Bybit Sues North Korea Over $1.5 Billion Ethereum Hack
ETH/USDT
$2,001,203,077.32
$1,926.72 / $1,912.27
Change: $14.45 (0.76%)
+0.0046%
Longs pay
AI SummaryAI
- Bybit filed a civil suit in the U.S. District Court for the District of Columbia against North Korea, the Reconnaissance General Bureau, and Lazarus Group.
- The February 2025 Bybit theft involved more than 400,000 Ether and stETH valued at about $1.5 billion at the time.
- On-chain analytics firm Chainalysis estimates North Korea-linked actors have stolen about $6.75 billion in crypto assets.
- Bybit recovered about $48.4 million and froze another $30.5 million across more than 28 exchanges and custody institutions.
Crypto News
Bybit has brought a civil action in a U.S. court against North Korea, its Reconnaissance General Bureau, and the Lazarus Group over the February 2025 theft of more than 400,000 Ether (ETH), Ethereum's native token, and stETH, valued then at roughly $1.5 billion. The exchange says the lawsuit is aimed at recovering assets and establishing accountability for what it describes as one of the largest digital-asset thefts ever recorded. Alongside the filing, Bybit obtained an early court order freezing some of the stolen funds still controlled by unidentified wallet holders and intermediary entities listed as unnamed defendants. The injunction bars those parties from moving or selling the blocked assets while the case proceeds. The company has framed the action as a civil track separate from ongoing U.S. criminal investigations, meaning its immediate purpose is recovery rather than prosecution. The underlying incident remains a defining security failure for the exchange sector: attackers took Ether and stETH from Bybit custody, triggering a multi-agency tracing effort and a broad review of custody controls. The scale of the loss has also drawn attention across the wider altcoin market, because the stolen assets were not a single token but a large block of Ether and a staking-derivative position. On-chain analytics firm Chainalysis underscores the wider North Korea problem: the firm has estimated that North Korea-linked actors have stolen about $6.75 billion in crypto assets over multiple operations, with part of the proceeds allegedly tied to weapons-program funding. Its filings argue that the legal route is necessary because part of the stolen value remains in addresses that investigators can still reach. Bybit's legal step matters even if enforcement against a sanctioned state is difficult, because it creates a formal record, reaches unknown intermediaries, and gives the exchange a mechanism to pursue funds that resurface on regulated platforms. The loss scale remains exceptional, even when compared with episodes that emerged during prior all-time-high market phases.
The more granular legal picture shows how Bybit moved through sealed filings before making the case public. The exchange initially filed the complaint under seal on June 18, obtained a temporary restraining order and expedited discovery one day later, renewed that order on July 16, and secured a partial preliminary injunction on July 30, according to unsealed court records. The court found that Bybit had shown a likelihood of success on the merits and treated the matter as among the most substantial crypto thefts ever recorded. The company has recovered about $48.4 million and frozen another $30.5 million across more than 28 exchanges and custody institutions, though that total remains a small fraction of the original $1.5 billion loss. Earlier disclosures indicated that 90.2% of the stolen assets had already passed through mixers, cross-chain bridges, and over-the-counter desks, leaving only 9.8% traceable to identifiable wallets at that time. The complaint also seeks punitive and multiplied damages under the U.S. Racketeer Influenced and Corrupt Organizations Act, adding a statutory penalty layer to the recovery effort. Bybit has credited enforcement actions that disrupted laundering routes, including German authorities' takedown of the eXch exchange and German and Swiss actions against Cryptomixer.io; the filing says more than $90 million moved through eXch in the weeks after the hack. The Federal Bureau of Investigation publicly attributed the theft to North Korean actors on February 26, 2025, calling the operation TraderTraitor and warning that stolen Ether was being converted into Bitcoin across thousands of addresses. Chief Executive Ben Zhou said the Lazarus operation attacked trust in the sector, and the exchange continues to share blockchain evidence with law enforcement. For tracing purposes, the civil case now turns less on the state defendants than on the unknown wallet holders and intermediaries who may still control identifiable recoverable funds.
COINOTAG's analysis is that the practical value of this litigation lies in the court's asset-freeze architecture rather than any near-term judgment against Pyongyang. The complaint filed in the U.S. District Court for the District of Columbia, the June 19 temporary restraining order, and the July 30 partial preliminary injunction establish the operative holding: Bybit demonstrated a likelihood of success, and covered defendants are barred from transferring frozen assets while discovery proceeds. That posture matters because state defendants are largely judgment-proof; the enforceable targets are traceable assets and third-party custodians within reach of U.S. process. The approach may shape future recovery attempts across exchange hacks, bridge exploits, and markets tied to algorithmic stablecoins or emerging AI crypto wallet systems.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


