Cryptocurrency exchange Bybit filed a civil lawsuit in US Federal Court against North Korea, the Reconnaissance General Bureau, and the Lazarus hacker group over the theft of US$ 1.5 billion in Ethereum tokens in 2025. The petition, filed under seal on June 18, 2026, in the US District Court for the District of Columbia, became public this week.
The lawsuit identifies the defendants as responsible for the intrusion that diverted more than 400,000 Ethereum on February 21, 2025. The attack occurred during a routine transfer from one of the exchange's offline storage wallets.
According to the investigation, the hackers compromised the computer of a developer at Safe{Wallet}, a multi-signature protocol used by Bybit. A malicious code, activated when the exchange's wallet address appeared, altered the transaction and installed a backdoor, draining the assets within minutes.
Response and tracing
Bybit says it covered more than US$ 4 billion in customer withdrawal requests without freezing accounts, a measure to preserve trust in the exchange during the crisis. The company also paid US$ 2.3 million in rewards to investigators who helped trace the funds.
According to the exchange, about 90% of the stolen value became impossible to trace after the criminals converted the Ethereum into bitcoin and distributed the funds across thousands of wallets, using mixers, blockchain bridges, and unregulated platforms.
Context of attacks
The case is not isolated. Chainalysis, a blockchain analysis company, estimates that North Korean hackers stole about US$ 2.02 billion in cryptocurrencies in 2025, up 51% from the previous year. Researchers note that the regime has accumulated US$ 6.75 billion in stolen digital assets, funds that US authorities say finance weapons programs.
The Lazarus group has previously attacked cryptocurrency platforms, including the theft of US$ 620 million from the Ronin bridge and US$ 100 million from Harmony, both in 2022. Bybit's lawsuit alleges that these incidents constitute a pattern of organized crime and uses the RICO Act, in addition to the Computer Fraud and Abuse Act and the Alien Tort Statute.
Judicial measures
Bybit requests the return of the stolen assets, approximately US$ 1.5 billion in damages, as well as punitive damages. The court has already ordered injunctive measures: on June 19, a judge ordered the temporary suspension of transfers of traceable assets; on July 30, it partially granted a preliminary injunction freezing funds of unidentified defendants linked to the scheme.
So far, the exchange has recovered approximately US$ 48.4 million and frozen another US$ 30.5 million across more than 28 exchanges and custodians. The partnership with investigators also helped German authorities shut down the eXch exchange and a joint operation between Germany and Switzerland to take down mixer Cryptomixer.io, according to the company.
Zhou, a representative of Bybit, described the attack as "an attack on trust in our sector" and said the company will continue with the case alongside the authorities.
Legal experts are watching how the court will handle the allegations against a sovereign government, since collecting directly from North Korea is considered unlikely. The immediate effect may come from asset freezes and the discovery phase, which could pressure intermediaries holding stolen funds to return them.


