Bybit has launched an unprecedented civil case against North Korea after a massive $1.5 billion theft from the exchange in February 2025, and has already secured a U.S. court order freezing a portion of the stolen assets that investigators have managed to track.
The complaint, filed in the U.S. District Court for the District of Columbia, targets the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the Lazarus Group – the state-linked hacking collective that U.S. authorities have long accused of orchestrating high‑profile crypto and financial cyberattacks. The filing also lists a series of unknown individuals and entities as “John Doe” defendants, covering anyone believed to be holding, moving, or laundering the stolen funds.
According to Bybit, investigators have so far recovered approximately $48.4 million connected to the hack and successfully frozen another $30.5 million in assets tied to the attackers. That total remains only a small fraction of the estimated $1.5 billion drained in the February breach, underscoring both the scale of the incident and the complexity of tracing funds across global blockchain networks and opaque off‑chain channels.
A federal judge granted a preliminary injunction blocking any transfer, disposal, or concealment of the identified assets while the case moves forward. In issuing the order, the court found that Bybit is likely to prevail on the merits of its claims, based on the evidence submitted to date. The injunction is designed to prevent the stolen funds from being dissipated, mixed, or further laundered while legal proceedings and forensic work continue.
The lawsuit marks one of the clearest attempts yet by a major crypto exchange to use civil litigation against a nation‑state and its affiliated hackers, rather than relying solely on law enforcement, sanctions regimes, or diplomatic pressure. By naming the DPRK, its intelligence apparatus, and Lazarus directly, Bybit is effectively arguing that the theft was not just a private cybercrime incident, but an operation directed or supported at the state level.
From a legal perspective, the case hinges on a combination of cybercrime, money laundering, conversion, and unjust enrichment claims, along with arguments that the funds remain traceable even after passing through mixing services, chain‑hopping, and complex obfuscation techniques. While much of the detailed legal strategy remains sealed or confidential, the preliminary order suggests the court found Bybit’s tracing and attribution evidence compelling enough to justify immediate asset freezes.
The inclusion of John Doe defendants is a key tactical move. It gives Bybit and its investigators the flexibility to add specific names later as new wallet owners, over‑the‑counter brokers, shell companies, or intermediaries are identified. This is particularly important in crypto cases, where addresses, exchanges, or custodians involved in moving tainted funds might emerge only gradually as on‑chain and off‑chain investigations progress.
Where the money went has become the central question for both the exchange and regulators. The attackers are believed to have rapidly dispersed the stolen crypto through a web of wallets, cross‑chain bridges, decentralized protocols, and centralized exchanges in multiple jurisdictions. Portions were allegedly pushed through mixers and privacy‑focused tools designed to break the visible link between the original hacked wallets and their final destinations.
Despite these efforts to obscure the trail, blockchain analytics firms working with Bybit have been able to flag and follow significant chunks of the funds. That work underpins the $48.4 million already recovered and the $30.5 million frozen under the court’s order. In practice, “recovery” often means compelling intermediaries-such as exchanges, custodians, or stablecoin issuers-to lock down assets once they are identified as proceeds of crime.
The amount still unaccounted for remains enormous, and it is unlikely that all of it will ever be clawed back. Once stolen crypto is mixed, swapped across chains, and potentially cashed out into fiat in less regulated or cooperative jurisdictions, the chances of full restitution diminish quickly. Bybit’s lawsuit is therefore as much about deterrence and precedent as it is about making customers whole.
The case also fits into a broader pattern of North Korea‑linked cyber activity aimed at financing the sanctioned regime. U.S. officials have repeatedly asserted that operations attributed to Lazarus and other DPRK‑affiliated groups help fund weapons programs and offset the economic impact of international sanctions. Bybit’s decision to pursue a civil route in U.S. courts aligns with that narrative, positioning the hack as part of a larger geopolitical and security issue rather than an isolated crime.
For the crypto industry, the lawsuit raises a series of practical and strategic questions:
– How far can exchanges go in using civil litigation to reclaim stolen assets, especially when nation‑states and sanctioned actors are involved?
– Will other platforms follow Bybit’s lead and file similar suits in U.S. or other jurisdictions after major breaches?
– To what extent will courts accept blockchain forensics as reliable, court‑grade evidence for injunctions and judgments?
The preliminary injunction is notable for what it implies about the third question. By granting early relief, the court signaled that sophisticated on‑chain analysis and supporting documentation can meet the threshold required to freeze assets and protect a plaintiff’s interests, even before a full trial on the merits.
The suit may also accelerate closer cooperation between exchanges, analytics providers, and traditional financial institutions. To trace $1.5 billion effectively, investigators must monitor flows not only on public blockchains but also through stablecoin issuers, OTC desks, bank rails, and other infrastructure where crypto and fiat meet. Each successful freeze or recovery reinforces the idea that the crypto ecosystem can respond collectively to major hacks, making large‑scale theft less attractive over time.
In parallel, the case underscores the rising compliance burden on exchanges. Platforms are under pressure to refine their transaction monitoring, sanctions screening, and incident response frameworks so they can move as quickly as possible when a breach occurs. The speed at which Bybit and its partners were able to identify and lock down tens of millions of dollars demonstrates that exchanges with strong internal controls and external partnerships can materially limit the damage from even very large attacks.
For users, the lawsuit is a reminder that centralized exchanges remain high‑value targets for sophisticated attackers, including state‑sponsored ones. It also highlights why know‑your‑customer checks, withdrawal monitoring, and risk‑based limits exist: these controls do not just satisfy regulators; they create friction that can slow or block the laundering of stolen assets. When a major incident occurs, the existence of robust controls can mean the difference between losing everything and recovering at least a portion of the missing funds.
Looking ahead, the outcome of Bybit’s case could shape how future cross‑border crypto hacks are handled. A judgment against North Korea and its affiliated actors-even if mostly symbolic in terms of direct enforcement-would strengthen the legal foundation for seizing assets tied to DPRK hacking in other cases. It could also encourage more aggressive use of asset‑freezing tools, secondary sanctions, and cross‑jurisdictional cooperation to target exchanges, brokers, or service providers that knowingly facilitate laundering.
At a higher level, the lawsuit illustrates how crypto disputes are increasingly moving into mainstream legal and policy arenas. What began as a security incident at a private exchange has become a test case for the intersection of digital assets, international law, cyberwarfare, and sanctions enforcement. As large‑scale hacks continue and state‑linked groups remain active, more exchanges may find themselves weighing similar strategies-combining technical defenses, rapid incident response, and direct legal action against the actors and states they believe are responsible.
For regulators and policymakers, Bybit’s move adds urgency to ongoing debates about how best to oversee crypto markets, protect users, and counter the use of digital assets for illicit finance. Enhanced information‑sharing, standardized incident reporting, and clearer pathways for cross‑border cooperation may all emerge as priorities as cases like this one work their way through the courts.
Bybit’s battle to claw back funds from a $1.5 billion theft is far from over. But the early asset freezes and the court’s finding that the exchange is likely to succeed on the merits signal that, even in the murky world of state‑sponsored hacking and crypto laundering, there are legal levers that can be pulled-and that the industry is increasingly willing to use them.

