Following a historic $1.5 billion cold-wallet hack in February 2025, cryptocurrency exchange Bybit has secured a preliminary injunction from a US federal court freezing assets tied to North Korea's Lazarus Group. However, the order comes 17 months after the theft, highlighting the severe lag of legal remedies against a highly optimized 45-day laundering cycle. Investigators report that hackers rapidly swap freezable stablecoins for native ether or bitcoin, routing them through mixers and cross-chain bridges to render over $1 billion of the stolen funds virtually unrecoverable.
Bybit lawsuit against Lazarus
- ▪Bybit filed a civil lawsuit in the US District Court for the District of Columbia against North Korea, the Reconnaissance General Bureau, and the Lazarus Group over the February 2025 hack of the exchange.
- ▪A US federal court granted Bybit a preliminary injunction freezing digital assets tied to the February 2025 hack and restricting unidentified "John Doe" defendants from transferring or selling them.
- ▪The preliminary injunction in the Bybit lawsuit was granted roughly 532 days, or about 17 months, after the February 2025 hack occurred.
45-day laundering cycle
- ▪From day 20 to day 45 of the laundering cycle, stolen coins are cashed out in small tranches, typically under $500,000, through no-KYC venues, instant exchangers, and over-the-counter networks.
- ▪During days zero through five of the laundering cycle, attackers swap stolen tokens through decentralized finance protocols and push them into transaction mixing services.
- ▪During days six through ten of the laundering cycle, stolen funds hop blockchains via cross-chain bridges and flow through exchanges with limited know-your-customer controls.
- ▪Crypto investigators describe a three-wave laundering cycle for stolen cryptocurrency that typically runs about 45 days from the initial theft to the final cashout.
Asset freezing efforts
- ▪Coordinated industry actions froze $42.9 million shortly after the Bybit hack, and mETH Protocol recovered 15,000 cmETH worth nearly $43 million, totaling an early recovery of about $85.9 million.
- ▪Bybit has reported recovering approximately $48.4 million and freezing another $30.5 million across more than 28 global exchanges and custodians in connection with the February 2025 hack.
- ▪Holders of old terrorism judgments against North Korea served a restraining notice on roughly 30,766 ETH, worth about $71 million, that was frozen during an unrelated exploit of the Kelp protocol on Arbitrum.
Blockchain traceability limits
- ▪To avoid contract-level freezes by stablecoin issuers like Tether and Circle, sophisticated attackers typically swap stolen stablecoins into native ether or bitcoin within minutes of a breach.
- ▪An analysis by zeroShadow cited by Elliptic indicated that more than $1 billion of the stolen Bybit funds had already moved through the laundering pipeline before the US court issued its injunction.
- ▪While blockchain records allow tracing of token flows, onchain transfers are irreversible and require cooperation from centralized services to recover assets.
2025-2026 theft statistics
- ▪Hackers stole $3.4 billion in cryptocurrency in 2025, with the February 2025 Bybit cold-wallet hack of $1.5 billion in ether accounting for approximately 44% of that yearly total.
- ▪The largest single cryptocurrency theft in the first half of 2026 was the April 19 exploit of the restaking protocol KelpDAO, which resulted in a $293 million loss.
- ▪During the first half of 2026, hackers stole approximately $1.1 billion across a record 212 incidents, with North Korean-linked crews responsible for about 55% of these losses.
Story comments
Loading comments…