Bybit Sues Lazarus Group Over Historic $1.5B Crypto Theft

Bybit has taken its fight against North Korea's Lazarus Group from blockchain investigations into the U.S. legal system, filing a civil lawsuit against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the state-linked hacking group over the $1.5 billion cryptocurrency theft that struck the exchange in February 2025.
Summary:
- Bybit has filed a civil lawsuit against North Korea and the Lazarus Group.
- A U.S. court has granted a preliminary injunction freezing identified stolen assets.
- The February 2025 attack remains the largest cryptocurrency theft on record.
- The case could influence how exchanges pursue future crypto asset recovery.
The move follows a preliminary injunction issued by the U.S. District Court for the District of Columbia freezing identified assets linked to the attack while litigation continues.
Rather than focusing solely on tracing stolen cryptocurrency, the exchange is now attempting to establish legal ownership over recoverable assets and expand its options for freezing funds that surface across exchanges, custodians and other financial intermediaries.
Bybit is turning blockchain evidence into a legal recovery effort
The lawsuit marks an important shift in how major crypto exchanges respond to state-sponsored cyberattacks.
Immediately after the hack, blockchain analytics firms concentrated on identifying wallet addresses connected to the stolen Ethereum and monitoring how the funds moved through decentralized exchanges, cross-chain protocols and laundering networks.
That process produced valuable intelligence but limited legal authority.
By filing suit in a U.S. federal court, Bybit is attempting to transform blockchain evidence into an enforceable legal claim. The preliminary injunction allows identified assets connected to the theft to remain frozen while the court considers the merits of the case.
The exchange has also named unidentified “John Doe” defendants, allowing the litigation to expand if investigators identify additional individuals or entities involved in laundering the stolen funds.
The injunction does not mean the stolen cryptocurrency has been recovered.
Instead, it prevents specific identified assets from being transferred while ownership claims are examined through the legal process.
The attack exploited operational trust rather than blockchain technology
The February 21, 2025 breach remains the largest cryptocurrency theft ever recorded, with approximately 400,000 ETH and stETH worth roughly $1.5 billion stolen from Bybit’s cold wallet infrastructure.
Investigators determined that the attackers targeted Safe{Wallet}, the multisignature wallet system used during treasury operations.
According to forensic investigations, the attackers compromised a developer environment through sophisticated social engineering before injecting malicious JavaScript into the Safe interface.
When Bybit employees later approved what appeared to be a routine transfer between internal wallets, the interface displayed legitimate transaction information while the underlying smart-contract call had been modified to transfer control to wallets operated by the Lazarus Group.
The incident demonstrated that sophisticated attackers no longer need to exploit vulnerabilities in blockchain protocols themselves.
Instead, compromising the software and operational environment surrounding transaction approval can bypass even robust multisignature security if authorized users unknowingly approve manipulated transactions.
The laundering operation moved faster than traditional compliance systems
The scale of the theft was matched by the speed with which the stolen assets were dispersed.
Blockchain intelligence firms observed the attackers splitting the Ethereum across thousands of wallets before routing funds through decentralized exchanges, cross-chain bridges and liquidity protocols including THORChain.
Large portions of the stolen cryptocurrency were subsequently converted into Bitcoin and moved through increasingly complex laundering paths.
Rather than relying on a single mixer or centralized exchange, investigators described a “flood the zone” strategy in which thousands of rapid transactions overwhelmed traditional compliance systems attempting to identify suspicious flows.
READ MORE: ZEUS Wallet Goes Offline After Infrastructure Security Breach
The FBI later formally attributed the attack to North Korea’s TraderTraitor operation and published lists of associated wallet addresses, urging exchanges, bridges, validators and service providers to block transactions involving the stolen assets.
Private blockchain analytics firms, including Elliptic, TRM Labs and cybersecurity specialists Sygnia, have continued tracking the movement of funds while assisting exchanges attempting to identify recoverable assets.
Why the lawsuit matters beyond Bybit
Recovering stolen cryptocurrency is fundamentally different from identifying where it moved.
Blockchain ledgers provide a transparent transaction history, allowing investigators to trace assets across wallets and networks. That visibility, however, does not automatically create legal authority to seize or freeze assets held by third parties.
The civil lawsuit gives Bybit another mechanism.
If assets linked to the theft reach regulated custodians, exchanges or identifiable counterparties operating within cooperative jurisdictions, court orders can strengthen requests to freeze those holdings and potentially return them to the exchange.
The case may also establish an important precedent for future institutional hacks.
Historically, exchanges have relied primarily on blockchain analysis, voluntary cooperation from trading platforms and criminal investigations led by government agencies. Bybit’s strategy combines those tools with private civil litigation, potentially creating an additional recovery pathway for victims of large-scale crypto theft.
North Korea remains the dominant state actor in crypto theft
The Bybit attack accounted for most of the approximately $2.02 billion in cryptocurrency attributed to North Korean hacking groups during 2025.
According to Chainalysis, DPRK-linked cyber operations have now stolen roughly $6.75 billion worth of digital assets over multiple years, with investigators widely believing the proceeds support North Korea’s sanctioned weapons and missile programs.
Those campaigns have increasingly shifted away from exploiting blockchain vulnerabilities.
Instead, recent operations have focused on phishing developers, compromising software supply chains, infiltrating cryptocurrency companies and manipulating operational workflows surrounding digital asset custody.
That evolution has forced exchanges to reconsider where their greatest security risks actually exist.
What comes next
The legal proceedings are likely to continue alongside ongoing blockchain investigations.
The next major milestone will not necessarily be another tracing report but additional court filings identifying new wallets, counterparties or intermediaries allegedly connected to the laundering network.
The effectiveness of Bybit’s strategy will ultimately be measured by recoveries rather than attribution. Investigators have already demonstrated they can follow much of the stolen cryptocurrency across multiple blockchains. The remaining challenge is converting that visibility into enforceable legal claims capable of freezing and recovering assets before they disappear into increasingly sophisticated laundering networks.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











