
The exchange filed a civil lawsuit in a US federal court against North Korea, its intelligence agency, and the Lazarus Group over the $1.5 billion hack of February 2025. A judge has already frozen stolen assets. The case tests whether civil law can do what criminal enforcement has not.
Summary
- Bybit filed a civil lawsuit on August 7, 2026, in the US District Court for the District of Columbia, naming North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group as defendants over the $1.5 billion crypto theft of February 21, 2025, which remains the largest recorded cryptocurrency hack.
- A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants, preventing them from transferring, selling, or otherwise disposing of the identified assets while the litigation continues.
- The FBI attributed the attack to North Korean actors operating under the name TraderTraitor shortly after the breach, and Bybit CEO Ben Zhou said the exchange had worked with investigators, regulators, other trading platforms, and law enforcement agencies since the attack.
- The traceability of stolen funds declined over time: 88.87 percent remained traceable in March 2025, but by April 2025, 27.6 percent could no longer be tracked after the attackers converted assets into Bitcoin and dispersed them across thousands of wallets using cross chain protocols and crypto mixers.
- North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025 alone, with cumulative theft reaching approximately $6.75 billion, and Lazarus linked attacks allegedly drained another $577 million from Drift Protocol and KelpDAO in April 2026.
On August 7, 2026, Bybit announced it had filed a civil lawsuit in the US District Court for the District of Columbia against the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group. The complaint concerns the February 21, 2025, breach that drained more than 400,000 Ether and staked Ether from the Dubai based exchange, an incident valued at approximately $1.5 billion at the time and still the largest recorded cryptocurrency theft.
The filing is unusual in almost every dimension. A private company is suing a sovereign nation in a US court. The defendants include a state intelligence agency and a hacking group that operates under its direction. The stolen assets have been laundered across thousands of wallets, converted between blockchains, and run through mixing services designed to break the transaction trail. And yet a federal judge granted a preliminary injunction, meaning a court has already determined that there is enough evidence and legal basis to freeze identifiable stolen assets while the case proceeds.
The question is not whether the lawsuit is symbolically important. It clearly is. The question is whether it can produce a practical outcome: the recovery of stolen funds, the creation of legal precedent for future cases, or both. The case arrives at a moment when the crypto industry is searching for institutional tools to complement its technical defenses. Blockchain tracing, exchange cooperation, and bug bounties have been the primary recovery mechanisms after major hacks. A civil lawsuit backed by a federal court order introduces a legal instrument that has not been widely tested in the crypto context but has deep precedent in traditional asset recovery litigation.
What the lawsuit actually claims
The complaint names three defendants. The Democratic People’s Republic of Korea is named as a sovereign state that directed the theft through its intelligence apparatus. The Reconnaissance General Bureau, North Korea’s primary foreign intelligence organization, is named as the agency that oversaw the operation. The Lazarus Group is named as the threat actor that carried out the technical execution.
The case is filed under theories of civil liability that do not require the defendants to appear in court. Bybit is pursuing the claim through the legal mechanisms available against sovereign states and their agents when those states are accused of sponsoring acts that cause financial harm to private parties. The Foreign Sovereign Immunities Act typically shields foreign governments from lawsuits in US courts, but exceptions exist for state sponsored terrorism and certain commercial activities.
Alongside the complaint, Bybit secured a preliminary injunction targeting John Doe defendants, unidentified individuals and entities that hold assets traced to the theft. The injunction bars them from transferring, selling, or otherwise disposing of the identified assets. A preliminary injunction is not a final ruling. It preserves property during litigation. But securing one requires demonstrating to a judge that the plaintiff is likely to succeed on the merits and that the assets would be at risk of dissipation without the order.
Bybit CEO Ben Zhou framed the filing in terms that emphasized accountability over financial recovery. “Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable,” Zhou said in a statement.
