
A US federal judge froze stolen assets linked to the 2025 Bybit hack. The civil suit against North Korea, its intelligence agency, and the Lazarus Group tests whether court orders can recover funds criminal enforcement has not.
Bybit filed a civil lawsuit in the US District Court for the District of Columbia on August 7, 2026, against the Democratic People's Republic of Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group. The complaint concerns the February 21, 2025, breach that drained more than 400,000 Ether and staked Ether from the Dubai-based exchange. The theft, valued at roughly $1.5 billion at the time, remains the largest recorded cryptocurrency heist.
A federal judge already granted a preliminary injunction. The order freezes identifiable stolen assets held by unnamed individuals and entities listed as John Doe defendants. Those defendants are barred from transferring, selling, or otherwise disposing of the identified assets while the case proceeds. Securing such an order required demonstrating to the court that Bybit is likely to succeed on the merits and that the assets would be at risk of dissipation without the freeze.
Bybit CEO Ben Zhou framed the filing around accountability rather than financial recovery. "Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable," Zhou said in a statement.
The case is unusual in several dimensions. A private company is suing a sovereign nation. The defendants include a state intelligence agency and a hacking group that operates under its direction. The stolen assets have been laundered across thousands of wallets, converted between blockchains, and run through mixing services designed to break the transaction trail. The Foreign Sovereign Immunities Act typically shields foreign governments from lawsuits in US courts. Exceptions exist for states designated as sponsors of terrorism. North Korea has been on the State Department's list since 2017. Whether the cryptocurrency theft qualifies under that exception is a legal question the court will need to address.
The timing matters. Bybit waited 18 months after the hack to file. That gap allowed blockchain tracing to mature. The initial weeks after a major theft are chaotic, with funds racing across chains and through mixers. Over time, some of that movement stops. Funds settle in wallets or land on exchanges where withdrawal requires interaction with regulated entities. The preliminary injunction targets those resting points.
The FBI attributed the attack to North Korean actors within days, identifying the perpetrators under the operational name TraderTraitor. The bureau urged exchanges, validators, and blockchain firms to block transactions connected to addresses used in the laundering operation. US intelligence agencies had tracked Lazarus Group operations for years. The on-chain signatures of the Bybit attack matched patterns from previous North Korean campaigns.
The attackers moved fast. Within the first week, a significant portion of the ETH was converted to Bitcoin through cross-chain bridges. The Bitcoin was then dispersed across thousands of wallets in a peel-chain pattern designed to overwhelm tracing tools. By March 2025, Bybit's CEO reported that 88.87 percent of the stolen funds remained traceable, with 7.59 percent lost to mixers and 3.54 percent frozen. By April 2025, 27.6 percent could no longer be tracked.
North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data. The Bybit attack accounted for most of that total. Cumulatively, North Korea-linked groups have stolen roughly $6.75 billion in digital assets over multiple years. The threat continued into 2026. In April, Lazarus-linked attacks allegedly drained $577 million from Drift Protocol and KelpDAO in two separate incidents.
The scale has geopolitical implications. US and South Korean intelligence agencies have assessed that North Korea channels crypto theft proceeds into weapons programs, including nuclear and missile development. That assessment explains why the FBI attributed the Bybit attack quickly and why US authorities have coordinated with exchanges to freeze funds more aggressively than after other crypto thefts.
A civil lawsuit offers advantages that criminal prosecution does not. The burden of proof is lower: a preponderance of the evidence, not proof beyond a reasonable doubt. Bybit controls its own case and can pursue recovery on its own schedule rather than waiting for a criminal prosecution that may take years. The preliminary injunction gives Bybit a legal instrument that exchanges and custodians must respect. When Bybit identifies stolen funds on a platform, it can point to a court order rather than relying on voluntary cooperation. Exchanges that refuse to freeze assets covered by a federal court order face legal exposure of their own.
Even with a favorable ruling, collecting from North Korea is a separate challenge. The country operates outside the conventional financial system and holds minimal assets subject to US courts. The practical value of the lawsuit may lie in the ancillary effects: the asset freeze, the legal precedent for future victims, and the signal to custodians that frozen assets have a court order behind them.
Bybit covered the immediate shortfall after the hack through ETH purchases, loans, and deposits from industry counterparties. The exchange continued processing customer withdrawals throughout the crisis, avoiding the liquidity collapse that has followed other major exchange hacks. The operational response was widely credited as one of the more effective post-hack recoveries in the industry's history.
For smaller victims who lack Bybit's resources, the precedent matters more than the specific case. If the lawsuit produces published court opinions on jurisdiction and immunity, those opinions become tools that future plaintiffs can use. If it succeeds in freezing and recovering stolen assets, it creates a roadmap.
The John Doe structure of the injunction allows Bybit to add identified individuals and entities as discovery progresses. If blockchain tracing leads to specific custodians, exchanges, or OTC desks that processed stolen funds, they could become parties to the lawsuit. Unlike North Korea itself, individuals who hold stolen crypto and fail to comply with a federal court order face consequences that can be enforced.
The case also tests the crypto industry's willingness to cooperate with civil court orders. Exchanges that receive freeze requests backed by a federal injunction face a different calculus than exchanges receiving informal requests from a hack victim. Legal formalization of the recovery process could accelerate compliance across the exchange ecosystem.
For the industry, the North Korean threat has become a baseline security assumption rather than an exceptional risk. Exchanges, DeFi protocols, and bridge operators now design their security models with state-sponsored attackers as a primary threat scenario. The Bybit lawsuit adds a legal dimension to what has primarily been a technical and operational response.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.