Key Points
- The cryptocurrency exchange initiated legal proceedings in US federal court targeting North Korea, its Reconnaissance General Bureau, and the Lazarus hacking collective following the February 2025 security breach
- Bybit secured expedited discovery rights from a federal judge, enabling the platform to track stolen cryptocurrency across US-registered services
- Hackers successfully obscured 90.2% of stolen digital assets using mixing services and blockchain bridge technologies
- Courts approved preliminary measures to freeze identifiable stolen holdings controlled by unnamed defendants
- Approximately $75.5 million, representing just 5.3% of total stolen funds, has been successfully frozen or retrieved
The Dubai-headquartered cryptocurrency platform has initiated civil proceedings in the US District Court for the District of Columbia, formally accusing North Korea, its intelligence arm known as the Reconnaissance General Bureau, and the notorious Lazarus hacking organization. The legal action stems from the devastating February 21, 2025 security breach that resulted in the theft of more than 400,000 Ether tokens from the exchange, valued at approximately $1.5 billion during the incident.
Federal investigators confirmed North Korean involvement in the cyberattack on February 26, 2025. American law enforcement agencies monitor this hacking operation under the designation TraderTraitor and have issued guidance to cryptocurrency platforms and blockchain companies to reject transactions associated with wallet addresses tied to the money laundering network.
Federal Judge Authorizes Critical Investigative Powers
Bybit submitted the legal complaint under confidential seal on June 18, 2026. Within twenty-four hours, a federal magistrate approved expedited discovery procedures. This judicial authorization empowers Bybit to demand identification records, account balance information, and comprehensive transaction logs from any service providers operating within United States jurisdiction.
The presiding judge simultaneously issued a temporary restraining directive on June 19, blocking unnamed respondents from moving any identifiable stolen digital assets. This protective order received an extension on July 16, followed by partial approval of a preliminary injunction on July 30.
The preliminary injunction functions as an interim protective measure rather than a conclusive judgment. Its purpose is to safeguard remaining assets during ongoing litigation.
Majority of Stolen Cryptocurrency Beyond Recovery
According to documentation submitted on June 18, Bybit confirmed that 90.2% of the compromised digital assets had disappeared from traceable blockchain pathways. The perpetrators employed sophisticated laundering techniques including cryptocurrency tumblers, cross-blockchain transfer protocols, and private over-the-counter exchanges to eliminate tracking capabilities.
The remaining 9.8% had been successfully traced to specific wallet addresses. Within that portion, approximately 5.3% of the complete theft amount—roughly $75.5 million—had been successfully frozen or reclaimed.
This represents a dramatic decline from initial recovery prospects. Bybit’s chief executive Ben Zhou reported over twelve months prior that 68.57% of the stolen cryptocurrency remained within tracking range. By April 2025, that percentage had collapsed to just 27.6%.
The security breach occurred when attackers penetrated Safe Wallet’s cloud computing systems using authentication credentials stolen from a Safe platform developer. The intruders inserted malicious programming code, facilitating the large-scale asset extraction.
Bybit maintains it ensured uninterrupted customer withdrawal services following the incident by acquiring Ether through market purchases, securing institutional loans, and receiving deposits from partner organizations within the cryptocurrency industry. The platform reported no disruption to standard operations.
Through this litigation, Bybit demands restitution of all stolen digital assets, compensatory damages totaling approximately $1.5 billion, additional punitive damages, and enhanced treble damages authorized under the United States Racketeer Influenced and Corrupt Organizations Act.
North Korean groups successfully stole an estimated $2.02 billion worth of cryptocurrency throughout 2025, based on intelligence compiled by Chainalysis. The Bybit incident accounted for the vast majority of that annual figure, elevating North Korea’s cumulative cryptocurrency theft to approximately $6.75 billion. Additional attacks in April 2026 attributed to Lazarus-affiliated operatives allegedly extracted another $577 million from Drift Protocol and KelpDAO platforms.
Bybit emphasizes that this civil litigation proceeds independently from active United States criminal investigations. The cryptocurrency exchange confirms its intention to pursue additional legal remedies as proceedings advance.
The post Bybit Takes Legal Action Against North Korea Following $1.5B Cryptocurrency Theft appeared first on Blockonomi.

4 hours ago
12
Bybit sues North Korea over the $1.5 billion Lazarus Group crypto heist.






English (US) ·