Full story
Lawsuit and Frozen Funds
Crypto exchange Bybit sued North Korea, its Reconnaissance General Bureau, and the Lazarus Group in a U.S. federal court over a February 21, 2025 hack that Bybit described as a record-breaking $1.5 billion theft.
“Bybit has sued North Korea in a U.S. federal court over last year’s record-breaking $1.5 billion hack”
Bybit filed the civil lawsuit under seal on June 18, 2026 in the U.S. District Court for the District of Columbia, and a U.S. court froze stolen assets on July 30 after Bybit filed suit on June 18, 2026.

The case centers on theft of more than 400,000 Ethereum tokens on Feb. 21, 2025, after attackers compromised a developer’s computer at Safe{Wallet} and inserted malicious code that activated when Bybit’s specific wallet address appeared.
Bybit said it had recovered $48.4 million so far, while over 90% of funds remained untraceable, and the company sought roughly $1.5 billion in damages plus additional punitive damages.
In the court process, a judge issued a temporary restraining order on June 19 blocking the transfer of certain traceable assets, and then partially granted a preliminary injunction freezing assets held by unidentified defendants tied to the stolen funds.
Tracing Limits and Discovery
Bybit’s effort to pursue information that could help trace stolen cryptocurrency advanced after U.S. court support for expedited discovery, with court records unsealed on Thursday showing Bybit filed a lawsuit under seal on June 18 against North Korea, its Reconnaissance General Bureau, the Lazarus Group, and 20 unidentified defendants.
A federal judge granted Bybit’s request for expedited discovery on June 19, giving the exchange a practical route to identify alleged intermediaries and pursue a small portion of stolen assets that remains traceable.
As of Bybit’s June 18 filing, Bybit said 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers, leaving 9.8% traced to identifiable wallets.
The same filings described that 5.3% of the total, about $75.5 million, had been frozen or recovered, marking a sharp drop from more than a year earlier when Ben Zhou said 68.57% of the funds remained traceable.
Bybit’s complaint said some traceable assets reached exchanges operating or maintaining infrastructure in the U.S., and Bybit sought account-holder identities, balances and transaction histories from platforms that indicated they would cooperate after receiving a court order.
Who’s Accused and What’s at Risk
Bybit’s civil case names the Democratic People’s Republic of Korea, its Reconnaissance General Bureau, and the Lazarus Group as defendants, and it frames the theft as organized racketeering under the Racketeer Influenced and Corrupt Organizations Act, along with the Computer Fraud and Abuse Act and the Alien Tort Statute.
““It was an attack on trust in our industry.””
The exchange also described the hack as “an attack on trust in our industry” and said its focus was to “protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” according to Bybit co-founder and CEO Ben Zhou.
Bybit said it covered more than $4 billion in customer withdrawal requests without freezing accounts, and it paid out $2.3 million through a bounty program that rewarded investigators for tracking the stolen funds.
Investigators later determined attackers had compromised a developer’s computer at Safe{Wallet} and inserted malicious code that activated only when Bybit’s specific wallet address appeared, allowing attackers to install a backdoor and drain the wallet in minutes.
The stakes in the litigation, as described in the coverage, include whether courts can reach intermediaries holding stolen funds through asset freezes and continued discovery, since collecting a judgment directly from North Korea remains unlikely.




