Bybit Lawsuit North Korea: A Legal First
Bybit filed suit on Friday, August 7, in US District Court in Washington, DC, naming North Korea, its Reconnaissance General Bureau, and the Lazarus Group as direct defendants over the $1.5 billion hack that hit the exchange in February 2025. The filing leans on the Foreign Sovereign Immunities Act's terrorism exception, a legal tool built for hostage-taking and bombing cases against states like Iran, Syria and Libya, and never before tested on a pure crypto theft. A federal judge has already granted a preliminary injunction freezing identified stolen assets held by unnamed "John Doe" holders. That is a real, fast early win. It is also, by design, close to the limit of what this lawsuit can achieve on its own.
Can Hacked Crypto Ever Actually Be Recovered From North Korea?
The honest answer is: barely, and not from North Korea itself. Pyongyang holds essentially no assets inside the US financial system, doesn't recognize the court's authority, and has no incentive to show up. Even a full default judgment in Bybit's favor doesn't create a bank account to garnish or a building to seize. What the injunction actually does is bind third parties — the exchanges and custodians who might unknowingly be sitting on stolen funds — and order them to freeze anything traceable back to the hack. That's the real mechanism here: a lawsuit that pressures private companies into acting, not one that extracts payment from the state directly.
The numbers make the ceiling obvious. Bybit has recovered roughly $48.4 million and frozen a further $30.5 million across more than 28 exchanges and custodians. Add it up and you're around $79 million against a $1.5 billion theft — call it 5%. That's not a symptom of weak enforcement; it's the mechanical result of how fast Lazarus moved once the funds were stolen.
Why the Injunction Doesn't Reach Pyongyang
North Korea's laundering machine is the real obstacle, and it outran the courts over time, not overnight. Lazarus scattered the roughly 401,000 ETH taken in the hack — plus smaller amounts of stETH, cmETH and mETH stolen alongside it — through a peel-chain pattern across thousands of wallets within hours. In the first few months, most of it stayed nominally traceable: Bybit's own updates put the figure above two-thirds through the spring of 2025, with the share that had "gone dark" still a minority. That didn't hold. By Bybit's June 18, 2026 court filing — the discovery motion that laid the groundwork for the August 7 suit — the exchange told the court that roughly 90% of the stolen assets had become untraceable, leaving under 10% still connected to identifiable wallets. Everything in that untraceable majority is effectively gone from a legal-recovery standpoint: converted, mixed, or moved into jurisdictions and platforms that won't honor a US freeze order. The injunction can only act on the shrinking slice that's still identifiable and sitting somewhere a compliant custodian controls. It can't reconstitute money that's already been laundered clean.
That's also why the frozen total keeps climbing in small increments rather than jumping. Each new custodian that identifies tainted funds and complies adds a few million to the tally. It's real progress, but it's addition, not multiplication — there's no single lever that recovers the other 95% at once.
Where the $1.5 Billion Actually Went
Worth separating two different questions here: how much was stolen, and what that's worth now. The roughly 401,000 ETH taken in February 2025, plus the smaller stETH, cmETH and mETH haul stolen alongside it, was valued at about $1.5 billion at the time of the theft. ETH has traded well below that hack-day level for most of the period since — it was trading in the mid-$2,400s as of this weekend (August 22-23) — so even in the counterfactual world where all the tokens were somehow clawed back today, the dollar value recovered wouldn't match the dollar value stolen. That's a secondary point next to the laundering problem, but it's part of why "full recovery" was never a realistic target, only a best-case anchor.
Does This Set a Precedent for the Next Hack?
This is where the case actually matters. The FSIA terrorism exception has decades of precedent behind it in physical-violence and hostage cases, but none on a fact pattern like this — a state-linked hacking unit stealing crypto through a private exchange's infrastructure. If the case proceeds toward a default judgment, given North Korea's near-certain non-appearance, it hands every other hacked platform a template: name the state directly, invoke the same exception, and use the resulting order to pressure exchanges into freezing tainted wallets on sight rather than waiting for a subpoena.
The risk cuts the other way too. Courts built this exception for hostage-taking and bombings; extending it to financial theft is a stretch some judges may not accept if the theory is tested on appeal, and a narrowing ruling here could make it harder for the next victim to use, not easier.
The realistic path over the next few months is incremental: more filings, a possible motion for default judgment, and periodic headlines about another few million frozen at an individual exchange as Bybit's investigators identify more tainted wallets. What it isn't is a mechanism that gets North Korea to pay. The lawsuit's real value sits in precedent and pressure — a legal weapon other hacked platforms can now point to — while the dollars actually recovered will likely stay a small, slowly-growing fraction of what was stolen.
Sources
- https://www.coindesk.com/policy/2026/08/07/bybit-sues-north-korea-and-lazarus-group-over-usd1-5-billion-hack-secures-asset-freeze
- https://crypto.news/bybit-sues-north-korea-lazarus-group-crypto-hack-lawsuit/
- https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa
- https://en.bloomingbit.io/feed/news/117917
- https://www.cryptotimes.io/2026/08/09/bybit-sues-north-korea-over-1-5b-hack-freezes-assets/
- https://www.chainalysis.com/blog/lazarus-group-north-korea-doj-complaint-august-2020/