Gold 24K AED 510.51/gUSD/AED 3.6725USDT/AED 3.6698AED/INR 25.94All live rates →

Bybit Sues North Korea Over Its $1.5B Hack and Wins a Rare Asset Freeze

Dubai-headquartered Bybit has taken the largest crypto theft in history into a US courtroom. The Bybit Lazarus Group lawsuit, filed in the US District Court for the District of Columbia, names the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group as defendants over the February 2025 hack that drained roughly $1.5 billion from the exchange. Alongside the filing, Bybit said it secured a preliminary injunction freezing identified stolen assets held by unnamed John Doe respondents.

Key takeaways: the suit was filed in the US District Court for the District of Columbia and disclosed on 7 August 2026; the injunction bars transfer or dissipation of identified assets while litigation continues; the February 2025 attack took over 400,000 ETH and stETH worth about $1.5 billion; Bybit says the civil action runs independently of ongoing US criminal investigations.

What the Bybit Lazarus Group lawsuit is asking for

The mechanics matter more than the headline. Bybit did not win a judgment. It won a preliminary injunction, which is a holding order: a federal judge has directed the respondents not to move or sell the identified assets while the case runs. In its statement, Bybit described the order as intended to preserve identified stolen digital assets during litigation, and said it will seek further relief from the court.

The John Doe structure is the notable procedural choice. Rather than waiting to identify every holder of traced funds, Bybit named unknown individuals and entities as defendants and pursued relief against the assets themselves. That approach has been used before in crypto asset-recovery work, but rarely at this scale and rarely against a defendant list that includes a sovereign state and its intelligence service.

Chief executive Ben Zhou framed the filing in industry terms, saying the Lazarus attack was not only an attack on Bybit but an attack on trust across the sector, and that the exchange had worked with investigators, exchanges, regulators, law enforcement and now the courts. Bybit also stressed that the civil action is being pursued independently of criminal investigations run by US authorities.

The scale of the underlying theft

On 21 February 2025, attackers identified by US authorities as the North Korean state-sponsored Lazarus Group executed what remains the largest cryptocurrency heist on record, taking over 400,000 ETH and stETH worth approximately $1.5 billion from Bybit. That single incident accounted for the bulk of the roughly $2.02 billion in crypto stolen by North Korean actors that year.

Cumulatively, Chainalysis data puts North Korean crypto theft at about $6.75 billion. The proceeds are widely believed to fund the country’s weapons programme, which is why the response has historically come through sanctions and criminal enforcement rather than private litigation. Our coverage of the record pace of crypto exploits in 2026 sets out how persistent this category has become.

Why a civil suit, and why now

Criminal enforcement against DPRK actors runs into an obvious limit: the defendants are not going to appear. Indictments and sanctions designations impose cost and constrain movement, but they do not directly recover funds for the victim. A civil action with asset-freezing relief tries to work a different lever, using the court’s authority over the intermediaries and holders that touch the money rather than over the hackers themselves.

That is also the strategy’s weakness. An injunction is only as effective as the willingness and ability of custodians, exchanges and jurisdictions holding the traced assets to honour it. Funds sitting on cooperative regulated venues are reachable. Funds already routed through mixers, cross-chain bridges or non-cooperative jurisdictions are considerably less so.

What it means

The precedent value is the real story here, and it cuts in a specific direction. If a court is willing to grant preservation relief against traced state-linked theft proceeds, exchanges gain a tool they did not obviously have before: the ability to act on their own timeline rather than waiting for a government to act on theirs. That is meaningful for any venue that has been hacked and watched enforcement move at diplomatic speed.

For the UAE specifically, there is a second angle. Bybit is Dubai-based, and its willingness to litigate in a US court reinforces a pattern the Emirates has been cultivating deliberately: firms licensed in the region behaving like regulated financial institutions rather than offshore venues. Whether the case survives sovereign immunity challenges is genuinely uncertain, and the eventual recovery figure may be far smaller than the headline. But the attempt itself changes what a hacked exchange is expected to do next.

FAQ

Does the injunction mean Bybit gets the stolen funds back?

No. A preliminary injunction is a preservation order, not a recovery. It bars the named John Doe respondents from transferring or dissipating identified assets while the case proceeds. Whether any of those assets are ultimately returned to Bybit depends on the outcome of the litigation and on cooperation from the platforms and jurisdictions holding them.

Can you actually sue a sovereign state in a US court?

Foreign states have broad immunity under the US Foreign Sovereign Immunities Act, but that immunity has exceptions, and plaintiffs have used them before in terrorism and state-sponsored harm cases. Whether Bybit clears that bar against the DPRK and its Reconnaissance General Bureau is one of the central legal questions the case will have to resolve.

Sources: CoinDesk, Bybit press release via PR Newswire, Chainalysis.

This article is for information only and is not financial, legal or investment advice. Cryptonite does not make price predictions. Always do your own research and consult a qualified professional before making decisions.

📧 The Gulf reads Cryptonite first
Get MENA regulation moves, RWA deals and AI-money trends in one weekly brief — plus instant alerts when the MENA Regulation Tracker changes. Free, no spam.
Was this briefing useful?Thanks for the feedback!
Vaibhavv Ali
Vaibhavv Ali

Vaibhavv Ali is the founder and editor of Cryptonite (cryptonite.ae), an independent digital-asset news and analysis publication with a UAE focus. He covers virtual-asset regulation — VARA, ADGM and the UAE Central Bank — alongside real-world-asset tokenization, stablecoins and agentic AI in finance. Every Cryptonite article is human-edited and its sources are linked.

More articles by Vaibhavv Ali →

Leave a Comment

About  ·  Contact  ·  Privacy Policy  ·  Editorial Policy  ·  Advertise  ·  Newsletter
Follow: X  ·  LinkedIn  ·  Instagram  ·  Binance Square  ·  CoinMarketCap  ·  Gate