Bybit has taken the extraordinary step of suing a sovereign state. The cryptocurrency exchange has filed a civil lawsuit in the U.S. District Court for the District of Columbia against the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB) intelligence agency, and the Lazarus Group, the state-linked hacking unit that U.S. authorities have blamed for the February 2025 theft of roughly $1.5 billion from the exchange, the largest cryptocurrency heist on record.
The exchange, which announced the suit this week after filing it under seal on June 18, 2026, is pursuing the claim under the Racketeer Influenced and Corrupt Organizations Act (RICO), a law built to prosecute organized crime, and has already secured early wins. A federal judge granted a temporary restraining order and expedited discovery in June, and on July 30 partially granted a preliminary injunction freezing certain traceable stolen assets while the case proceeds.
What Bybit Filed
According to Bybit’s announcement and the case docket, the complaint names four sets of defendants: North Korea, its RGB military-intelligence agency, the Lazarus Group, and 20 unidentified individuals and entities listed as “John Doe” defendants, the placeholder used for parties whose identities are not yet known. Bybit is seeking the return of the stolen funds, roughly $1.5 billion in damages, and additional punitive damages.
The choice of RICO is notable. The statute, best known for targeting mafia enterprises, lets plaintiffs sue over a “pattern of racketeering activity,” and Bybit’s suit argues that Lazarus’s long record of crypto thefts, including a $620 million theft from the Ronin bridge and a roughly $100 million hack of Harmony, both in 2022, forms exactly such a pattern of organized, ongoing criminal conduct. The complaint also invokes the Computer Fraud and Abuse Act and the Alien Tort Statute, an 18th-century law that allows certain claims for violations of international law to be heard in U.S. courts. Bybit has said the civil action is being pursued independently of the separate criminal investigations by U.S. law enforcement.
The Court Has Already Acted
Unusually for a suit against a state that will almost certainly never appear, the case has already produced concrete results. The court granted expedited discovery and a temporary restraining order on June 19, and on July 30 issued a partial preliminary injunction. That order prohibits the transfer or sale of identified stolen assets held by the John Doe defendants while litigation continues.
The distinction matters: the freeze does not depend on North Korea’s participation. It operates against the specific, traceable assets and whoever currently controls them: the exchanges, custodians, and intermediaries holding funds that investigators have linked on-chain to the hack. Bybit described the order as intended to preserve identified stolen digital assets during the case, and said it will seek further relief.
The Hack Behind the Case
The lawsuit stems from an attack on February 21, 2025, when more than 400,000 Ether, worth about $1.5 billion at the time, were drained from one of Bybit’s cold, or offline, storage wallets during what appeared to be a routine transfer. It remains the largest cryptocurrency theft ever recorded. The FBI attributed the breach to North Korea within days, identifying the actors under the designation TraderTraitor and urging exchanges and blockchain firms to block addresses tied to the laundering operation.
Bybit absorbed the shock without halting operations. The exchange covered the shortfall through a combination of Ether purchases, loans, and deposits from industry counterparties, allowing it to keep processing customer withdrawal, a response widely credited at the time with preventing a broader crisis of confidence.
Why Sue a State That Ignores US Courts?
On its face, suing North Korea looks futile: the country does not recognize the authority of American courts and will not defend the case or pay a judgment. The significance lies elsewhere, and it is what makes this case a potential landmark. Because the stolen assets moved across public blockchains, they can be traced and identified, and a US court can order the parties holding identifiable portions of them not to move or sell them. In effect, the transparency of the blockchain gives victims a legal handle on stolen funds even when the ultimate thief is a nation-state beyond the court’s reach.
That is why the John Doe defendants, not North Korea itself, are the practical targets of the freeze. Legal commentators covering the case have framed it as the emergence of a new recovery playbook: pairing civil litigation with on-chain forensics to preserve and claw back stolen crypto, rather than relying solely on criminal prosecution or diplomatic pressure. Whether it becomes a durable template will depend on how courts and asset-holders respond.
The Limits of the Approach
For all its novelty, the case faces steep practical constraints, and it is worth being clear-eyed about them. Bybit has said that about 90.2% of the stolen funds are no longer traceable, having been laundered through mixers, cross-chain bridges, and over-the-counter dealers designed to break the on-chain trail. Recovery to date stands at roughly $48.4 million, a small fraction of the $1.5 billion. Any further recovery will depend on whether the exchanges and custodians controlling the identified assets actually comply with the court’s orders.
In other words, the realistic goal is not extracting $1.5 billion from Pyongyang, but preserving and eventually recovering the sliver of funds that remain identifiable, and establishing a legal precedent. The freeze is about asset preservation and accountability, not a payout.
The Bigger Picture
The stakes extend well beyond one exchange. North Korea-linked groups stole an estimated $2.02 billion in cryptocurrency across 2025, according to Chainalysis, with the Bybit hack accounting for the bulk of it and pushing the regime’s estimated cumulative crypto theft to around $6.75 billion, proceeds that analysts and governments say help fund its weapons programs. Bybit CEO Ben Zhou framed the suit in industry-wide terms, calling the Lazarus attack “an attack on trust in our industry” and saying the exchange’s focus has been to recover what it can and hold those responsible accountable.
Whether the courts ultimately return meaningful funds to Bybit, the case marks one of the most aggressive attempts yet to use civil law and blockchain forensics against state-sponsored crypto crime, and a test of whether the traceability that makes crypto vulnerable to theft can also make that theft legally recoverable.
Also Read: From Trusted Vendor to Insider Job? Coinkite CTO Now Linked to $110M Coldcard Hack Code
