Bybit sued North Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group on Aug. 7 in the U.S. District Court for the District of Columbia, seeking to recover the roughly $1.5 billion stolen from the exchange in a February 2025 hack, and won a preliminary injunction freezing identified stolen assets the same day.
The defendants named in the action include the Democratic People’s Republic of Korea (DPRK), the Reconnaissance General Bureau (RGB), which serves as the country’s intelligence agency, and the Lazarus Group, a hacking organization that U.S. authorities have linked to North Korea.
The case also names unidentified individuals and entities as “John Doe” defendants in connection with assets allegedly derived from the theft.
The legal action represents a new phase in Bybit’s attempt to recover funds stolen from an Ethereum cold wallet on February 21, 2025. Rather than relying solely on blockchain tracing and cooperation with exchanges, the Bybit lawsuit gives the exchange a formal legal mechanism to seek the preservation and recovery of assets connected to the attack.
Bybit lawsuit follows record crypto theft
The February 2025 attack remains central to the Bybit lawsuit. Attackers stole approximately $1.5 billion in Ethereum and related assets from a Bybit wallet, making it one of the largest cryptocurrency thefts ever recorded. Bybit has said the attack involved the compromise of infrastructure connected to its wallet operations.
U.S. authorities subsequently attributed the theft to North Korea. In a February 2025 public advisory, the Federal Bureau of Investigation said the DPRK was responsible for the theft and referred to the specific activity as “TraderTraitor.” The FBI said the stolen assets were rapidly converted into other cryptocurrencies and distributed across thousands of blockchain addresses.
“TraderTraitor actors are proceeding rapidly and have converted some of the stolen assets to Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains,” — Federal Bureau of Investigation.
The FBI also warned that the stolen assets were expected to be further laundered and eventually converted into fiat currency. It encouraged cryptocurrency exchanges, blockchain infrastructure providers, DeFi platforms and other virtual-asset businesses to block transactions involving addresses associated with the North Korean operation.
That warning provides important context for the Bybit lawsuit, which comes more than a year after the initial theft and after extensive efforts to track the stolen funds across different blockchains.
Lazarus Group becomes central to the legal fight
The Bybit lawsuit places the Lazarus Group at the centre of a legal effort that extends beyond identifying the hackers. U.S. authorities and blockchain investigators have repeatedly associated Lazarus with major cryptocurrency thefts, while the FBI formally attributed the Bybit incident to North Korean actors operating under the TraderTraitor designation.
The group has previously been linked by U.S. authorities to other major cyberattacks. In a 2018 criminal complaint, the U.S. Department of Justice described Lazarus as a North Korean government-sponsored hacking team and alleged that its members were involved in cyberattacks including the WannaCry ransomware campaign, the Sony Pictures intrusion and the theft from Bangladesh Bank.
The Bybit attack demonstrated why cryptocurrency exchanges remain attractive targets for state-linked cyber operations. The stolen assets could be moved quickly across decentralized networks, converted between different tokens and distributed across large numbers of addresses, creating significant challenges for investigators attempting to freeze or recover them.
In the Bybit lawsuit, the exchange is now seeking to use the U.S. court system alongside those blockchain investigations. The preliminary injunction prevents the transfer or sale of identified assets while the litigation proceeds, according to Bybit and reporting on the case.
Bybit seeks recovery through US courts
The immediate significance of the Bybit lawsuit is not simply the naming of North Korea and Lazarus. The preliminary injunction creates a legal restraint around assets identified as connected to the case, potentially giving Bybit and investigators additional leverage in their recovery efforts.
Bybit said the civil case is being pursued separately from criminal investigations by U.S. law enforcement authorities. That distinction matters because the lawsuit is primarily aimed at asset preservation, recovery and civil accountability rather than replacing criminal proceedings against the alleged perpetrators.
“The order is intended to preserve identified stolen digital assets while the litigation continues, representing an important step in Bybit’s ongoing efforts to recover funds, support international law enforcement investigations, and reinforce accountability for large-scale cybercrime,” — Bybit.
Bybit co-founder and CEO Ben Zhou said the exchange’s objective remains focused on protecting customers and recovering the stolen assets.
“Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” — Ben Zhou, co-founder and CEO of Bybit.
Zhou added that the attack had implications beyond the exchange itself, framing the incident as a broader challenge to confidence in the cryptocurrency industry.