Key Takeaways
- The Dubai-based crypto exchange has initiated civil proceedings in US federal court targeting North Korea, the Reconnaissance General Bureau, and the Lazarus Group following a February 2025 security breach
- The court approved expedited discovery measures, enabling Bybit to track stolen cryptocurrency through platforms operating in the United States
- Hackers successfully laundered 90.2% of the pilfered digital assets using cryptocurrency mixers and cross-chain bridge technologies
- Federal authorities issued a preliminary injunction to freeze specific stolen holdings controlled by unnamed defendants
- Approximately $75.5 million, representing just 5.3% of total stolen cryptocurrency, has been successfully frozen or retrieved
The cryptocurrency exchange Bybit has initiated legal proceedings in the United States District Court for the District of Columbia against the Democratic People’s Republic of Korea, its intelligence agency known as the Reconnaissance General Bureau, and the notorious cybercrime syndicate Lazarus Group. The litigation stems from a devastating cyberattack executed on February 21, 2025, which resulted in the theft of more than 400,000 Ether tokens from the Dubai-headquartered trading platform, valued at approximately $1.5 billion during the breach.
Federal investigators from the FBI formally attributed responsibility for the cyberattack to state-sponsored North Korean threat actors on February 26, 2025. American law enforcement agencies monitor this hacking collective under the designation TraderTraitor and have issued advisories to cryptocurrency exchanges and blockchain companies to blacklist transactions associated with wallet addresses tied to the money laundering infrastructure.
Federal Judge Authorizes Critical Recovery Mechanisms
The cryptocurrency platform submitted its lawsuit under confidential seal on June 18, 2026. Within 24 hours, a federal magistrate approved expedited discovery procedures. These legal instruments empower Bybit to demand disclosure of account ownership details, wallet balances, and complete transaction records from any cryptocurrency service providers maintaining operational infrastructure within United States jurisdiction.
Additionally, the court enacted a temporary restraining order on June 19, prohibiting unnamed defendants from moving or disposing of identifiable stolen digital assets. Judicial authorities extended that protective order on July 16, followed by the partial granting of a preliminary injunction on July 30.
The preliminary injunction functions as an interim protective measure rather than a conclusive legal determination. Its primary purpose is to safeguard recoverable assets throughout the duration of litigation proceedings.
Vast Majority of Stolen Cryptocurrency Disappears
According to documentation submitted on June 18, Bybit disclosed that 90.2% of the compromised digital assets had vanished from traceable blockchain pathways. Cybercriminals employed sophisticated obfuscation techniques including cryptocurrency tumbling services, cross-blockchain bridge protocols, and private over-the-counter trading networks to eliminate the forensic trail.
The exchange managed to trace just 9.8% of the stolen holdings to specific wallet addresses. From that fraction, investigators successfully froze or recovered 5.3% of the aggregate stolen amount, equivalent to roughly $75.5 million.
This represents a dramatic deterioration from initial recovery efforts. Bybit’s chief executive Ben Zhou stated over twelve months prior that investigators could still track 68.57% of the misappropriated funds. By April 2025, that percentage had plummeted to 27.6%.
The security compromise occurred when adversaries penetrated Safe Wallet’s cloud computing infrastructure by obtaining authentication credentials belonging to a Safe platform developer. The attackers inserted malicious software code, facilitating the large-scale theft operation.
Bybit maintains it fulfilled all customer withdrawal requests following the incident through emergency Ether acquisitions, secured credit facilities, and capital injections from partner organizations within the cryptocurrency industry. The exchange sustained uninterrupted business operations during the crisis period.
Through this legal action, Bybit demands restitution of all stolen digital assets, compensatory damages totaling approximately $1.5 billion, punitive damages, and enhanced treble damages pursuant to the United States Racketeer Influenced and Corrupt Organizations Act.
According to blockchain analytics firm Chainalysis, North Korean groups misappropriated an estimated $2.02 billion worth of cryptocurrency throughout 2025. The Bybit security breach constituted the largest single incident within that annual figure, elevating North Korea’s estimated aggregate cryptocurrency theft to approximately $6.75 billion. During April 2026, cyberattacks bearing hallmarks of Lazarus Group operations reportedly siphoned an additional $577 million from Drift Protocol and KelpDAO platforms.
Bybit clarifies that this civil litigation proceeds independently from concurrent criminal investigations conducted by United States federal authorities. The exchange indicates it will pursue additional legal remedies as the judicial proceedings advance.


