds to a domestic exchange and issued a seizure order in June.
* Bybit is pursuing civil action alongside criminal investigations and shares blockchain intelligence with agencies like the FBI.
Executive Summary
Crypto exchange Bybit filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group in the U.S. District Court for the District of Columbia regarding the theft of $1.5 billion from the exchange in February 2025. A judge issued a preliminary injunction to freeze identified stolen assets while the case proceeds, and the court found Bybit likely to succeed on the merits. The lawsuit names the DPRK, its Reconnaissance General Bureau, and the Lazarus Group as responsible for the attack, naming unidentified individuals as John Doe defendants.
Bybit reported that approximately $48.4 million has been recovered and about $30.5 million has been frozen across more than 28 exchanges and custodians, representing roughly 5% of the total stolen amount. The theft involved draining about 500,000 ETH from a Bybit cold wallet in February 2025 through manipulated signing interfaces. Subsequent tracking showed that most stolen Ethereum was converted to Bitcoin via mixers like Tornado Cash and Railgun. The exchange asserted that this legal action runs parallel to criminal investigations, sharing blockchain intelligence with law enforcement agencies such as the FBI, citing cooperation with international bodies like Germany and Switzerland in disruptions related to cryptocurrency infrastructure.
Full Take
The narrative involves the intersection of state-sponsored cybercrime, decentralized finance, and international legal frameworks. The movement of assets from a centralized exchange into obfuscated cryptocurrency channels highlights the systemic vulnerability of digital asset custodians against sophisticated state actors. The success in freezing and recovering funds demonstrates a tangible outcome of cross-jurisdictional cooperation between private entities and government agencies tracing illicit flows.
The pattern observed is the leveraging of technical manipulation (exploiting signing interfaces) followed by layered obfuscation (mixing services) to achieve financial anonymity. This suggests that vulnerability in the protocol layer, combined with the use of established mixing technologies, creates a high barrier for attribution, even when physical assets are seized or frozen. The ongoing parallel civil and criminal proceedings underscore the tension between immediate legal remedy and long-term attribution of state responsibility.
The implication for cognitive sovereignty lies in understanding the operational space where trust is manufactured—in code, in exchange protocols, and in regulatory response times. When private entities must rely on external law enforcement or judicial action to secure assets stolen by state actors, it reveals a gap in immediate defensive agency within the digital ecosystem. The challenge remains in ensuring that the speed of technological execution matches the pace required for meaningful legal and regulatory accountability against transnational criminal operations.
Bridge Questions: What mechanisms are most effective for enforcing digital asset recovery across disparate legal jurisdictions? How does the opacity introduced by mixing services affect the viability of tracing state-sponsored financial flows? What systemic changes are necessary to build more resilient trust frameworks within decentralized finance that prioritize security over simple transactional flow?
