Bybit, a major cryptocurrency exchange, announced on August 7, 2026, that it has filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau (RGB), and the hacker group “Lazarus Group” in connection with the theft of approximately $1.5 billion worth of assets in February 2025.
This series of legal actions marks a full-scale effort to recover assets from the incident, which recorded the largest loss in the history of the crypto industry. Bybit simultaneously obtained a prejudgment attachment order against unspecified third parties holding or moving the stolen funds, implementing measures to prohibit the transfer or disposal of the siphoned assets.
According to Cointelegraph, a crypto-focused media outlet that reviewed the court filings, Bybit filed the lawsuit under seal on June 18, 2026. An expedited discovery order was granted the following day, June 19, enabling the flow of stolen funds to be traced across exchanges. A temporary restraining order (TRO) was also obtained that same day, renewed on July 16, and a partial preliminary injunction was granted on July 30. These measures have resulted in the freezing of assets held by unidentified “John Doe” defendants.
Such legal tools are critically important in the crypto world, where stolen funds can move instantaneously across numerous platforms. Expedited discovery orders compel exchanges and custodians to disclose wallet-related information, while freeze orders prevent funds from dissipating further during protracted recovery efforts.
North Korea’s Involvement and the FBI’s Assessment
The hack occurred on February 21, 2025. The damage amounted to approximately 401,000 ETH (roughly $1.5 billion at the exchange rate at the time). On February 26, 2025, just days after the incident, the U.S. Federal Bureau of Investigation (FBI) issued an assessment confirming North Korea’s involvement in the cyberattack and launched an investigation under the name “TraderTraitor.”
According to an analysis report by blockchain analytics firm Chainalysis, the attack originated from a phishing scam targeting Bybit’s wallet administrators. The criminal group fragmented the funds into countless addresses and attempted to launder them by exploiting decentralized exchanges (DEXs) and cross-chain bridges. The tactic of temporarily leaving stolen assets dormant to evade scrutiny was analyzed as a “classic delaying tactic” characteristic of North Korean-linked hackers.
Current Status and Limits of Asset Recovery
According to Bybit’s official statement, the company has directly recovered approximately $48.4 million in stolen assets on its own and has collaborated with over 28 exchanges and custodians to freeze more than $30.5 million worth of assets. However, the total amount of assets recovered and frozen represents only a small fraction of the total loss.
The court filings lay bare the harsh reality of asset recovery in massive cryptocurrency hacks. At the time of filing on June 18, 2026, the status of the stolen assets was as follows:
ItemPercentage / AmountAssets rendered untraceable90.2% of totalAssets remaining in identifiable wallets9.8% of totalAssets frozen or recovered5.3% of total (approx. $75.5 million)
Note: Percentages are as of the June 18, 2026, filing date.
As these figures show, even with court orders, the majority of the funds had already been laundered through mixers or untraceable wallets before legal action could be taken. Freeze orders have no power to recover assets that have already been washed.
Top Executive’s Statement and Future Policy
Ben Zhou, co-founder and CEO of Bybit, stated on his X (formerly Twitter) account that he has been pursuing multi-faceted tracing and recovery efforts since immediately after the breach. In the company’s statement, Zhou emphasized, “Our focus remains unchanged: first, protect our users, recover what can be recovered, and ensure that those behind the attack are held fully accountable.”
He characterized the attack as “a serious threat to the entire cryptocurrency industry” and indicated that the company will continue to thoroughly trace the outflow of funds and pursue recovery through legal means, in collaboration with blockchain analytics firms and law enforcement agencies.
This lawsuit presents a new template for how cryptocurrency exchanges can combine incident response with civil litigation when victimized by large-scale hacks. At the same time, it will further intensify pressure on exchanges and platforms through which stolen funds pass to strengthen compliance and transaction monitoring. While recovery is by no means guaranteed, the sequence of events—from a sealed filing to obtaining injunctive relief in just over a month—demonstrates how rapidly civil remedies can be deployed in the aftermath of a major breach.