Koinlytics

Bybit Sued North Korea in a US Court and a Judge Actually Froze the Money

Aug 8, 2026ETHBTCsecurityexchangeslazaruslegalrecovery
Bybit filed suit in the US District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau and the Lazarus Group over the $1.5 billion February 2025 hack, and secured a preliminary injunction freezing identified stolen assets.

Bybit has sued the Democratic People's Republic of Korea, its Reconnaissance General Bureau and the Lazarus Group in the US District Court for the District of Columbia over the February 2025 attack that drained $1.5 billion in digital assets. The court granted a preliminary injunction freezing identified stolen assets, finding that Bybit had demonstrated a likelihood of success on the merits.

The announcement came on August 8. The injunction prohibits the transfer or dissipation of identified assets connected to the case while litigation continues.

The Numbers So Far

That is a recovery and freeze rate of roughly 5% against the original theft, eighteen months after the fact. The figure is low in absolute terms and high relative to what North Korean attributed thefts have historically returned, which is close to nothing.

The Legal Architecture

The interesting part is not the claim against North Korea, which is largely symbolic given that a sovereign state does not appear to answer a civil summons. It is the John Doe defendants.

Bybit named unidentified individuals and entities currently holding or moving the stolen funds. That structure lets the court reach the actual custodians of the assets without knowing who they are, which is exactly the situation blockchain forensics produces: you can identify an address and its transaction history with certainty while knowing nothing about the person controlling it.

An injunction against a John Doe address is enforceable in practice because it binds the regulated intermediaries. Any exchange or custodian receiving those funds now has notice of a federal court order, which converts a discretionary compliance decision into a legal exposure. That is the mechanism doing the work here.

Why This Is Genuinely New

Stolen crypto recovery has historically depended on the goodwill of centralised venues and on attackers making mistakes. Both are unreliable. A civil judgment creates a different lever:

The theft was permissionless. The laundering is not. Every point where stolen crypto touches a regulated venue is a point where a court order has teeth, and that is the entire strategy.

The Limits

None of this recovers funds that have already been laundered through mixers, converted to Monero, or moved through jurisdictions that do not recognise US court orders. North Korean operations have become notably more sophisticated at exactly this since 2022, and the 5% recovery figure reflects that.

It also does not address the entry point. The February 2025 attack succeeded through a compromise of the signing process rather than a break in the exchange's cold storage cryptography, which is the same category of failure that has produced most of 2026's large incidents: the Coldcard entropy flaw, the BTCPay credential theft, the bridge exploits that took $35 million in six hours. The pattern is credentials and processes, not mathematics.

What to Watch

For anyone holding funds on an exchange, the practical lesson is unchanged and unglamorous. Recovery after a venue-level compromise depends on litigation, jurisdiction and years of process, and it returns a fraction. The exposure you can actually control is how much sits on any single venue at any given time, and that is a number worth knowing precisely rather than approximately.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics