Bybit sues North Korea over USD $1.5 billion theft
Tue, 11th Aug 2026 (Today)
Bybit has filed a civil lawsuit in a US federal court against North Korea, its Reconnaissance General Bureau and the Lazarus Group over a cryptocurrency theft valued at USD $1.5 billion.
It has also secured a preliminary injunction freezing identified digital assets allegedly linked to the attack. The order covers unnamed individuals and entities accused of holding or moving the funds. The case was filed in the US District Court for the District of Columbia.
Bybit alleges that North Korea and Lazarus, which US authorities have identified as a North Korea-linked hacking group, orchestrated a cyberattack in February 2025 that caused the loss. In granting an earlier temporary restraining order, the court described the incident as "one of the largest cryptocurrency thefts in history".
The injunction bars the transfer or dissipation of identified assets while the litigation proceeds. Bybit plans to seek further judicial relief as the case advances.
The civil action is separate from criminal investigations by US law enforcement. Bybit said it has shared blockchain intelligence and investigative findings with agencies including the FBI as authorities pursue broader enforcement efforts.
Recovery efforts
Bybit said it has been working with blockchain analytics firms, exchanges, custodians and international law enforcement agencies to trace the stolen funds and disrupt laundering routes. Those efforts have so far led to the recovery of about USD $48.4 million in stolen assets.
It also said more than USD $30.5 million has been frozen across more than 28 exchanges and custodians pending further legal and investigative action. Even so, only a small portion of the alleged theft has so far been recovered or restrained.
The case adds to growing scrutiny of cross-border cybercrime involving digital assets, where stolen funds can move quickly through multiple wallets, exchanges and mixing services. Civil proceedings serve a different purpose from criminal cases by trying to preserve assets before they are dissipated.
In the court order cited by Bybit, the judge said "Bybit has demonstrated a likelihood of success on the merits" in its lawsuit. That finding helped secure the preliminary injunction, although the underlying claims will still need to be tested as the litigation continues.
Ben Zhou, co-founder and chief executive officer of Bybit, linked the action to the exchange's response to the breach. "Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable," Zhou said.
"The Lazarus attack wasn't just an attack on Bybit. It was an attack on trust in our industry. That's why we've worked closely with investigators, exchanges, regulators, law enforcement, and now the courts. We hope this marks another step toward making crypto a much harder place for criminals to operate in and a much safer place for everyone else," Zhou said.
Broader crackdown
Bybit said the tracing effort has also supported wider action against infrastructure allegedly used to launder stolen funds. It pointed to moves by authorities in Germany and Switzerland against platforms named eXch and Cryptomixer.io.
According to Bybit, German authorities dismantled cryptocurrency exchange eXch, while German and Swiss authorities later disrupted Cryptomixer.io. The company said the two actions removed channels allegedly used to move illicit proceeds.
That reflects a broader pattern in crypto-related investigations, with exchanges, custodians, analytics groups and police agencies increasingly working across borders to trace flows of funds. Even so, recovery remains difficult once assets have been fragmented and moved through multiple services.
The lawsuit also highlights how private companies are turning to courts alongside regulators and criminal investigators when dealing with major breaches. Freezing orders can be an important tool in trying to stop suspected holders of assets from moving them beyond reach.
Zhou said the company's work did not end with the initial incident. "The real test comes after the crisis," he said.
"That's when you show whether your commitment is real. For us, that means continuing to strengthen our security, working hand in hand with investigators and industry partners, and doing everything we can to protect our users. Trust isn't something you claim. You have to earn it through action, every single day," he said.