Bybit sued North Korea, its Reconnaissance General Bureau, and Lazarus Group in the US District Court for the District of Columbia. The exchange won a preliminary injunction blocking unnamed defendants from moving or selling stolen crypto.
Public court reporting describes the order as covering those identified assets, without confirming the full $1.5 billion stolen in February 2025 or disclosing the dollar value the injunction protects.
This injunction landed roughly 532 days after the hack—about 17 months after North Korean hackers pulled off the largest crypto theft on record. Chainalysis tracked a consistent laundering pattern by DPRK-linked groups after a major theft, moving stolen funds through exchanges, bridges, mixers, and laundering services over roughly 45 days.
Coordinated action by industry partners froze $42.9 million in the first days after the theft, and mETH Protocol recovered another 15,000 cmETH, worth nearly $43 million. Combined, that early save came to about $85.9 million, roughly 5.9% of the $1.46 billion stolen.
Elliptic, citing a six-month review from zeroShadow, said more than $1 billion of the stolen funds had already moved through the laundering pipeline well before this new court order existed.
Whatever value the injunction protects now probably represents a small residue that never fully escaped that pipeline.
| Event / metric | Figure | What it shows |
|---|---|---|
| Bybit hack date | Feb. 21, 2025 | Starting point of the largest crypto theft on record |
| Reported court injunction timing | ~532 days later | Legal process arrived roughly 17 months after the theft |
| DPRK laundering cycle | ~45 days | Stolen funds often move through the main laundering pipeline far faster than courts move |
| Early frozen funds | $42.9 million | Industry coordination worked immediately after the hack |
| cmETH recovered | ~$43 million | Token/protocol-level recovery was possible early |
| Total early save | ~$85.9 million | Roughly 5.9% of the $1.46 billion theft |
| Funds reportedly laundered by six-month mark | $1 billion+ | Most value likely moved before the new injunction existed |
Why a blockchain never has to reverse anything
Stolen crypto becomes stoppable the moment it lands somewhere a court order can reach: an exchange, a stablecoin issuer, a custodian, or any other operator capable of freezing what passes through it.
That is why the FBI asked exchanges, bridges and RPC operators to block Lazarus-linked transactions within days of the hack. It is also why Bybit’s own stolen stETH and cmETH were swapped into native ETH almost immediately.
Elliptic says token issuers can often freeze wallets holding their own tokens, but no central party directly controls ETH or Bitcoin balances. Converting stolen liquid-staking tokens into native ETH removes one of the easiest tools available to victims for freezing assets.
Native ETH or Bitcoin sitting in self-custody is nearly impossible to freeze directly, while stablecoins sit at the other end, since issuers can blocklist addresses depending on the chain and contract design.
Centralized exchanges sit close behind, able to block withdrawals or comply with a warrant. Bridges, swap services and DAO-controlled recovery wallets fall somewhere in between, and OTC brokers operating across borders remain the hardest targets of all.
A Lazarus-linked theft from the crypto platform Rain drew a similar response. The FBI froze roughly 2,204 SOL at the exchange WhiteBIT and served a seizure warrant. WhiteBIT transferred the funds to the US government, and a federal court later granted default judgment forfeiting the crypto outright.
| Asset location | Freeze difficulty | Who can act | Why it matters |
|---|---|---|---|
| Native ETH or BTC in self-custody | Very hard | No central controller | Transactions are irreversible and balances cannot be directly frozen by an issuer |
| Liquid-staking tokens | Medium | Token issuer / protocol operator | Issuers or protocols may have tools to block or recover some assets |
| Stablecoins | Lower | Stablecoin issuer | Issuers can often blocklist addresses depending on contract design |
| Centralized exchanges | Lower | Exchange / law enforcement | Exchanges can freeze withdrawals or comply with seizure warrants |
| Bridges and swap services | Mixed | Operator, DAO, court, or governance process | Depends on control structure and jurisdiction |
| OTC brokers | Very hard | Law enforcement, sanctions authorities | Cross-border laundering makes recovery slower and less predictable |
A second fight brewing over who gets frozen funds
Holders of old terrorism judgments against North Korea served a restraining notice on roughly 30,766 ETH, worth about $71 million, that had been frozen when an unrelated exploit hit the Kelp protocol on Arbitrum.
Arbitrum’s governance records show a DAO vote that later moved ETH to an Aave-controlled wallet, with the restraining notice accompanying the assets to their new location.
No public record shows that competing creditors have claimed the assets Bybit is now pursuing, though the Kelp episode establishes a real pattern. Once DPRK-linked crypto sits frozen somewhere reachable, other parties holding judgments against North Korea can try to get in line for it too.
The US Treasury Department designated Lazarus Group, Bluenoroff and Andariel in 2019 as entities controlled by North Korea through their ties to the Reconnaissance General Bureau. Treasury says the country’s cyber operations generate revenue that can fund weapons and ballistic missile programs.
Chainalysis says North Korean hackers stole over $2 billion in crypto in 2025 alone, a 51% jump from the year before, even as the number of known attacks fell sharply.
Cumulative DPRK crypto theft has reached at least $6.75 billion, and the pattern points toward fewer, larger hits and away from a broad spray of small ones.
What happens to the crypto from here
The bull case is that more of the stolen $1.46 billion will turn up at reachable chokepoints than anyone currently expects.
Investigators trace additional funds held by exchanges, stablecoin issuers, bridges, or custodians willing to cooperate, and Bybit’s injunction becomes a template other victims use to chase down DPRK-linked funds long into a hack’s aftermath.
Recovery climbs meaningfully above the roughly $85.9 million secured so far, and courts prove that persistence still beats time even against a state-backed hacking operation.
The bear case is that the injunction covers only a small residual balance already trapped by ordinary compliance systems before Bybit filed suit.
Most of the $1.46 billion stays gone, laundered through the 45-day window Chainalysis describes long before any court could act.
| Scenario | What happens next | Recovery implication | Broader market meaning |
|---|---|---|---|
| Bull case | More funds surface at exchanges, bridges, stablecoin issuers, or custodians | Recovery rises meaningfully above the ~$85.9 million already frozen or recovered | Courts prove stolen crypto can remain reachable long after a hack |
| Base case | The injunction preserves only identified residual assets | Bybit recovers some funds, but not close to the full $1.46 billion | Legal tools work, but mostly at the edges after funds are laundered |
| Bear case | Most funds remain beyond reach after the 45-day laundering window | The lawsuit becomes more about accountability than recovery | A 17-month delay looks nearly fatal to meaningful restitution |
| Competing-claim risk | Other creditors of North Korea try to claim frozen DPRK-linked assets | Recovery becomes a priority fight, not just a tracing fight | Frozen crypto may become contested sovereign-linked property |
The lawsuit proves that legal reach exists, but it also proves that a 17-month head start is nearly fatal to recovery, whatever it says about accountability.
Bybit’s lawsuit is proving that the assets sitting at the end of one blockchain transaction can still be stopped, just not for free and never on a predictable schedule.
The post This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is appeared first on CryptoSlate.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
