Bybit sues North Korea, Lazarus Group over $1.5 billion hack, secures asset freeze

Bybit sues North Korea, Lazarus Group over $1.5 billion hack, secures asset freeze

Bybit, the world’s second-largest cryptocurrency exchange, has filed a civil lawsuit against North Korea and its intelligence agencies. The suit names the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and the notorious Lazarus Group. It was lodged today in the U.S. District Court for the District of Columbia.

This action follows February 21, 2025’s cryptocurrency heist. The Lazarus Group reportedly pilfered over 400,000 ETH and stETH, valued at $1.5 billion, from Bybit. The Dubai-based exchange also secured a preliminary injunction, freezing identified digital assets.

Bybit sues North Korea over Lazarus Group hack

Bybit’s civil lawsuit directly targets North Korea, its intelligence apparatus, and the Lazarus Group. The exchange seeks to recover the staggering $1.5 billion lost during the 2025 incident. This filing represents a bold escalation against state-backed hacking operations.

Adding immediate teeth to the legal proceedings, Bybit successfully obtained a preliminary injunction. This court order prohibits the transfer or dissipation of specific identified assets. These assets are held by unidentified individuals and entities, termed “John Doe” defendants.

It means these funds are now frozen while litigation against North Korea and its cyber operatives unfolds. Bybit aims to hold the perpetrators accountable for their actions.

The devastating February 2025 Bybit hack

The hack itself occurred on February 21, 2025, netting approximately $1.5 billion from Bybit. Lazarus Group, North Korea’s primary state-sponsored hacking collective, exploited a vulnerability. This was found in the user interface (UI) source code of Safe Wallet.

Safe Wallet is a platform Bybit used for its multi-signature processes. Hackers initially compromised a developer’s macOS workstation through social engineering. They deployed a malicious Python application to establish persistent access.

They then leveraged stolen session tokens to access Bybit’s Amazon Web Services (AWS) resources. The attackers even tried to register a fraudulent Multi-Factor Authentication (MFA) device to solidify their control.

Malicious JavaScript was ultimately injected into Safe Wallet’s frontend application, hosted on AWS S3. This allowed transaction data interception and manipulation. The theft targeted a routine 30,000 ETH transfer from a Bybit Ethereum cold wallet to a warm wallet.

This exploit altered the smart contract logic of the cold wallet. It enabled funds to be siphoned across 39 different addresses. This demonstrates a sophisticated understanding of blockchain infrastructure.

Ben Zhou, Bybit co-founder and CEO, highlighted the attack’s broader implications. “The Lazarus attack wasn’t just an attack on Bybit. It was an attack on trust in our industry,” Zhou stated. He affirmed Bybit’s commitment to user protection, fund recovery, and accountability for large-scale cybercrime.

Securing and tracing stolen digital assets

The preliminary injunction is a critical step, designed to preserve identified stolen digital assets as litigation proceeds. This legal maneuver prevents defendants from selling or moving the funds. Bybit has indicated it will pursue further relief from the U.S. District Court for the District of Columbia.

Even before the lawsuit, coordinated industry efforts managed to freeze $42.89 million of the exploited funds. Additionally, the mETH Protocol successfully recovered 15,000 cmETH tokens. These tokens were valued at nearly $43 million.

These early recoveries highlight the potential for collective action. Such collaboration can significantly mitigate damage from large-scale thefts. The crypto community plays a vital role in tracing illicit assets.

North Korea’s extensive crypto funding network

This Bybit incident is far from an isolated event. North Korea, through entities like the Lazarus Group, systematically engages in cryptocurrency theft. This strategy bypasses international sanctions and funds its illicit weapons programs.

Reports indicate the DPRK finances approximately 50% of its foreign currency income via cyberattacks. Up to 40% of its weapons of mass destruction (WMD) programs are also supported this way. This underscores the nation’s reliance on digital theft.

In 2025 alone, North Korean hackers stole $2.02 billion in cryptocurrency. The Bybit hack accounted for a substantial portion of that sum. Data from Chainalysis suggests North Korean hackers have stolen an estimated $6.75 billion worth of crypto to date.

This makes them one of the most prolific state-sponsored cybercriminal groups globally. They leverage digital assets to sustain their regime and military ambitions. The international community continues to grapple with these persistent threats.

Lazarus Group: A key player in DPRK cyber warfare

The Lazarus Group, also known as APT38 or TraderTraitor, operates under the direct control of North Korea’s Reconnaissance General Bureau (RGB). Established in 2009, the RGB serves as the DPRK’s primary foreign intelligence service, reporting directly to Supreme Leader Kim Jong Un.