How the February 2025 hack unfolded
The breach occurred on February 21, 2025, when attackers compromised Bybit’s security infrastructure and drained more than 400,000 ETH and stETH from the exchange. The assets were valued at approximately $1.5 billion at the time, making it the single largest cryptocurrency theft ever recorded.
The FBI attributed the attack to North Korean actors within days. The bureau identified the perpetrators under the operational name TraderTraitor and urged exchanges, validators, and blockchain firms to block transactions connected to addresses identified in the laundering operation. The speed of the attribution was notable. US intelligence agencies had been tracking Lazarus Group operations for years, and the on chain signatures of the attack matched patterns from previous North Korean campaigns.
The attackers moved quickly to launder the stolen funds. Within the first week, a significant portion of the ETH was converted to Bitcoin through cross chain bridges. The Bitcoin was then dispersed across thousands of wallets in a pattern designed to overwhelm tracing tools. By March 2025, Bybit’s CEO reported that 88.87 percent of the stolen funds remained traceable, while 7.59 percent had gone dark through crypto mixers and 3.54 percent had been frozen.
The legal architecture of the complaint reflects a calculated strategy for navigating the unusual challenge of suing a sovereign nation and its intelligence apparatus. By filing in the District of Columbia, Bybit places the case in a jurisdiction where federal courts routinely handle matters involving foreign states and international sanctions. The FSIA exception for state sponsored terrorism is well established in this courthouse, with decades of precedent from cases against Iran, Syria, and Libya providing a roadmap for how plaintiffs can pursue claims against sovereign defendants who refuse to appear. The preliminary injunction freezing stolen assets demonstrates that the court is willing to exercise jurisdiction and issue enforceable orders even before the defendants respond, which in a case against North Korea may never happen.
The traceable share declined over the following months. By April 2025, Zhou disclosed that 27.6 percent of the stolen funds could no longer be tracked. The attackers used a combination of cross chain protocols, mixing services, and decentralized exchanges to obscure the trail. Each hop between chains and each pass through a mixer made the remaining funds harder to follow.
Bybit covered the immediate shortfall through ETH purchases, loans, and deposits from industry counterparties. The exchange continued processing customer withdrawals throughout the crisis, avoiding the liquidity collapse that has followed other major exchange hacks. The operational response was widely credited as one of the more effective post hack recoveries in the industry’s history.
The scale of the laundering operation reveals the sophistication of the North Korean apparatus. The attackers did not simply send the stolen ETH to a single mixer and wait. They ran a multi-stage pipeline. First, the ETH was swapped for other tokens through decentralized exchanges to break the direct link to the Bybit wallets. Then the tokens were bridged to other chains, primarily Bitcoin, through cross chain protocols. The Bitcoin was then split across thousands of newly created wallets in a pattern called “peel chain” laundering, where each wallet sends a small portion to a destination and forwards the remainder to the next wallet in the chain. Each stage added a layer of obfuscation, and the entire process was automated using scripts that executed faster than human analysts could follow in real time.
Why a civil lawsuit and why now
The timing of the filing raises an obvious question: why wait 18 months? The answer involves both legal strategy and the evolution of the available evidence.
Criminal investigations into the hack are ongoing. US law enforcement agencies, including the FBI, are pursuing their own cases against the North Korean actors. Bybit’s civil lawsuit is explicitly separate from those criminal proceedings. The exchange is not dependent on prosecutors’ timelines or priorities.
The laundering infrastructure that the Lazarus Group employed after the Bybit breach illustrates how state backed hackers have professionalized their operations to exploit the structural gaps in cryptocurrency compliance. Within hours of the theft, the stolen Ether moved through a cascade of intermediary wallets designed to break the chain of provenance. The funds then flowed through decentralized exchanges, cross chain bridges, and mixing services that do not perform know your customer checks. By the time law enforcement agencies began coordinating their response, a significant portion of the stolen assets had already been converted into bitcoin and routed through additional obfuscation layers. This rapid dispersal is a signature of North Korean crypto operations, refined through years of practice across multiple high profile thefts.
