The $1.4 billion hack suffered by Bybit is no longer played out only on technical grounds. Indeed, the exchange platform has just initiated legal proceedings against North Korea and the hacker group Lazarus, accused of being at the origin of the attack. This is an unprecedented initiative that could redefine the way in which Web3 players respond to cyberattacks attributed to States and open a new chapter in the legal protection of cryptos.

In brief
- Bybit sues North Korea, Lazarus Group and North Korean Intelligence (RGB) in US federal court.
- American justice grants an injunction ordering the immediate freezing of stolen assets around the world.
- Around $48.4 million has been recovered and more than $30.5 million is frozen across 28 partner platforms.
- CEO Ben Zhou reaffirms the top priority of protecting users and bringing those responsible to justice.
Bybit’s legal offensive in the American courts
The Bybit exchange has filed a sweeping federal lawsuit in the United States District Court for the District of Columbia. This legal action directly targets several key players in the state threat and quickly led to firm precautionary measures:
- The entities sued: the complaint specifically targets the Democratic People’s Republic of Korea (DPRK), its foreign intelligence service, the General Reconnaissance Bureau (RGB), the hacker collective Lazarus Group, as well as anonymous defendants referred to under the legal term “John Doe defendants”;
- The Court’s Decision: The federal court granted a preliminary injunction ordering the freezing of identified stolen assets, expressly stating that “Bybit has demonstrated a probability of success on the merits”.
This legal offensive follows the devastating attack suffered by the platform on February 21, 2025, considered by the magistrates to be “one of the biggest crypto thefts in history”. That day, hackers had compromised an Ethereum cold wallet by manipulating the Safe UI via a spoofing and targeted phishing technique.
The hackers had captured a colossal jackpot estimated at nearly $1.5 billion, made up of precisely 401,347 ETH, 90,375 stETH, 15,000 cmETH and 8,000 mETH. By choosing to initiate an autonomous civil action in the United States in parallel with criminal investigations carried out by law enforcement agencies such as the FBI, Bybit activates a binding legal lever allowing it to legally order financial intermediaries around the world to block suspicious flows.
The balance sheet and the official response from Bybit’s leadership
On an accounting and operational level, the international hunt carried out jointly with blockchain analysis companies is starting to bear fruit despite the complexity of laundering. To date, approximately $48.4 million of the stolen total has been physically recovered, while over $30.5 million is currently frozen across a network of over 28 third-party exchanges and custodians. These precautionary seizures demonstrate the effectiveness of immediate technical coordination between the major players in digital finance during a critical incident.
Reacting to these advances, Ben Zhou, co-founder and CEO of Bybit, reaffirmed his group’s top priority: “Our goal has never changed: to protect our users first, recover what we can, and ensure that the people behind these attacks are held accountable”.
He also insisted on the global scope of this battle, emphasizing that “Lazarus’ attack wasn’t just an attack on Bybit. This was an attack on trust in our industry. That’s why we’ve worked closely with investigators, exchanges, regulators, law enforcement, and now the courts. We hope this marks another step in making crypto a much tougher industry for criminals and a much safer ecosystem for everyone else”. The manager concluded on the rigor required in the management of such a financial trauma: “the real test comes after the crisis. This is where you show if your commitment is real”.
The noose tightens on North Korean financing
The scale of this issue fits into a global security context where digital assets have become major geopolitical targets. On-chain data published by Chainalysis indicates that North Korean hackers stole around $2.02 billion in crypto over the whole of 2025, bringing the cumulative balance sheet attributed to the Pyongyang regime to around $6.75 billion, largely intended to finance its weapons programs.
However, the unprecedented volume of the Bybit heist overwhelmed Lazarus’ usual mixing protocols, forcing cybercriminals to attempt to convert massive amounts of Ether into Bitcoin via over-the-counter (OTC) markets. This technical constraint left exploitable digital footprints on public registers, making it possible to identify and isolate destination addresses.
In the future, this unprecedented junction between blockchain traceability, inter-company cooperation and American civil law could transform risk management for the entire sector. Although North Korea’s sovereignty makes direct enforcement of judgments legally complex, the ability to obtain international freezing injunctions locks hackers’ access to fiat currency off-ramps. If this case law consolidates, the opportunity cost and operational difficulty of recycling stolen funds could reduce the attractiveness of state attacks against Web3 infrastructures.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
