🔥BTC/USDT

Bybit sues Lazarus over $1.46 billion theft

Bybit has secured a U.S. court order freezing identifiable digital assets tied to its February 2025 breach, giving the exchange a legal mechanism to block transfers by unnamed holders while it pursues claims against North Korea, its Reconnaissance General Bureau, and the Lazarus Group.

The U.S. District Court for the District of Columbia issued a temporary restraining order and later granted a preliminary injunction after finding that Bybit had shown a likelihood of success on the merits of its case. The injunction applies to certain allegedly stolen assets held by “John Doe” defendants, preventing their sale, transfer, or disposal during the litigation.

The case follows one of the largest cryptocurrency thefts attributed to a North Korean-linked hacking operation. Bybit alleges that Lazarus actors exploited a supply-chain compromise involving Safe’s multisignature wallet infrastructure on Feb. 21, 2025, diverting assets during a planned transfer from a cold wallet to a warm wallet.

The alleged attackers took 401,347 ETH, 90,375 stETH, 15,000 cmETH and 8,000 mETH, assets valued at roughly $1.46 billion at the time of the breach, according to Bybit’s account of the incident. The stolen ETH alone represented about 0.42% of Ethereum’s supply, briefly placing the addresses associated with the theft among the network’s largest ETH holders.

The court order does not provide Bybit with automatic control over every asset that may have passed through the laundering chain. Its practical reach depends on whether assets remain identifiable on public blockchains and whether the wallets, custodians, or entities holding them can be brought within the order’s scope. Funds that moved through mixers, bridges, or non-cooperating counterparties remain substantially harder to recover.

a supply-chain breach turned a routine transfer into a $1.46 billion theft

According to Bybit’s allegations, the intrusion targeted the transaction interface used in a Safe multisignature wallet process rather than simply compromising a private key. Safe multisig systems typically require several authorized signatures before funds can move, a safeguard designed to reduce the risk associated with any single wallet credential.

In this case, the attackers allegedly altered what signers saw during a transfer between Bybit-controlled wallets. That would have allowed the transaction to appear legitimate while redirecting the assets to addresses controlled by the attackers.

The incident illustrates a risk that remains difficult for large cryptocurrency holders to eliminate: strong wallet custody procedures can be undermined when the software, interface, or transaction-building tools around those procedures are compromised. Hardware wallets and multiple approvals can reduce exposure to private-key theft, but they do not fully protect an institution if authorized personnel are shown manipulated transaction details.

Bybit said it and its partners recovered about $48.40 million and froze another $30.50 million across more than 28 venues and custodians. The combined $78.90 million represented approximately 5% of the amount taken, based on the exchange’s calculation.

Those figures place the legal action in a broader recovery campaign involving blockchain analytics companies, law-enforcement agencies, custodians, and platforms capable of blacklisting or freezing assets. German authorities dismantled the platform eXch, while German and Swiss authorities jointly shut down Cryptomixer.io, two actions connected to enforcement pressure on infrastructure used in illicit asset flows.

most of the assets moved within days

The theft’s scale was compounded by the speed of the laundering operation. Blockchain monitoring platform Spot On Chain reported that approximately 266,309 ETH, equal to 53.3% of the stolen amount it tracked, had been laundered within one week.

According to Spot On Chain, much of that flow passed through THORChain and was converted into Bitcoin, at an average pace of roughly 48,420 ETH a day. THORChain is a cross-chain protocol that allows users to exchange assets between blockchains without relying on a conventional centralized intermediary.

On-chain analyst Yu Jin reported in early March 2025 that laundering activity had continued for about 10 days and that about 90.2% of the stolen assets had become untraceable through the routes being monitored. The trail included cross-chain bridges, mixers and over-the-counter channels, which can fragment a large theft into many transactions and move value into assets with different tracking and custody characteristics.

The alleged laundering activity drove substantial traffic through THORChain. The protocol was reported to have handled about $5.9 billion in trading volume associated with the flows and generated roughly $5.5 million in fees. Those figures show how a theft of this size can create unusual demand for cross-chain liquidity, even when the original assets remain publicly visible on Ethereum.

Ethereum’s price also fell sharply during the period in which the assets were being moved, declining from roughly $2,730 around the theft to about $1,920 later, a drop of approximately 30%. Yu Jin’s monitoring noted an earlier 23% decline during the roughly 10-day laundering period. The price moves occurred alongside wider market activity, so the on-chain transfers alone do not establish that the theft caused the decline.

lawsuit extends pressure beyond wallet tracking

Bybit’s lawsuit names the Democratic People’s Republic of Korea, the Reconnaissance General Bureau and Lazarus Group, alongside the unidentified defendants alleged to control some of the assets. The U.S. Federal Bureau of Investigation identified Lazarus as the perpetrator of the Bybit theft, according to the material supplied with the case.

Lazarus is widely described by governments and blockchain security researchers as a North Korean state-linked hacking cluster associated with the Reconnaissance General Bureau. Its known or alleged activity has been connected to the 2014 Sony Pictures attack, the $81 million Bangladesh Bank theft in 2016, the WannaCry outbreak in 2017, and major cryptocurrency attacks including the $620 million Ronin Bridge breach and $100 million Harmony Horizon Bridge theft in 2022.

The group has also been linked to attacks on Atomic Wallet and Stake in 2023. UNC4736, also known as AppleJeus or Citrine Sleet and identified as a Lazarus-linked subgroup, was tied to the $50 million Radiant Capital theft in October 2024 and the $285 million Drift Protocol attack reported in April 2026.

Chainalysis has estimated that North Korean hacking groups have stolen about $6.75 billion in cryptocurrency overall, including more than $2 billion during 2025. The Bybit incident accounts for a major share of that annual total and has reinforced scrutiny of the services that provide rapid swaps, cross-chain transfers, and asset obfuscation.

The preliminary injunction gives Bybit a route to preserve assets that can still be linked to the theft and found within reachable custodial or legal channels. It does not solve the technical and jurisdictional problems created once tokens have been mixed, bridged, or converted through counterparties outside the reach of cooperating authorities.


Learn how major exchanges tackle hacks and protect users in our breakdown of 2025 crypto crime trends.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up