A civil lawsuit offers several advantages that criminal prosecution does not. First, the burden of proof is lower. Criminal cases require proof beyond a reasonable doubt. Civil cases require a preponderance of the evidence. Second, a civil plaintiff controls its own case. Bybit can pursue recovery on its own schedule rather than waiting for a criminal prosecution that may take years to culminate in a judgment.
Third, and most practically, a civil lawsuit with a preliminary injunction gives Bybit a legal instrument that exchanges and custodians must respect. When Bybit identifies stolen funds on a platform, it can now point to a court order rather than relying on voluntary cooperation. Exchanges that refuse to freeze assets covered by a federal court order face legal exposure of their own.
The 18 month gap also allowed the blockchain tracing to mature. The initial weeks after a major hack are chaotic. Funds move rapidly across chains and through mixers. Over time, some of that movement stops. Funds sit in wallets. They end up on exchanges where withdrawal requires interaction with regulated entities. The preliminary injunction targets those resting points, the wallets and accounts where traceable stolen funds currently sit.
Can you actually sue North Korea and collect
This is the question that makes the case unusual. Suing a sovereign nation in a foreign court is not standard practice, and collecting a judgment against a country that does not participate in the international financial system presents obvious challenges.
The legal framework for suing foreign governments in US courts is governed by the Foreign Sovereign Immunities Act. Under normal circumstances, foreign states are immune from suit in US courts. But exceptions exist. The terrorism exception, added after the 1996 amendments, allows claims against states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017.
Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question that the court will need to address. Previous cases under this exception have involved acts of physical violence, hostage taking, and material support for terrorist organizations. A cryptocurrency hack committed for financial gain rather than political violence may test the boundaries of the statute.
Even if Bybit obtains a default judgment (North Korea is unlikely to send lawyers to defend the case), collecting on that judgment against a state that operates outside the conventional financial system is a separate challenge. The practical value of the lawsuit lies not in extracting payment from Pyongyang but in the ancillary effects: the preliminary injunction that freezes assets, the legal precedent that future victims can cite, and the signal to exchanges and custodians that frozen assets have a court order behind them.
The John Doe component of the lawsuit is potentially more actionable. If the identities of individuals or entities holding the stolen funds are discovered during the litigation, they can be added to the case and subjected to enforcement actions. Unlike North Korea itself, individuals who hold stolen crypto and fail to comply with a federal court order face consequences that can be enforced.
The broader pattern of North Korean crypto theft
The Bybit hack was not an isolated incident. It was the largest single event in a sustained campaign of cryptocurrency theft that US intelligence agencies attribute to the North Korean state.
North Korean groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data. The Bybit attack accounted for most of that total. Cumulatively, North Korea linked groups have stolen approximately $6.75 billion in digital assets across multiple years of operations.
The threat continued into 2026. In April, Lazarus linked attacks allegedly drained $577 million from Drift Protocol and KelpDAO in two separate incidents. The attacks used different technical methods but shared the same operational playbook: identify a vulnerability in a DeFi protocol or exchange, exploit it rapidly, and move the stolen funds through a pre planned laundering chain that crosses multiple blockchains within hours.
The scale of the theft has geopolitical implications. US and South Korean intelligence agencies have assessed that North Korea channels crypto theft proceeds into its weapons programs, including nuclear and missile development. This assessment is one reason the FBI attributed the Bybit attack so quickly and why US authorities have been unusually active in coordinating with exchanges to freeze funds. The scale of the February 2025 breach, exceeding all prior incidents by a factor of three, forced the industry to confront the inadequacy of its existing response mechanisms and consider whether civil litigation might fill the enforcement gap that criminal prosecution has left open.
For the crypto industry, the North Korean threat has become a baseline security assumption rather than an exceptional risk. Exchanges, DeFi protocols, and bridge operators now design their security models with state sponsored attackers as a primary threat scenario. The Bybit lawsuit adds a legal dimension to what has primarily been a technical and operational response.
