Bybit has launched a civil case in U.S. federal court against North Korea, its Reconnaissance General Bureau and the Lazarus Group, seeking to recover assets taken in the exchange’s February 2025 hack. The lawsuit was filed in the U.S. District Court for the District of Columbia.

The case centers on the Feb. 21, 2025 breach that drained more than 400,000 ETH and staked ETH from the Dubai-based exchange. Those holdings were worth about $1.5 billion at the time, making the incident the largest recorded cryptocurrency theft.

Court action follows FBI attribution

U.S. authorities linked the attack to North Korea soon after the breach. The FBI attributed the operation to actors it tracks as TraderTraitor and urged exchanges, validators and blockchain firms to block transactions tied to addresses identified in the laundering effort.

Bybit said it has worked with investigators, regulators, law enforcement agencies and other trading platforms since the theft. Co-founder and chief executive Ben Zhou said the company’s priorities were to protect users, recover assets where possible and hold those responsible accountable.

Injunction targets identified stolen assets

Alongside the lawsuit, Bybit obtained a preliminary injunction covering certain stolen assets held by unidentified people and entities listed in the case as John Doe defendants. The order bars those defendants from transferring, selling or otherwise disposing of the identified assets while the litigation continues.

The injunction preserves the property during the case, but it is not a final decision on liability or ownership. Bybit said it plans to seek additional relief as the civil action moves forward, separate from ongoing U.S. criminal investigations.

Tracing effort became harder over time

The civil case gives Bybit another path to pursue the missing funds after months of relying on blockchain tracing, voluntary freezes by industry participants and a bounty program tied to recoveries. Lazarus-linked wallets used cross-chain protocols and crypto mixers to make the transaction trail more difficult to follow.

Earlier reporting cited by the company showed that in March 2025, 88.87% of the stolen funds remained traceable, while 7.59% had gone dark and 3.54% had been frozen. That picture worsened as the attackers converted assets into Bitcoin and spread them across thousands of wallets. By April 2025, Zhou said 27.6% of the stolen funds could no longer be tracked.

Bybit previously offered rewards to platforms and investigators that helped identify or freeze stolen assets. The exchange also said it covered the shortfall after the hack through Ether purchases, loans and deposits from industry counterparties, allowing customer withdrawals to continue.

Broader North Korea crypto theft probe continues

The lawsuit opens a U.S. civil route for asset recovery while federal agencies continue examining North Korea’s cryptocurrency operations. Any eventual recovery is likely to depend on whether the defendants, or exchanges and custodians that control identified assets, comply with the court order.

Chainalysis data previously cited by crypto.news estimated that North Korean groups stole $2.02 billion in cryptocurrency during 2025, with the Bybit attack accounting for most of that amount and lifting the country’s cumulative crypto theft to about $6.75 billion. The activity has continued into 2026, with Lazarus-linked attacks allegedly draining another $577 million from Drift Protocol and KelpDAO in April.

The next confirmed step in the Bybit case is the exchange’s effort to seek permanent relief and recover the assets covered by the injunction. The court has not yet issued a final judgment.

Source: crypto.news