Landmark: Bybit Sues North Korea & Lazarus For $1.5B Crypto Heist






Bybit Files Landmark Lawsuit Against North Korea and Lazarus Group Over $1.5 Billion Crypto Heist



By Ariel, CryptoCity


Bybit Launches Historic Lawsuit Against North Korea and Lazarus Group

In a groundbreaking legal maneuver poised to set a new precedent for international cyber accountability, leading cryptocurrency exchange Bybit has officially announced it is suing the North Korean government, its intelligence arm (the Reconnaissance General Bureau – RGB), and the notorious state-sponsored hacking collective, the Lazarus Group. The lawsuit, filed in the U.S. District Court for the District of Columbia, holds these entities responsible for a colossal crypto heist in February 2025, which saw approximately $1.5 billion in digital assets stolen.

This unprecedented legal action marks a pivotal moment in the history of cryptocurrency, representing the first instance where a crypto exchange has directly utilized the U.S. federal judicial system to pursue civil claims against a sovereign nation and state-level hackers. The court has already issued a preliminary injunction, effectively freezing funds in associated wallets and platforms implicated in the theft, signaling the gravity of the allegations.


Seeking $1.5 Billion in Damages Plus Triple Punitive Penalties

According to recently unsealed court documents, Bybit secretly initiated legal proceedings in June of this year, targeting the North Korean government, the RGB, and 20 unidentified “John Doe” defendants. The lawsuit, filed under the U.S. Racketeer Influenced and Corrupt Organizations (RICO) Act, demands approximately $1.5 billion in compensatory damages, alongside an additional claim for triple punitive damages, underscoring the severity of the alleged criminal enterprise.

Despite the intricate nature of tracing stolen digital assets, Bybit has reported significant progress in its recovery efforts. The exchange has successfully reclaimed approximately $48.4 million of the stolen assets, with an additional $30.5 million frozen across a network of 28 global exchanges and custodial institutions.

Image Source: Bybit Press Release | Bybit sues North Korean government and Lazarus Group across borders, seeking $1.5 billion and triple punitive damages.

The Elusive Trail: Most Stolen Funds Remain Unrecovered

However, the sophisticated methods employed by the perpetrators continue to pose significant hurdles for comprehensive asset recovery. Tracking data indicates that a staggering 90.2% of the stolen funds have become exceedingly difficult to trace, having been laundered through complex channels including mixers, cross-chain bridges, and Over-The-Counter (OTC) dealers. Only a mere 9.8% of the assets can currently be traced to specific wallet addresses.

Ben Zhou, CEO of Bybit, publicly reiterated the company’s unwavering commitment: “Our objective has never wavered – to diligently recover user funds and hold those responsible accountable. This attack not only impacted Bybit but represents a direct threat to the integrity and trust of the entire cryptocurrency industry.”

  • Related Report: Bybit $1.4 Billion Hack Tracking Progress: Nearly 28% of fund flows ‘severed’, 3.84% of assets successfully frozen.

Unpacking the Largest Crypto Heist: How Bybit Was Targeted

This incident, widely recognized as one of the largest cryptocurrency thefts in history, has been definitively attributed to North Korea’s Lazarus Group by blockchain security analytics firm Elliptic. The firm highlights the group’s extensive history, having allegedly stolen over $6 billion in assets since 2017 to finance North Korea’s illicit missile programs.

Bybit’s post-incident forensic investigation, conducted by third-party cybersecurity firm Sygnia, revealed a highly sophisticated attack methodology. Hackers infiltrated the development environment of Safe{Wallet} (formerly Gnosis Safe), injecting malicious code into its AWS S3 repository. This allowed them to subtly alter front-end transaction details, deceptively luring multi-signature signers into approving malicious contracts.

While Safe{Wallet} issued a statement asserting that its core smart contracts remained uncompromised, Binance founder Changpeng “CZ” Zhao publicly questioned the ambiguity of their explanation. Doubts were raised, particularly regarding how multiple signers could simultaneously be deceived during the hardware wallet verification process, indicating persistent questions surrounding supply chain security protocols and the incident’s full scope.

  • Related Report: The Largest Crypto Heist in History: Bybit Hack Incident Fund Flow Analysis, Where Did the Stolen Money Go?
  • Related Report: Bybit Audit Report: Attack Due to Safe Wallet Compromise, Safe’s Explanation Fails to Convince CZ

Bybit Navigates Regulatory Scrutiny Amidst Legal Battle

Concurrently with its groundbreaking lawsuit against North Korea, Bybit is also contending with significant global regulatory compliance challenges.

In June of this year, the Monetary Authority of Singapore (MAS) placed Bybit on its Investor Alert List, citing the exchange’s operation without the necessary local financial services license. Bybit responded with a statement clarifying that its headquarters relocated from Singapore to Dubai in 2022 and that it no longer provides services to Singaporean IP addresses, thereby operating outside local jurisdiction.

Furthermore, Bybit currently faces restrictions on providing services in several other key regions, including Canada, the United States, China, and Hong Kong. Malaysia’s Securities Commission has also taken enforcement action due to its unregistered operations, ordering the shutdown of related local platforms.

Despite this complex global regulatory landscape, Bybit’s aggressive judicial stance underscores its determination to leverage the U.S. federal court system. The exchange aims to establish a historical precedent for asset recovery against state-sponsored cyber attackers, potentially reshaping the future of accountability in the digital asset space.


(The above content is an excerpt and reproduction authorized by our partner “CryptoCity”, original link.)


Disclaimer: This article is for market information purposes only. All content and views are for reference only and do not constitute investment advice, nor do they represent the views and positions of BlockTempo. Investors should make their own decisions and trades. The author and BlockTempo will not be liable for any direct or indirect losses incurred by investors’ transactions.


About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these