Bybit Files Historic $1.5 Billion Lawsuit Against North Korea Over Crypto Hack
Bybit, one of the world's largest cryptocurrency exchanges, has taken an unprecedented legal step by suing the North Korean government, its military intelligence agency (RGB), and the notorious hacker group Lazarus. The lawsuit, filed in the U.S. Federal Court for the District of Columbia, marks the first time a private commercial crypto entity has directly sued a sovereign state for a cyberattack and digital asset theft.
In February 2025, Lazarus, identified by U.S. intelligence as operating under North Korean government sponsorship, stole approximately 500,000 Ethereum coins valued at $1.5 billion from Bybit. The hackers exploited Bybit's internal system, deceiving employees into approving transfers that appeared legitimate but actually sent hundreds of millions of dollars to the attackers' accounts. Despite efforts to trace the stolen funds, about 90% have vanished through sophisticated laundering techniques, including mixing funds, cross-blockchain transfers, and private sales, with most Ethereum converted into Bitcoin.
Bybit has pursued recovery aggressively, filing a RICO lawsuit against North Korea, RGB, and Lazarus. A judge ruled there is a high likelihood of success and ordered freezing of recovered assets. However, North Korea does not recognize U.S. court jurisdiction and is unlikely to participate in proceedings, making direct collection of the full amount from Pyongyang improbable. So far, Bybit has recovered roughly $48.4 million and frozen an additional $30.5 million across more than 28 exchanges, about 5% of the stolen sum.
The case has broader implications amid rising cyber threats linked to North Korea. German authorities recently shut down the crypto exchange eXch, suspected of laundering stolen funds including some from the Bybit hack, and jointly with Swiss authorities dismantled Cryptomixer.io, a platform used to obscure illicit crypto origins. Meanwhile, North Korean hacker groups like Kimsuky and BlueNoroff have upgraded their tactics using AI to conduct sophisticated cyberattacks, including deepfake Zoom calls to install malware targeting crypto wallets. These groups focus heavily on the crypto industry, with founders and CEOs as prime targets.
According to a recent TRM Labs report, North Korean-affiliated hackers stole about $600 million in cryptocurrency from January to April 2026, accounting for 76% of global crypto theft in that period. Attacks in April on platforms Drift Protocol and Kelp DAO involved direct assaults on authentication and digital signature systems, mirroring the Bybit breach method and suggesting centralized coordination by Lazarus and its handlers. This lawsuit by Bybit is seen as a potential game-changer in combating state-sponsored cyberterrorism in the crypto sector.