
Bybit has taken its fight against North Korean hackers into a U.S. courtroom, filing a civil lawsuit tied to the Bybit $1.5 billion hack that drained the exchange of hundreds of thousands of ether tokens earlier this year. The Dubai-based exchange, the world’s second-largest by trading volume, is now asking a federal court to hold the Democratic People’s Republic of Korea (DPRK) and its state-linked hacking unit accountable for what investigators call the largest cryptocurrency heist ever recorded.
Key takeaways
Bybit sued the DPRK, its Reconnaissance General Bureau (RGB) intelligence agency, and the Lazarus Group over the $1.5 billion hack.
The theft happened on February 21, 2025, and involved more than 400,000 ETH and stETH taken from Bybit.
A U.S. federal judge granted a preliminary injunction freezing stolen assets held by unnamed “John Doe” defendants.
North Korean hackers stole $6.75 billion in crypto in total last year, according to Chainalysis, funds widely believed to support the country’s weapons program.
The civil case, filed in the U.S. District Court for the District of Columbia, runs separately from ongoing criminal investigations by U.S. law enforcement.
Bybit’s Lawsuit Against North Korea and Lazarus Group
Bybit has formally accused the DPRK, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group of orchestrating the theft that stripped the exchange of $1.5 billion last year. The move marks one of the most direct legal confrontations a crypto exchange has launched against a state-linked hacking operation.
Details of the Civil Suit
The Lazarus Group has long been identified by Western governments as a DPRK-linked hacking outfit, and Bybit’s suit names it directly as the entity responsible for pulling off the theft. Alongside the group, the lawsuit targets North Korea itself and the RGB, the intelligence agency accused of directing the operation.
Legal Filing and Jurisdiction
Bybit brought the case in the U.S. District Court for the District of Columbia, a jurisdiction often used for actions touching on national security and foreign state conduct. The exchange was careful to note that this civil action moves on a separate track from any criminal investigations already underway among U.S. law enforcement authorities, meaning the two processes can proceed without one blocking the other.
The $1.5 Billion Cryptocurrency Hack
The breach at the center of this case unfolded on February 21, 2025, when attackers linked to North Korea allegedly executed what has become known as the biggest crypto heist on record. The scale of the theft, and the speed with which it happened, sent shockwaves through the exchange industry.
Date and Scale of the Breach
On that day, the North Korean state-sponsored Lazarus Group allegedly siphoned off roughly $1.5 billion in Ethereum-based assets, including more than 400,000 ETH and staked ETH tokens, from Bybit’s reserves. The sheer size of the theft instantly made it the largest single cryptocurrency hack in history, dwarfing previous exchange breaches by a wide margin.
Perpetrators and Historical Context
The Lazarus Group’s connection to North Korea is well documented, and this incident cemented its reputation as the group behind the largest cryptocurrency heist ever pulled off. The Lazarus Group crypto theft at Bybit accounted for a large share of the $2.02 billion in digital assets North Korea is estimated to have stolen last year alone.
Broader North Korean Crypto Crime
Zooming out, the numbers get even bigger. According to data from blockchain analytics firm Chainalysis, North Korean hackers have stolen a combined $6.75 billion worth of cryptocurrency to date. This North Korea crypto hack pattern is widely believed to serve a specific purpose: funding the country’s weapons program, giving the regime a workaround for international sanctions that would otherwise cut off traditional financing routes.
This is precisely why the case matters beyond Bybit’s balance sheet. When a hack of this size is tied to a sanctioned government’s weapons ambitions, it stops being a routine exchange security failure and becomes a matter of international financial crime enforcement — one that regulators, exchanges, and law enforcement agencies worldwide are watching closely.
Asset Freeze and Recovery Efforts
Bybit didn’t stop at filing a complaint — it also secured a court order stopping the movement of stolen funds still traceable on-chain. That combination of legal action and financial containment is what sets this case apart from typical post-hack responses.
Preliminary Injunction Details
The court granted Bybit a preliminary injunction covering certain stolen assets held by unidentified individuals and entities, listed in the filing as John Doe defendants. In practical terms, a federal judge ordered these holders not to transfer, sell, or otherwise move the frozen assets while the litigation continues. Bybit said it plans to seek further relief from the court as the case progresses.
Bybit’s Recovery and Enforcement Goals
Bybit described the order as an important step toward recovering funds, supporting international law enforcement investigations, and reinforcing accountability for large-scale cybercrime. This Bybit asset freeze lawsuit is designed to preserve identifiable stolen digital assets so they remain available for eventual recovery, even as the broader legal process unfolds.
Statements from Bybit Leadership
Ben Zhou, Bybit’s co-founder and CEO, framed the lawsuit as a continuation of a commitment the exchange made right after the breach. “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” Zhou said in a statement. He added a pointed remark about what the incident meant for the industry at large: “The Lazarus attack wasn’t just an attack on Bybit. It was an attack on trust in our industry. That’s why we’ve worked closely with investigators, exchanges, regulators, law enforcement, and now the courts.”
That last line captures the bigger stakes here. State-sponsored hacking groups targeting exchanges don’t just threaten one company’s bottom line — they chip away at confidence in the entire crypto ecosystem, pushing exchanges, regulators and courts to coordinate in ways that weren’t common even a few years ago. Whether this lawsuit actually recovers meaningful funds may matter less, in the long run, than whether it sets a legal precedent other exchanges can use against similar state-linked theft.
FAQ
Who did Bybit sue over the $1.5 billion cryptocurrency hack?
Bybit filed a civil lawsuit against the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the Lazarus Group.
What was stolen in the Bybit hack and when did it occur?
On February 21, 2025, the Lazarus Group stole approximately $1.5 billion in Ethereum, including over 400,000 ETH and stETH, from Bybit.
What legal measures has Bybit secured following the hack?
Bybit obtained a preliminary injunction from a federal court freezing stolen assets held by unnamed defendants to prevent transfer or sale during litigation.
Is the civil lawsuit connected to ongoing criminal investigations?
No, Bybit’s U.S. law enforcement is conducting ongoing criminal investigations, while a separate civil action is being pursued independently.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
