
Bybit has achieved significant progress in recovering assets from its $1.5 billion North Korea-linked hack, with the exchange reporting $48.4 million recovered and $30.5 million frozen across more than 28 exchanges and custodians worldwide. According to Bybit's latest update published August 7, this brings the total amount in the recovered or frozen category to approximately $78.9 million. The exchange secured a partial preliminary injunction on July 30, with Judge John D. Bates finding that Bybit has demonstrated a likelihood of success on the merits. Court records show the temporary restraining order began June 19, with expedited discovery granted the following day allowing Bybit to seek account identities, balances and transaction histories from U.S.-linked platforms. A U.S. federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants, preventing them from transferring, selling, or otherwise disposing of the identified assets while the litigation continues.
Bybit filed a civil lawsuit on August 7, 2026, in the U.S. District Court for the District of Columbia against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB) intelligence agency, the Lazarus Group, and 20 unidentified defendants. The lawsuit targets the DPRK-linked hacking group responsible for stealing $1.5 billion from the exchange in the February 21, 2025 breach that drained more than 400,000 Ether (ETH) and staked Ether from the Dubai-based exchange. The case also includes unidentified John Doe defendants, with the exchange pursuing legal action independently of ongoing criminal investigations conducted by U.S. law enforcement authorities. The FBI formally attributed the theft to North Korea five days after the attack, identifying the malicious cyber activity as 'TraderTraitor' and warning that actors were rapidly converting portions of the stolen assets into Bitcoin and other cryptocurrencies across thousands of addresses on multiple blockchains. The filing is unusual in almost every dimension, with a private company suing a sovereign nation in a U.S. court, targeting a state intelligence agency and hacking group that operates under its direction.
The stolen funds have become increasingly difficult to trace as attackers converted assets into Bitcoin and dispersed them across thousands of wallets. Bybit's June filing revealed that 90.2% of the stolen assets had become untraceable after moving through mixers, cross-chain bridges and over-the-counter dealers, with only 9.8% remaining connected to identifiable wallets. The exchange's August 7 figures show that 88.87% of the stolen funds could still be traced when the June complaint was initially filed, while 7.59% had gone dark and 3.54% had been frozen. By April 2025, 27.6% of the stolen funds could no longer be tracked as Lazarus-linked wallets used services including cross-chain protocols and crypto mixers to make the transaction trail harder to follow. The attackers moved quickly to launder the stolen funds, with a significant portion converted to Bitcoin through cross-chain bridges within the first week, then dispersed across thousands of wallets in a pattern designed to overwhelm tracing tools. The traceable share declined over the following months, with each hop between chains and pass through a mixer making the remaining funds harder to follow.
The theft occurred on February 21, 2025, with the FBI formally attributing the attack to North Korean cyber actors called 'TraderTraitor' five days later. The agency said the attackers converted some stolen assets into Bitcoin and other cryptocurrencies and dispersed them across thousands of addresses on multiple blockchains. The attack was also traced to compromised infrastructure connected to Safe Wallet, with forensic investigators finding that a compromised Safe developer machine enabled the attackers to propose a disguised malicious transaction. Safe later said its review found no vulnerability in its smart contracts or source code and that it rebuilt infrastructure and rotated credentials after the breach. The FBI previously urged exchanges, validators and blockchain firms to block transactions connected to addresses identified in the laundering operation, with Bybit continuing to share blockchain intelligence with the agency. The speed of the attribution was notable, as US intelligence agencies had been tracking Lazarus Group operations for years, and the on-chain signatures of the attack matched patterns from previous North Korean campaigns.
Ben Zhou, co-founder and CEO of Bybit, emphasized the company's commitment to user protection and accountability. According to CoinDesk's account of the filing, Zhou stated that the Lazarus attack wasn't just an attack on Bybit but an attack on trust in the industry. The exchange has worked closely with investigators, exchanges, regulators, law enforcement, and now the courts to address the cybercrime. "Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable," Zhou said. The new court orders provide Bybit additional tools beyond its earlier bounty program and blockchain tracing efforts. The complaint seeks return of the stolen assets, about $1.5 billion in compensatory damages, punitive damages and treble damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, with Bybit planning to seek further judicial relief as the litigation proceeds. The lawsuit offers several advantages over criminal prosecution, including a lower burden of proof (preponderance of evidence vs. beyond a reasonable doubt), control over the case timeline, and the ability to freeze assets through court orders that exchanges must respect.