Bybit wins injunction to freeze crypto linked to North Korea hack

1 hour ago 10

Bybit is doing something most companies would consider futile: suing North Korea. And so far, it’s actually working.

A federal judge in the District of Columbia granted a preliminary injunction freezing crypto assets in wallets linked to the February 2025 Bybit hack, in which North Korean state-sponsored hackers allegedly made off with approximately $1.5B in Ethereum. The civil lawsuit, filed on August 7, 2026, names the Democratic People’s Republic of Korea, its intelligence arm the Reconnaissance General Bureau, and the infamous Lazarus Group as defendants.

The largest crypto heist gets its day in court

The hack itself dates back to February 21, 2025, when attackers exploited a supply-chain vulnerability in Safe{Wallet} multisig software used by Bybit. The result was the single largest theft from a crypto exchange ever recorded.

Within days, the FBI attributed the attack to North Korean actors, linking it to a broader pattern of DPRK-sponsored cyber operations. According to Chainalysis, North Korean hackers have stolen a cumulative $6.75B in cryptocurrency assets across multiple campaigns over the years.

Bybit CEO Ben Zhou has framed the lawsuit as part of a multi-pronged recovery strategy. The exchange has been coordinating with other platforms, offering financial incentives for the return of stolen funds, and now pursuing civil litigation in US federal court.

The preliminary injunction is designed to prevent whatever remains of the stolen assets from being moved while the case proceeds.

Why Bybit is betting on the courts

But the lawsuit isn’t really about getting Kim Jong Un to write a check. It’s about creating legal authority to freeze and seize assets wherever they surface. A court order gives Bybit and cooperating exchanges the legal cover to lock down wallets, block transactions, and work with law enforcement across jurisdictions.

Bybit has also implemented a 10% bounty program for recovered funds, essentially crowdsourcing the detective work to blockchain sleuths and white-hat hackers who can trace the flow of stolen Ethereum across the network.

What this means for exchange security and regulation

The case also puts a spotlight on supply-chain vulnerabilities in crypto infrastructure. The attackers didn’t brute-force Bybit’s systems directly. They compromised the multisig software the exchange relied on, a reminder that security is only as strong as the weakest link in the stack.

For regulators, the Bybit saga reinforces the argument that exchanges need more rigorous security standards and incident response protocols. The $6.75B cumulative figure attributed to North Korean cyber operations is hard to ignore, and it gives lawmakers concrete ammunition for pushing stricter oversight.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article