The pattern of North Korean attacks also reveals a preference for targeting infrastructure points where large amounts of value are concentrated in a single signing operation. The Bybit attack compromised the process by which the exchange moved funds between cold and warm wallets. The Ronin bridge attack targeted the validator set that controlled cross chain transfers. In both cases, the attackers identified the moment when a single compromised action could move the maximum amount of value. This targeting pattern has forced exchanges to rethink how they structure high value transactions, adding multi party computation, hardware security modules, and time delayed execution to what were previously routine operations.
What the case means for future hack recoveries
The Bybit lawsuit could create a template for how exchanges and other victims pursue stolen funds through civil courts. Previous major hacks, including the Ronin bridge theft in 2022 and the Wormhole exploit in the same year, relied primarily on law enforcement cooperation, voluntary freezes by industry participants, and bounty programs.
A civil lawsuit with a preliminary injunction adds a layer that voluntary cooperation cannot provide: compulsion. When a court orders assets frozen, the custodian holding them has a legal obligation to comply. The order converts a request into a requirement, and non compliance carries legal consequences.
The dual track approach, civil and criminal running simultaneously, also matters. Criminal cases move on prosecutors’ timelines and serve public enforcement objectives. Civil cases move on the plaintiff’s timeline and serve the plaintiff’s recovery objectives. When both tracks operate in parallel, the stolen funds face pressure from multiple legal directions.
For smaller victims who lack Bybit’s resources, the precedent matters more than the specific case. If the lawsuit succeeds in freezing and eventually recovering stolen assets, it creates a roadmap that other victims can follow. If it produces published court opinions on the jurisdictional and immunity questions, those opinions become tools that future plaintiffs can use to streamline their own cases.
The case also tests the crypto industry’s willingness to cooperate with civil court orders. Exchanges that receive freeze requests backed by a federal court injunction face a different calculus than exchanges that receive informal requests from a hack victim. The legal formalization of the recovery process could accelerate compliance across the exchange ecosystem.
There is also a deterrence argument, though its force against a state actor is debatable. Most criminal hackers weigh the expected profit against the expected penalty. For a state intelligence agency that channels theft proceeds into weapons programs, the calculus is different. But the lawsuit creates costs at the laundering stage. Every exchange that freezes assets in response to the court order reduces the amount that reaches its intended destination. If the civil lawsuit makes laundering 5 or 10 percent harder, that translates to hundreds of millions of dollars in stolen value that cannot be converted to cash. Over multiple operations, incremental friction at the laundering stage compounds into a meaningful reduction in the program’s effectiveness.
What to watch
Compliance with the preliminary injunction. The order is only as effective as the willingness of custodians and exchanges to enforce it. Watch for reports of exchanges freezing funds in response to the order, or for disputes where custodians challenge the scope of the injunction.
Additional defendants added to the case. The John Doe structure allows Bybit to add identified individuals and entities as discovery progresses. If blockchain tracing leads to specific custodians, exchanges, or OTC desks that processed stolen funds, they could become parties to the lawsuit.
North Korea’s response or non response. Sovereign defendants in US courts typically either invoke immunity and challenge jurisdiction or simply ignore the proceedings. North Korea’s approach will determine whether the case proceeds by default judgment or through contested litigation on the jurisdictional questions.
Recovery rate compared to criminal track. Bybit has been working with law enforcement since February 2025. The civil lawsuit now runs in parallel. Comparing the amounts recovered through each track will indicate whether civil litigation adds meaningful recovery capacity beyond what criminal enforcement achieves alone.
Follow on lawsuits from other hack victims. If the Bybit case survives jurisdictional challenges and produces asset recovery, other victims of state sponsored hacks may file similar civil complaints. Watch for cases from victims of the Drift Protocol and KelpDAO attacks, which are also attributed to Lazarus Group.
