BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Bybit takes North Korean hacker group to US court, over 90% of funds may be hard to recover

Foresight News
特邀专栏作者
2026-08-10 10:30
This article is about 1792 words, reading the full article takes about 3 minutes
Bybit sues North Korea and Lazarus Group in the US, obtaining court injunction to freeze stolen assets.
AI Summary
Expand
  • Core Insight: Bybit has filed a civil lawsuit against North Korea's Lazarus Group and obtained a preliminary injunction freezing some stolen crypto assets. However, only about 5% of the $1.5 billion stolen in the February 2025 incident has been recovered, highlighting the significant challenges cross-chain money laundering poses to asset recovery.
  • Key Elements:
    1. Bybit filed a lawsuit in a US court against the North Korean government, the Reconnaissance General Bureau, and Lazarus Group. The court approved a temporary restraining order, determining that Bybit has a likelihood of success on the merits.
    2. The court issued a preliminary injunction freezing some of the involved assets held by unidentified John Doe defendants, prohibiting them from transferring or selling these assets during the proceedings.
    3. On February 21, 2025, Lazarus Group hacked into the supply chain of Safe's multi-signature wallet, tampered with the transaction interface, and stole approximately 401,000 ETH and related tokens, valued at around $1.46 billion.
    4. The stolen ETH accounted for approximately 0.42% of Ethereum's total supply, temporarily making the hackers the 14th largest ETH holder globally. Within about 10 days of the attack, 53.3% of the funds were laundered through channels such as THORChain, and the price dropped by about 23%.
    5. Bybit, in cooperation with multiple parties, has recovered approximately $78.9 million in total, with about $30.5 million frozen across 28 exchanges—accounting for only about 5% of the total stolen amount. Platforms involved, such as eXch and Cryptomixer.io, have also been dismantled.
    6. North Korean hackers have stolen approximately $6.75 billion in crypto assets cumulatively, with over $2 billion stolen in 2025 alone. Sub-clusters under Lazarus Group, including UNC4736 and TraderTraitor, have been responsible for multiple major attack incidents.

Original author: Nicky, Foresight News

On August 8, Bybit filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People's Republic of Korea, its Reconnaissance General Bureau, and the DPRK-linked hacker group Lazarus Group, as reported by CoinDesk. The group stole approximately $1.5 billion in crypto assets from Bybit in February 2025, marking one of the largest cryptocurrency heists in history. The court granted a preliminary temporary restraining order, finding that Bybit has a "likelihood of success on the merits" of the case.

In addition to filing the lawsuit, Bybit successfully obtained a preliminary injunction freezing a portion of the stolen assets held by a group of unidentified individuals and entities named as "John Doe" defendants in the case. The injunction prohibits the relevant parties from transferring or selling the assets in question during the proceedings. Bybit stated it will continue to seek further relief from the court, emphasizing that this civil action is independent of ongoing criminal investigations by U.S. law enforcement.

On February 21, 2025, the Lazarus Group compromised the supply chain of Safe multisig wallets, tampering with the transaction interface while Bybit was transferring funds from its cold wallet to a warm wallet. By seizing control of the multisig process, the attackers redirected approximately 401,347 ETH, 90,375 stETH, 15,000 cmETH, and 8,000 mETH to hacker-controlled addresses — worth roughly $1.46 billion at the time. The stolen ETH accounted for approximately 0.42% of Ethereum's total supply, briefly making the hacker the world's 14th-largest ETH holder, with holdings exceeding those of Fidelity and Ethereum co-founder Vitalik Buterin.

The hackers' laundering operation began immediately after the attack. According to Spot On Chain monitoring, approximately 266,309 ETH — 53.3% of the total stolen — had been laundered within the first week, primarily swapped for BTC via THORChain, averaging roughly 48,420 ETH per day. By early March 2025, on-chain analyst EmberCN's tracking indicated the entire laundering process took about 10 days, during which ETH's price fell approximately 23%, and roughly 90.2% of the stolen funds had become untraceable. The hackers primarily laundered funds through THORChain, which generated approximately $5.9 billion in trading volume and roughly $5.5 million in fees from the activity.

To date, Bybit, in collaboration with blockchain analytics firms, multiple exchanges, and international law enforcement agencies, has recovered approximately $48.4 million of the stolen assets and facilitated the freezing of roughly $30.5 million in涉案 assets across more than 28 exchanges and custodians — totaling approximately $78.9 million, or only about 5% of the total amount stolen. The FBI confirmed the Lazarus Group as the perpetrator, and law enforcement agencies from multiple countries have coordinated follow-up actions. German authorities dismantled the涉案 cryptocurrency exchange eXch, and German and Swiss authorities jointly shut down the mixing platform Cryptomixer.io.

Despite some progress in law enforcement coordination, the vast majority of the stolen funds have evaded tracking through cross-chain bridges, mixers, and OTC channels. The injunction in the lawsuit only applies to identifiable on-chain assets, and funds that have flowed through mixers and cross-chain conversions into the hands of entities or individuals not subject to judicial freezing are extremely difficult to recover. At the time of the theft, ETH was priced at approximately $2,730; it now trades around $1,920, a decline of roughly 30%. Even if portions of the assets are located in the future, their actual value has diminished significantly.

Source: SotaMedia

The Lazarus Group is a North Korean state-sponsored cyber threat actor cluster operating under the Reconnaissance General Bureau, encompassing multiple sub-clusters including UNC4736 (also known as AppleJeus/Citrine Sleet) and TraderTraitor. According to Chainalysis, North Korean hackers have stolen approximately $6.75 billion in cryptocurrency through clusters such as Lazarus, with over $2 billion stolen in 2025 alone.

The organization has been responsible for numerous high-profile attacks worldwide: the 2014 breach of Sony Pictures Entertainment, the 2016 theft of $81 million from the Bangladesh Central Bank, the 2017 WannaCry ransomware global outbreak, the 2022 exploits of Ronin Bridge and Harmony Horizon Bridge with losses of $620 million and $100 million respectively, and the 2023 attacks on Atomic Wallet and Stake. In October 2024, UNC4736 attacked Radiant Capital and stole $50 million; in February 2025, TraderTraitor executed the record-breaking $1.5 billion theft from Bybit; and in April 2026, the group completed a $285 million attack on Drift Protocol.

exchange
Safety
Cross-chain
Welcome to Join Odaily Official Community