Bybit $1.5B Suit Exposes Limits of Freezing Stolen Crypto

Bybit sued North Korea and Lazarus Group after a Feb. 21, 2025 hack that stole $1.46 billion. A U.S. court issued an injunction 532 days later; more than $1 billion was laundered within six months.

Bybit filed a lawsuit in the U.S. District Court for the District of Columbia after a Feb. 21, 2025 theft that it reports removed $1.46 billion from its systems. The complaint names North Korea, the Reconnaissance General Bureau and the Lazarus Group and seeks to freeze and recover assets tied to the attack.

A federal judge issued a preliminary injunction about 532 days after the theft, barring unnamed defendants from moving or selling identified assets. Public filings describe the order as covering specific assets but do not disclose the dollar value the injunction protects or confirm the broader $1.5 billion figure cited in some reports.

Blockchain analysis firms have documented a repeated laundering pattern used by groups linked to the Democratic People’s Republic of Korea: stolen funds move through centralized exchanges, cross-chain bridges, coin mixers and specialized laundering services over a period of roughly 45 days. Federal investigators asked exchanges, bridge operators and node providers to block transactions tied to those groups within days of the breach.

An analytics review covering the first six months after the hack found that more than $1 billion of the stolen funds had already passed through laundering channels before the recent court order. Industry and protocol responses in the immediate aftermath froze about $42.9 million, and the mETH protocol recovered roughly 15,000 cmETH, valued at nearly $43 million. Those actions together account for about $85.9 million, or 5.9% of the $1.46 billion figure Bybit reports.

How easily stolen crypto can be stopped depends on where the funds land. Native ether or bitcoin held in private wallets cannot be directly frozen because no central authority can block transfers. Tokens created by protocols or liquid-staking platforms can sometimes be restricted by their issuers or governance, while stablecoin issuers can often blocklist addresses depending on contract design. Centralized exchanges can freeze withdrawals and comply with seizure warrants. Bridges, decentralized autonomous organization-controlled wallets and over-the-counter brokers present mixed and often greater challenges for seizure and return.

Previous enforcement actions illustrate those distinctions. After a Lazarus-linked theft from another platform, U.S. authorities froze about 2,204 SOL at one exchange; the exchange transferred the assets to the U.S. government and a federal court later granted a default judgment forfeiting the funds. In a separate Arbitrum incident, a restraining notice accompanied roughly 30,766 ETH that had been frozen after an exploit; governance action moved the ETH to a wallet controlled by a lending protocol while the legal notice remained attached to the balance.

The U.S. Treasury designated the Lazarus Group, Bluenoroff and Andariel in 2019 as entities connected to North Korea’s Reconnaissance General Bureau, citing cyber operations that generate international revenue. Chainalysis reported that actors linked to North Korea stole more than $2 billion in cryptocurrency in 2025 and put cumulative DPRK-linked theft at least $6.75 billion.

Bybit’s court action requests the court’s help in tracing and freezing assets tied to the February 2025 theft. Public filings and the injunction do not list the total value protected. Independent analytics show a large portion of the value moved through laundering services in the months after the incident, while a smaller amount was frozen or recovered by industry and protocol actors in the immediate response period.

The litigation remains active in federal court. Further asset tracing, cooperation from custodians and additional legal steps are part of the process Bybit has initiated to pursue funds tied to the Feb. 21, 2025 theft.

Articles by this author