
Filing in D.C. federal court turns blockchain tracing into enforceable claims, with a preliminary injunction freezing assets linked to the February theft.
Bybit has filed a civil lawsuit in U.S. District Court for the District of Columbia over the $1.5 billion cryptocurrency theft that hit the exchange in February 2025, naming North Korea and its Reconnaissance General Bureau as defendants, with the state-linked Lazarus Group named alongside them. A preliminary injunction from the court has frozen identified assets tied to the attack while the case proceeds, the exchange said.
The suit shifts how the exchange is responding to the theft. Instead of relying only on blockchain tracing to follow the stolen funds, Bybit is trying to establish legal ownership over recoverable assets. Court orders give it a way to freeze funds when they surface at regulated custodians and exchanges, options that go beyond voluntary cooperation from trading platforms. The injunction does not mean the money has been recovered. It prevents specific identified assets from being transferred while ownership claims are examined through the legal process.
Bybit has also named unidentified John Doe defendants, a structure that lets the litigation expand if investigators identify additional individuals or entities involved in laundering the stolen assets.
The February 21 breach remains the largest crypto theft on record. Attackers took about 400,000 Ethereum (ETH) and stETH, worth roughly $1.5 billion at the time, from Bybit's cold wallet infrastructure. Forensic investigations traced the entry point to Safe{Wallet}, the multisignature system Bybit used during treasury operations. The attackers compromised a developer environment through social engineering and injected malicious JavaScript into the Safe interface, the investigations found. When Bybit employees approved what looked like a routine transfer between internal wallets, the interface displayed legitimate transaction details while the underlying smart-contract call had been modified to hand control to wallets operated by the Lazarus Group.
The scale of the theft was matched by the speed of the dispersal. Blockchain intelligence firms tracked the attackers splitting the Ethereum across thousands of wallets before routing funds through decentralized exchanges and cross-chain bridges, with liquidity protocols including THORChain in the mix. Large portions were converted into Bitcoin (BTC) and pushed through increasingly complex laundering paths. The dispersal leaned on speed and volume rather than a single mixer or centralized exchange, investigators said, describing a flood-the-zone strategy in which thousands of rapid transactions overwhelmed compliance systems attempting to identify suspicious flows.
The FBI formally attributed the attack to North Korea's TraderTraitor operation and published lists of associated wallet addresses, urging exchanges, bridges, validators and service providers to block transactions tied to the stolen assets. Blockchain analytics firms including Elliptic and TRM Labs, plus cybersecurity specialists Sygnia, have continued tracking the funds while assisting exchanges trying to identify recoverable assets.
Recovering stolen cryptocurrency is a different problem from identifying where it moved. Blockchain ledgers offer a transparent transaction history, letting investigators follow assets across wallets and networks. That visibility does not create legal authority to seize or freeze holdings held by third parties. The civil lawsuit gives Bybit a mechanism to turn the tracing work into enforceable claims, the exchange said, strengthening requests to freeze assets at regulated custodians and exchanges in cooperative jurisdictions. The remaining challenge is converting that visibility into claims that can freeze and recover assets before they vanish into the laundering networks.
The case could also set a precedent for institutional hacks. Exchanges have historically leaned on blockchain analysis and voluntary cooperation from trading platforms, with criminal investigations led by government agencies running in parallel. Bybit's approach adds private civil litigation to those tools, opening a potential recovery path for victims of large-scale theft.
The Bybit attack accounted for most of the roughly $2.02 billion in cryptocurrency attributed to North Korean hacking groups during 2025. Chainalysis data showed DPRK-linked cyber operations have stolen about $6.75 billion worth of digital assets across multiple years, with investigators widely believing the proceeds help fund North Korea's sanctioned weapons and missile programs.
Those campaigns have moved away from exploiting vulnerabilities in blockchain protocols themselves. Recent operations have focused on phishing developers, compromising software supply chains, infiltrating cryptocurrency companies and manipulating the workflows around digital asset custody. The Safe{Wallet} breach showed the same pattern: the attackers did not need to break the multisignature scheme, they needed to compromise the software and operational environment surrounding transaction approval. That evolution has pushed exchanges to reconsider where their greatest security risks sit. For Bybit, the answer pointed to the software and the people around transaction approval, not the blockchain itself.
The litigation will run alongside the blockchain investigations. Whether the strategy works will be measured by recoveries, not by attribution alone, Bybit said. The next major milestone is likely to be additional court filings naming new wallets and counterparties tied to the laundering network, not another tracing report.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.