
Bybit won a U.S. court order freezing North Korea-linked crypto 17 months after the $1.46 billion hack. The real question is how much is left to freeze.
Bybit sued North Korea, its Reconnaissance General Bureau, and the Lazarus hacking group in U.S. District Court for the District of Columbia. The exchange won a preliminary injunction blocking unnamed defendants from moving or selling stolen crypto tied to the February 2025 hack.
Public court filings describe the order as covering identified assets without confirming whether the full $1.5 billion is protected or what dollar value the injunction actually secures.
The injunction landed about 532 days after the theft – roughly 17 months after North Korean hackers pulled off the largest crypto theft on record. Chainalysis tracked a consistent laundering pattern by DPRK-linked groups after major hacks, with stolen funds moving through exchanges, bridges, mixers, and laundering services over roughly 45 days.
Coordinated action by industry partners froze $42.9 million in the first days after the theft. mETH Protocol recovered another 15,000 cmETH, worth nearly $43 million. Combined, that early save came to about $85.9 million, roughly 5.9% of the $1.46 billion stolen.
Elliptic, citing a six-month review from zeroShadow, said more than $1 billion of the stolen funds had already moved through the laundering pipeline before this court order existed. Whatever value the injunction protects now probably represents a small residue that never fully escaped.
Stolen crypto becomes stoppable the moment it lands somewhere a court order can reach: an exchange, a stablecoin issuer, a custodian, or any other operator capable of freezing what passes through it. That is why the FBI asked exchanges, bridges and RPC operators to block Lazarus-linked transactions within days of the hack. It is also why Bybit's own stolen stETH and cmETH were swapped into native ETH almost immediately.
Token issuers can often freeze wallets holding their own tokens, Elliptic says. No central party directly controls ETH or Bitcoin balances. Converting stolen liquid-staking tokens into native ETH removes one of the easiest tools victims have for freezing assets.
Native ETH or Bitcoin sitting in self-custody is nearly impossible to freeze directly. Stablecoins sit at the other end, since issuers can blocklist addresses depending on the chain and contract design. Centralized exchanges sit close behind, able to block withdrawals or comply with a warrant. Bridges, swap services and DAO-controlled recovery wallets fall somewhere in between. OTC brokers operating across borders remain the hardest targets of all.
A Lazarus-linked theft from the crypto platform Rain drew a similar response. The FBI froze roughly 2,204 SOL at the exchange WhiteBIT and served a seizure warrant. WhiteBIT transferred the funds to the U.S. government, and a federal court later granted default judgment forfeiting the crypto outright.
Holders of old terrorism judgments against North Korea served a restraining notice on roughly 30,766 ETH, worth about $71 million, that had been frozen when an unrelated exploit hit the Kelp protocol on Arbitrum. Arbitrum's governance records show a DAO vote that later moved ETH to an Aave-controlled wallet, with the restraining notice accompanying the assets to their new location.
No public record shows that competing creditors have claimed the assets Bybit is now pursuing. The Kelp episode establishes a real pattern. Once DPRK-linked crypto sits frozen somewhere reachable, other parties holding judgments against North Korea can try to get in line for it too.
The U.S. Treasury Department designated Lazarus Group, Bluenoroff and Andariel in 2019 as entities controlled by North Korea through their ties to the Reconnaissance General Bureau. Treasury says the country's cyber operations generate revenue that can fund weapons and ballistic missile programs.
Chainalysis says North Korean hackers stole over $2 billion in crypto in 2025 alone, a 51% jump from the year before, even as the number of known attacks fell sharply. Cumulative DPRK crypto theft has reached at least $6.75 billion. The pattern points toward fewer, larger hits and away from a broad spray of small ones.
The bull case for Bybit is that more of the stolen $1.46 billion will turn up at reachable chokepoints than anyone currently expects. Investigators trace additional funds held by exchanges, stablecoin issuers, bridges, or custodians willing to cooperate. Bybit's injunction becomes a template other victims use to chase down DPRK-linked funds long into a hack's aftermath. Recovery climbs meaningfully above the roughly $85.9 million secured so far. Courts prove that persistence still beats time even against a state-backed hacking operation.
The bear case is that the injunction covers only a small residual balance already trapped by ordinary compliance systems before Bybit filed suit. Most of the $1.46 billion stays gone, laundered through the 45-day window Chainalysis describes long before any court could act. The lawsuit proves that legal reach exists. It also proves that a 17-month head start is nearly fatal to recovery.
Bybit's lawsuit is proving that the assets sitting at the end of one blockchain transaction can still be stopped. Just not for free, and never on a predictable schedule.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.