Bybit Sues North Korea Over $1.5B Crypto Hack

Bybit has filed a U.S. civil lawsuit against North Korea, its intelligence service and the Lazarus Group over the $1.5 billion crypto theft.
Key Takeaways
- Bybit has sued North Korea, its Reconnaissance General Bureau and the Lazarus Group over the $1.5 billion 2025 crypto theft.
- A U.S. federal court granted a preliminary injunction covering certain stolen digital assets while the case continues.
- The FBI formally attributed the Bybit hack to North Korea in February 2025 and identified the activity as TraderTraitor.
According to CoinDesk, the exchange filed the case in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea, the Reconnaissance General Bureau (RGB), the Lazarus Group and unidentified John Doe defendants.
The court also granted a preliminary injunction covering certain assets connected to the case, barring their transfer or dissipation while the litigation continues. Bybit says the measure is intended to preserve digital assets that may still be recoverable and plans to seek further relief from the court.
The FBI Had Already Blamed North Korea
The case stems from the February 21, 2025 attack that drained approximately $1.5 billion in virtual assets from Bybit.
Five days later, the FBI formally attributed the theft to North Korea. The agency identified the malicious cyber activity as “TraderTraitor.”
The FBI warned that the actors were rapidly converting portions of the stolen assets into Bitcoin and other cryptocurrencies and dispersing them across thousands of addresses on multiple blockchains.
Its IC3 public-service announcement urged exchanges, bridges, DeFi services, blockchain analytics firms and other virtual-asset businesses to block transactions connected to addresses being used to launder the stolen funds.
Lazarus Has Been Under U.S. Sanctions Since 2019
In September 2019, the U.S. Treasury Department sanctioned Lazarus Group, along with Bluenoroff and Andariel, describing them as North Korean state-sponsored cyber groups controlled by the RGB. Treasury identifies the RGB as North Korea’s primary intelligence bureau.
A joint FBI, CISA and Treasury advisory on TraderTraitor said North Korean actors had targeted cryptocurrency exchanges, DeFi protocols, blockchain companies, venture funds and individual crypto holders. The advisory described social engineering and malicious applications among the methods used to reach their targets.
Treasury has separately linked stolen virtual currency to North Korea’s wider revenue operations. In a 2023 sanctions action, the department said the DPRK uses stolen crypto and laundering networks to generate revenue for its unlawful weapons of mass destruction and ballistic missile programs.
Recovering the Stolen Crypto Will Be the Hard Part
Bybit is not the first party to use the D.C. federal court system to pursue crypto linked to North Korean operations.
In June 2025, the Justice Department filed a civil forfeiture complaint in the same federal district court involving more than $7.74 million allegedly tied to North Korean IT-worker schemes and cryptocurrency theft. DOJ said the funds had been frozen and seized while the actors attempted to launder them.
Bybit’s lawsuit is separate from ongoing U.S. criminal investigations, according to the exchange’s statement cited by CoinDesk.
The new court order can help preserve assets that Bybit manages to identify and bring within the scope of the case.
CoinDesk’s account of the filing does not establish how much of the original $1.5 billion remains identifiable, reachable or recoverable through the U.S. court process.
- Disclaimer: This article is for informational purposes only and does not constitute legal, financial or investment advice. Allegations in the lawsuit remain subject to court proceedings, and no final judgment has been issued.