International coordination on asset freezing. The US court order applies to entities within US jurisdiction, but stolen crypto moves globally. Watch for parallel legal actions in jurisdictions like Singapore, the UK, and the EU, where exchanges and custodians may hold portions of the laundered funds. A coordinated multi-jurisdictional freeze would be significantly more effective than a single country order.
North Korean adaptation to the legal pressure. State sponsored hacking groups adapt their laundering techniques in response to enforcement actions. If the civil lawsuit makes conventional exchange-based laundering more difficult, the attackers may shift to peer-to-peer trading, decentralized exchanges without KYC, or privacy chains. The speed and nature of this adaptation will indicate how much friction the legal approach creates.
Frequently asked questions
u003cstrongu003eWhat is Bybit suing North Korea for?u003c/strongu003e
u003cpu003eBybit filed a civil lawsuit alleging that North Korea, through its Reconnaissance General Bureau intelligence agency and the Lazarus Group, stole approximately $1.5 billion in Ether and staked Ether from the exchange on February 21, 2025. The case was filed in the US District Court for the District of Columbia.u003c/pu003e
u003cstrongu003eHas a court already taken action?u003c/strongu003e
u003cpu003eYes. A US federal judge issued a preliminary injunction freezing certain stolen assets held by unidentified individuals and entities listed as John Doe defendants. The order prevents them from transferring or selling the identified assets while the case proceeds.u003c/pu003e
u003cstrongu003eHow much of the stolen funds has been recovered?u003c/strongu003e
u003cpu003eBybit has not disclosed a specific recovery figure. As of April 2025, 27.6 percent of the stolen funds could no longer be tracked. The remaining traceable portion is subject to ongoing recovery efforts through blockchain tracing, industry cooperation, and now the civil lawsuit.u003c/pu003e
u003cstrongu003eCan a private company actually sue a foreign country?u003c/strongu003e
u003cpu003eUnder the Foreign Sovereign Immunities Act, foreign states are generally immune from suit in US courts. However, exceptions exist for states designated as sponsors of terrorism. North Korea has been on the State Department’s state sponsor of terrorism list since 2017. Whether the cryptocurrency theft qualifies under the terrorism exception is a legal question the court will address.u003c/pu003e
u003cstrongu003eIs this lawsuit separate from the FBI investigation?u003c/strongu003e
u003cpu003eYes. Bybit explicitly stated that the civil lawsuit is being pursued independently of ongoing criminal investigations by US law enforcement agencies. The two tracks operate in parallel, each with different procedural rules, burdens of proof, and objectives.u003c/pu003e
u003cstrongu003eWhy did Bybit wait 18 months to file?u003c/strongu003e
u003cpu003eThe timing allowed blockchain tracing to mature, identifying where stolen funds currently sit. It also allowed Bybit to build a factual record sufficient for a preliminary injunction. Filing too early would have risked a weaker case with fewer identifiable assets to freeze.u003c/pu003e
u003cstrongu003eWhat happens if North Korea ignores the lawsuit?u003c/strongu003e
u003cpu003eIf North Korea does not respond, Bybit can seek a default judgment, a court ruling in its favor based on the defendant’s failure to appear. Default judgments against sovereign states are enforceable against the state’s assets within US jurisdiction, though North Korea holds minimal assets subject to US courts.u003c/pu003e
u003cstrongu003eCould other hack victims file similar lawsuits?u003c/strongu003e
u003cpu003eYes. The Bybit case could create a template for civil recovery actions by other victims of state sponsored cryptocurrency theft. If the case produces favorable court opinions on jurisdiction and immunity, those opinions become precedent that future plaintiffs can cite. This is educational analysis, not investment advice.u003c/pu003eu003cpu003eu003cemu003eDisclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets carry significant risk. Always conduct independent research before making investment decisions. Information is current as of August 8, 2026.u003c/emu003eu003c/pu003e
Feature,media,Regulation,SEC,securities,Trading#Bybit #suing #North #Korea #work1786344815

