What to Know
- Bybit has filed a civil lawsuit against the Democratic People's Republic of Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group.
- The case was filed in the U.S. District Court for the District of Columbia.
- A federal U.S. court granted a preliminary injunction prohibiting the transfer or dissipation of identified assets connected to the case while litigation continues.
- Bybit says the action targets the alleged theft of approximately $1.5 billion in Ethereum, including over 400,000 ETH and stETH.
- The alleged hack took place on February 21, 2025, and has been described as the largest cryptocurrency heist in history.
- The exchange says certain stolen assets are held by unidentified individuals and entities named as John Doe defendants.
- Bybit says the civil action is separate from ongoing criminal investigations conducted by U.S. law enforcement authorities.
- Chainalysis data cited in the case context indicates North Korea stole $2.02 billion in crypto last year and $6.75 billion in total.
Bybit Turns to U.S. Courts After Historic Crypto Theft
Bybit has escalated its response to one of the crypto industry’s most consequential security breaches, filing a civil lawsuit against the Democratic People's Republic of Korea, the country’s Reconnaissance General Bureau intelligence agency and the Lazarus Group, a hacking organization identified as linked to the DPRK. The lawsuit was filed in the U.S. District Court for the District of Columbia and seeks to advance the exchange’s recovery efforts following the alleged theft of approximately $1.5 billion in Ethereum from the Dubai-based platform.
The case marks a notable legal step in the wider effort to hold state-linked cyber actors accountable for large-scale digital asset theft. Bybit, described as the world’s second-largest cryptocurrency exchange, is using civil litigation alongside cooperation with investigators, exchanges, regulators and law enforcement. The exchange says the proceedings are intended to preserve stolen funds, strengthen accountability and support broader international efforts to pursue those responsible for cybercrime targeting crypto markets.
Federal Court Freezes Identified Assets
A key development in the case is the preliminary injunction granted by a federal U.S. court. The order prohibits the transfer, sale or dissipation of identified assets tied to the alleged theft while litigation continues. In practical terms, the injunction is designed to stop respondents from moving or liquidating assets that Bybit says are connected to the hack, preserving them as the court process advances.
Bybit said the frozen assets are held by a group of unidentified individuals and entities named in the case as John Doe defendants. The use of John Doe defendants is common in complex cybercrime litigation where asset holders, intermediaries or participants may not yet be publicly identified. In crypto cases, tracing can reveal wallet flows and transaction paths before investigators or litigants can conclusively connect all activity to specific real-world identities.
The exchange framed the injunction as an important step in its efforts to recover funds and reinforce accountability for large-scale cybercrime. Asset freezes are particularly important in digital asset cases because crypto can be moved rapidly across wallets, exchanges, bridges and other infrastructure. Once assets are dispersed through multiple layers of transactions, recovery can become significantly more difficult, even when blockchain trails remain visible.
Alleged Lazarus Group Attack Targeted Ethereum Holdings
Bybit says the February 21, 2025 attack was carried out by the North Korean state-sponsored Lazarus Group and resulted in the theft of approximately $1.5 billion in Ethereum. The stolen assets included over 400,000 ETH and stETH, according to the exchange’s account of the incident. The scale of the theft placed it among the most damaging events ever recorded in the digital asset sector and intensified scrutiny of state-backed cyber operations targeting crypto firms.
The Lazarus Group has long been associated by governments and cybersecurity investigators with sophisticated hacking campaigns. In the crypto sector, the group’s alleged tactics have included social engineering, infrastructure compromise, private key targeting and laundering through a web of wallets and services. While techniques vary by case, the broader pattern has made centralized exchanges, decentralized finance protocols and digital asset custodians key targets for advanced threat actors.
For exchanges, the Bybit case underlines the systemic risk created when highly resourced attackers focus on hot wallets, transaction approval workflows and operational security gaps. The size of the alleged loss also highlights the importance of layered custody controls, transaction monitoring and cross-platform coordination after suspicious activity is detected. Market participants often view rapid industry-wide response as essential because stolen crypto can be moved through multiple venues in a short period of time.
North Korea Crypto Theft Remains a Global Concern
The alleged Bybit theft represented a major share of the $2.02 billion in crypto stolen by North Korea last year, based on Chainalysis data cited in the case context. In total, North Korean hackers have stolen $6.75 billion worth of crypto, according to the same data. Those figures have kept digital asset security at the center of discussions among exchanges, regulators and law enforcement agencies seeking to limit the use of stolen crypto in state-backed activity.