It consolidates various intelligence and special operations units. This makes it a formidable cyber warfare group. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) placed Lazarus on its Specially Designated Nationals (SDN) List in April 2022.

The U.S. Department of Justice has also indicted several RGB members. These include Park Jin Hyok, Jon Chang Hyok, and Kim Il Park. Their involvement in Lazarus hacking campaigns is well-documented. Their financially motivated cyber activities are aimed squarely at bolstering North Korea’s economy and military.

Understanding complex crypto attack vectors

The attack on Bybit exemplifies the evolving sophistication of state-sponsored cyber threats. Exploiting vulnerabilities in platforms like Safe Wallet demonstrates a deep understanding of blockchain infrastructure. These platforms facilitate secure multi-signature transactions.

The use of social engineering to compromise developer workstations also highlights persistent human element risks. These are the kinds of challenges that keep security experts up at night. The incident serves as a stark reminder that even robust systems can be breached through cunning and persistent efforts.

Bybit’s robust recovery and ongoing efforts

Despite the colossal loss, Bybit acted swiftly to shore up its finances and recover. Within just two days of the hack, the exchange secured $1.23 billion in ETH. This was through a combination of bridge loans, whale deposits, and over-the-counter (OTC) purchases.

This rapid influx of capital was crucial in covering the significant ETH deficit created by the theft. Hacken, an independent blockchain security auditor, confirmed Bybit successfully closed the ETH gap within 72 hours of the incident.

Their proof-of-reserves report verified that Bybit’s key assets maintained collateral ratios exceeding 100%. This demonstrated Bybit’s financial resilience and commitment to its users during an unprecedented crisis. Bitcoin whales, a significant force in the wider cryptocurrency market, often respond to such incidents by either de-risking or seeing opportunities.

In a further effort to recoup losses and deter future attacks, Bybit launched a “LazarusBounty” program. This initiative offers a 10% reward on recovered funds. This is split between those who help freeze assets (5%) and those who assist in tracing them (5%).

It’s a strategic move to leverage the broader crypto community in asset recovery. The bounty program encourages collaboration. It incentivizes individuals and firms to actively participate in the fight against cybercrime.

Collaborative approach to cyber accountability

Bybit hasn’t pursued this action in isolation. CEO Ben Zhou stressed that the exchange has worked closely with investigators, other exchanges, regulators, and law enforcement agencies since the attack. This collaborative effort is vital in tracing complex trails of stolen funds.

The Federal Bureau of Investigation (FBI), Sygnia, and TRM Labs have all been instrumental in attributing the hack. They also help track illicit assets. This multi-agency approach strengthens the pursuit of justice in the digital realm.

The civil action, Bybit noted, is proceeding independently of ongoing criminal investigations led by U.S. law enforcement authorities. This dual approach aims to maximize financial recovery and criminal prosecution. It reflects a growing trend for cybercrime victims.

Victims are increasingly turning to civil courts to seek redress. This holds true even when dealing with state-backed actors. It underscores a shift towards more aggressive legal strategies in cybersecurity cases.

Setting a new legal precedent in cyber warfare

Suing a sovereign nation-state like North Korea in a U.S. federal court is a legally complex undertaking. It carries significant implications for future cases. This lawsuit could establish a vital precedent for future state-sponsored cyberattacks.

It is particularly relevant for attacks targeting critical financial infrastructure. It signals that even nation-states are not immune from legal challenges in the digital realm. This case could reshape international cyber law.

The case highlights broader geopolitical tensions surrounding cyber warfare and economic sanctions. North Korea relies heavily on illicit gains to circumvent global restrictions. Successful legal actions like Bybit’s could disrupt these crucial funding streams.

This kind of financial pressure might prove more effective than traditional sanctions alone in curbing their weapons programs. It also reflects broader shifts in global economic dynamics.

Furthermore, the lawsuit could encourage greater transparency and security measures across the cryptocurrency industry. Exchanges and other digital asset platforms might face increased scrutiny. They will likely be pressured to implement more robust defenses.

The sheer scale of the $1.5 billion loss means the industry can’t afford to ignore these threats. The importance of robust technological infrastructure is clear across all sectors. This includes the security of digital assets. The outcome of Bybit’s lawsuit against North Korea and the Lazarus Group will be closely watched by governments and financial institutions.

The entire cryptocurrency sector will also monitor this case. It represents a significant step towards holding nation-state actors accountable for their cyber aggressions. It also reinforces the idea that the digital landscape, despite its borderless nature, is not beyond the reach of international law.

The pursuit of justice in this high-stakes legal battle could shape the future of cybersecurity and asset recovery in the crypto world.