Bybit CEO Ben Zhou wearing a black Bybit shirt

Bybit Sued North Korea Over Its $1.5 Billion Hack. The Court’s First Move Reached the Wallets

August 7, 2026 4:05 pm Comments

Bybit is trying to turn one of crypto’s largest thefts into something more than a trail of wallet addresses.

The exchange has sued North Korea, the country’s military intelligence agency and the Lazarus Group over the $1.5 billion hack that struck Bybit in February 2025.

The defendants also include unidentified people alleged to be holding or moving assets tied to the theft.

A federal judge has already granted Bybit a preliminary injunction that freezes specified stolen assets while the case moves forward.

Then the notice went somewhere most court papers never go.

It reached the wallets themselves.

CoinDesk reports that Bybit filed the civil action in the U.S. District Court for the District of Columbia. The complaint names the Democratic People’s Republic of Korea, its Reconnaissance General Bureau and the Lazarus Group.

The preliminary injunction covers identified stolen assets held by anonymous defendants while the court considers the case. It preserves the disputed crypto rather than deciding, at this early stage, who ultimately wins on the merits.

Bybit CEO Ben Zhou said the company is focused on protecting users, recovering what it can and pursuing accountability. The civil lawsuit is separate from any criminal investigation by the United States or another government.

The lawsuit is a creative response to a problem that has frustrated exchanges, investigators and victims for years.

A blockchain may show where stolen crypto travels, but a visible transaction record does not automatically reveal the person controlling each address. Assets can move through thousands of wallets, decentralized exchanges, bridges, mixers and services spread across multiple countries.

A court order cannot reach into a self-custody wallet and press a freeze button.

What it can do is create legal consequences for people and companies subject to the court’s authority.

If an exchange, custodian, stablecoin issuer or other identifiable intermediary controls assets covered by the order, the injunction gives Bybit a document it can use to demand that those assets remain in place.

It can also put anonymous wallet holders on notice that the funds they control are the subject of a federal case.

That is where the non-fungible tokens entered the picture.

The Block reported that Bybit used NFTs to notify anonymous wallet holders about the injunction. At least one man in Australia appeared in the case to challenge his inclusion after receiving notice.

Serving legal notice through an NFT sounds like a publicity stunt until the target is known only by a blockchain address.

Traditional service assumes the plaintiff has a name and a physical or electronic destination tied to the defendant. Crypto theft cases often begin with neither.

An NFT can place a visible notice directly into the address named in the case. It cannot prove who read it, and other service requirements still apply.

The notice links the court proceeding to the on-chain location where the disputed assets sit.

The Australian appearance also demonstrates why due process matters.

A traced wallet can receive funds linked to a theft without its current owner being the original hacker. Assets may pass through a service, an over-the-counter transaction or an innocent buyer before investigators identify the address.

The injunction is designed to preserve assets while those competing claims are tested. It is not a declaration that every current wallet holder joined the original attack.

The FBI’s public alert assigns the February 21, 2025 theft to North Korean cyber actors and calls the operation TraderTraitor. The agency said approximately $1.5 billion in virtual assets was taken from Bybit, putting the U.S. government formally behind the finding rather than leaving it as an exchange’s private allegation.

The stolen assets included ether and related tokens. The hackers rapidly converted portions of the haul and dispersed the proceeds across thousands of blockchain addresses.

The FBI asked cryptocurrency exchanges, bridges, node operators and other private-sector companies to block transactions involving addresses it identified.

Its public notice included Ethereum addresses tied to the theft so compliance teams and infrastructure providers could recognize the assets as they moved.

The agency also asked companies to preserve transaction information that could help investigators connect addresses to real operators.

That request relies on cooperation.

Bybit’s injunction adds a legal mechanism that can matter when voluntary cooperation is not enough.

The original breach did not come from cracking Ethereum.

Attackers compromised the signing process surrounding a routine transfer from Bybit’s cold wallet. The interface presented the transaction as legitimate to the people approving it while the underlying logic redirected control.

Roughly 400,000 ETH and staked-ether tokens were taken. Bybit continued honoring customer withdrawals and restored reserves, preventing the theft from becoming an exchange-wide liquidity collapse.

Recovering the stolen crypto has been much harder.

Chainalysis estimates that North Korean hackers stole $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year. The Bybit attack accounted for roughly three-quarters of that annual total and pushed the regime’s single-year haul to a new record by a wide margin.

The blockchain intelligence firm puts North Korea’s cumulative crypto theft at about $6.75 billion. Those proceeds are widely treated as a national-security problem because governments say the funds support the regime and its weapons programs.

Chainalysis found that the 2025 spike was driven by fewer but vastly larger operations, showing how one successful compromise can dominate an entire year’s theft figures.

The scale changes the economics of recovery.

A small hacker may need to cash out quickly. A state-backed operation can divide assets among teams, wait for attention to fade and use a long chain of services to obscure the path.

Public wallet tracing still has value because the stolen crypto cannot become truly invisible. Every movement creates another record, and every interaction with a regulated service can create a point where identity, custody and legal authority meet.

Bybit has also used a bounty program to encourage investigators and exchanges to help trace and freeze the stolen assets. The lawsuit gives that recovery campaign a courtroom lane.

There are limits.

North Korea is unlikely to appear in a U.S. civil courtroom and voluntarily satisfy a judgment. Wallet holders outside the United States may dispute jurisdiction.

Assets that remain entirely under the control of actors who ignore the order may continue moving.

None of that makes the injunction symbolic.

Crypto theft recovery is usually a contest over chokepoints. The winner is often determined when stolen assets touch a service capable of freezing them, or when an anonymous controller becomes identifiable enough to face legal pressure.

Bybit now has an order aimed at preserving those opportunities.

The most important part of the case may be the bridge it builds between two systems that rarely speak the same language: blockchain addresses and federal court procedure.

The hackers used wallets to scatter the money.

Bybit is using those same wallets to tell whoever controls it that the chase has reached them.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.