- Bybit, a cryptocurrency exchange, has filed a civil lawsuit against North Korea and the Lazarus Group following a massive hack.
- The company successfully froze $30.5 million of stolen assets across multiple exchanges and custodians.
- Bybit has already recovered $48.4 million of the stolen funds.
- Collaboration with law enforcement and blockchain analysts was key to this recovery effort.
- The attack highlights vulnerabilities in crypto infrastructure and the ongoing threat from state-sponsored hacking groups.
Bybit Sues North Korea and Lazarus Group Over Last Year’s Hack and Freezes Part of the Stolen Funds
In an unprecedented move, cryptocurrency exchange Bybit has taken legal action against North Korea’s government, its intelligence agency, and the notorious hacker group known as the Lazarus Group. This lawsuit comes in response to a devastating cyberattack that occurred on February 21, 2025, resulting in approximately $1.46 billion worth of Ethereum being stolen.
The federal court in Columbia has granted Bybit a preliminary injunction to prevent further movement or dispersal of these identified stolen assets. So far, over $78.9 million has been either recovered or frozen as part of this landmark crypto asset recovery initiative.
Details of the Cyberattack
During the attack, hackers exploited a vulnerability within AWS cloud infrastructure to siphon off about 401,346 ETH from Bybit’s holdings. Subsequent on-chain analysis linked this breach to Lazarus Group—a hacker collective with ties to North Korea.
The significant steps taken by Bybit include recovering $48.4 million and freezing an additional $30.5 million across more than 28 exchanges and custodians worldwide.
Efforts Towards Recovery
Ben Zhou, co-founder and CEO of Bybit, emphasized their commitment to asset recovery through collaboration with various stakeholders such as exchanges, blockchain analysts, custodians, and law enforcement agencies.
“Since the Lazarus attack in February 2025,” Zhou stated on social media platforms like X (formerly Twitter), “we have been working tirelessly from every possible angle.”
At present:
- Approximately $48.4 million in stolen assets have been recovered.
- An additional $30.5 million remains frozen across numerous platforms.
- The court’s order is crucial for preventing further dispersal or movement associated with this case.
Zhou expressed that their primary focus remains unchanged: safeguarding users’ interests while ensuring accountability for those responsible behind these attacks—highlighting how it wasn’t just an assault on Bybit but also trust within our industry itself.
Civil vs Criminal Investigations
It’s important noting however; civil proceedings are separate from ongoing criminal investigations conducted by U.S law enforcement agencies which includes active collaboration between FBI agents sharing valuable insights gained through both internal investigations alongside external partnerships forged during times like these when unity matters most!
Lazarus’ Money Laundering Tactics Exposed!
Following last year’s breach—the culprits actively moved stolen Ethereum between addresses converting assets via various channels including THORChain—a platform receiving around ~$5 .5M fees alone! However earlier reports indicated roughly ~69% remained traceable despite attempts made using services such Wasabi & Tornado Cash among others mentioned previously throughout aforementioned paragraphs above…
Nevertheless private sector cooperation alongside authorities worldwide helped dismantle laundering infrastructure utilized e.g., Germany successfully shut down eXch while Swiss counterparts closed Cryptomixer.io operations entirely!
In conclusion—the true test begins post-crisis revealing genuine dedication towards resolving issues faced head-on ensuring future resilience built upon lessons learned today paving way brighter tomorrow…