North Korea is widely believed to use illicitly obtained cryptocurrency to help fund its weapons program. That belief has made crypto hacks tied to the DPRK more than private-sector security incidents. They are also treated as national security and sanctions-enforcement concerns. When stolen assets move across exchanges, mixers, wallets or other crypto infrastructure, compliance teams may face pressure to identify exposure, freeze funds where possible and coordinate with authorities.
The Bybit lawsuit reflects the growing use of courts as one tool in the response to cyber-enabled financial crime. Criminal investigations remain central, but civil actions can help victims seek asset preservation orders, establish claims over stolen property and pursue parties that may be holding or controlling traceable assets. Bybit said its civil action is being pursued independently of ongoing criminal investigations conducted by U.S. law enforcement authorities.
Bybit Says User Protection Remains Central
Ben Zhou, co-founder and CEO of Bybit, said the exchange’s focus has not changed: protecting users, recovering what can be recovered and ensuring the people behind the attacks are held accountable. He also said the Lazarus attack was not only an attack on Bybit, but an attack on trust in the industry. His comments reflect the reputational stakes for crypto venues following major breaches, especially when the incident involves a widely used exchange and a large Ethereum loss.
Trust is a core operating asset for cryptocurrency exchanges. Users rely on trading platforms to safeguard deposits, execute withdrawals and maintain resilient security systems. When a major breach occurs, exchanges must manage both the technical recovery and the market confidence challenge that follows. Public legal action, asset tracing and cooperation with authorities can help demonstrate that an exchange is actively seeking recovery rather than treating the loss as closed.
Bybit said it will seek further relief from the court. While the preliminary injunction preserves certain identified assets, litigation can involve additional steps, including discovery, further asset tracing, claims against additional parties or requests for court orders aimed at recovery. The outcome will depend on how the case develops and whether the frozen or identified assets can ultimately be connected to the alleged theft in a way that supports recovery.
Why the Case Matters for Crypto Markets
The lawsuit comes at a time when institutional and retail users continue to weigh the benefits of crypto market access against the operational risks of digital asset custody. Large thefts can shape how regulators view exchange supervision, how compliance teams approach wallet screening and how platforms communicate with users after security incidents. A court-ordered freeze also sends a signal that blockchain-based asset tracing can be paired with traditional legal remedies.
For the broader market, the case may reinforce the importance of cooperation among exchanges. Stolen assets often pass through multiple points in the crypto ecosystem, making rapid communication and coordinated freezes critical when suspicious flows are identified. Even where attackers use obfuscation techniques, the transparency of public blockchains can allow investigators to follow transaction patterns and identify assets that may be subject to legal action.
The Bybit action also highlights the evolving relationship between decentralized asset movement and centralized legal enforcement. Crypto transactions can occur globally and quickly, but courts can still issue orders against identifiable assets, account holders, intermediaries and entities subject to their jurisdiction. That combination is becoming increasingly important as victims of crypto theft look beyond technical tracing and seek enforceable recovery mechanisms.
For now, the preliminary injunction preserves certain stolen assets while the litigation continues. The lawsuit against the DPRK, the Reconnaissance General Bureau and the Lazarus Group places one of the industry’s largest alleged hacks into a formal U.S. court process, while separate criminal investigations proceed. FXCOINZ will continue monitoring the case as it develops and as the exchange seeks further court relief.
Frequently Asked Questions (FAQs)
Who did Bybit sue?
Bybit sued the Democratic People's Republic of Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group, which has been identified as a DPRK-linked hacking organization.
Where was the lawsuit filed?
The civil lawsuit was filed in the U.S. District Court for the District of Columbia.
What did the U.S. federal court order?
The court granted a preliminary injunction that prohibits the transfer or dissipation of identified assets connected to the case while the litigation continues.
How much crypto does Bybit say was stolen?
Bybit says approximately $1.5 billion in Ethereum was stolen, including over 400,000 ETH and stETH.
When did the alleged hack occur?
The alleged hack took place on February 21, 2025.
Why are John Doe defendants named in the case?
Bybit says certain stolen assets are held by unidentified individuals and entities, which are named as John Doe defendants while the case proceeds.
Is the civil lawsuit separate from criminal investigations?
Yes. Bybit says the civil action is being pursued independently of ongoing criminal investigations conducted by U.S. law enforcement authorities.
Why is North Korean crypto theft a major concern?
North Korean hackers have stolen large amounts of crypto, and the country is widely believed to use illicitly obtained digital assets to fund its weapons program.
What could happen next in the Bybit case?
Bybit has said it will seek further relief from the court, while the preliminary injunction remains aimed at preserving identified stolen assets during litigation.
Photo by DS stories on Pexels
