Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

coindesk+1cryptobriefingcoinnessCryptocurrency exchange Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group over the record $1.5 billion hack it suffered in February 2025, securing a preliminary injunction freezing some of the stolen assets. The exchange announced the legal action on Friday.coindesk+1
The suit, filed in the U.S. District Court for the District of Columbia, names a group of unidentified holders of stolen funds as "John Doe" defendants. The court order bars those defendants from transferring or selling the identified assets while the litigation proceeds.cryptobriefing+1
Bybit CEO Ben Zhou framed the case as extending beyond his company's losses. "The Lazarus attack was not simply an attack on Bybit. It was an attack that shook trust in our industry," Zhou said, according to CoinDesk Coinbase Global, Inc. . He added that Bybit's goal is to "put user protection first, recover as much as possible, and hold accountable those behind these attacks."coinness+1
The civil case is being pursued separately from ongoing criminal investigations by U.S. law enforcement authorities. Bybit said it plans to seek additional relief from the court as the case moves forward.coindesk+1
On February 21, 2025, the Lazarus Group allegedly stole more than 400,000 ETH and stETH — worth approximately $1.5 billion — from Dubai-based Bybit in what became the largest cryptocurrency theft in history. The FBI attributed the hack to North Korea days after the breach.ic3+1
The Bybit theft made up the bulk of the $2.02 billion in crypto North Korea stole last year, according to data from Chainalysis. In total, North Korean hackers have taken $6.75 billion worth of crypto. The country is widely believed to use stolen cryptocurrency to fund its weapons program.coindesk
The lawsuit arrives as North Korea-linked actors continue targeting the crypto industry through social engineering. Security firm JUMPSEC reported in July that the BlueNoroff group — designated by the U.S. Treasury as a North Korean state-sponsored entity controlled by the Reconnaissance General Bureau — is using compromised Telegram accounts to lure cryptocurrency professionals into fake video meetings that deliver malware.cryptonews
The FBI has warned separately that North Korean actors conduct "highly tailored social engineering against cryptocurrency and DeFi employees," specifically flagging requests to run scripts to fix video calls or install unfamiliar applications.cryptonews