Bybit Sues North Korea and Lazarus Group Over $1.5B Hack, Secures Asset Freeze
Bybit sues Lazarus Group and North Korea after saying it secured an asset freeze tied to an alleged $1.5 billion hack, pushing the exchange’s recovery effort into court while the public evidence base remains narrow.

CoinDesk reported on Aug. 7, 2026 that Bybit sued North Korea and the Lazarus Group over the alleged $1.5 billion hack, while the FBI’s 2025 cyber alert on the Bybit hack publicly attributed the theft to North Korea.
What the available sources confirm
Based on the two clearest URLs in the brief, the supported fact pattern is limited: Bybit is the plaintiff, North Korea and Lazarus are the named targets, and the case is tied to the same theft discussed in federal attribution and later reporting. Coincu previously covered address overlap tied to the Bybit hack, but that context does not add verified court specifics beyond CoinDesk’s lawsuit report.
The FBI alert matters because it gives the story an official attribution layer rather than leaving it as only an exchange allegation. Separate policy attention has also appeared in Coincu’s report that the G7 planned to discuss North Korea’s crypto theft allegations, which helps explain why the case has drawn interest beyond a routine platform security update.
Why the asset freeze matters more than unverified procedural detail
An asset freeze, as summarized in CoinDesk’s Aug. 7, 2026 report, is best understood here as a legal restraint step, not proof that funds have already been returned. The brief does not provide a court order, a jurisdiction, or a quantified recovery, so stronger claims would go beyond the available evidence. For related coverage, see G7 to Address North Korea's $1.5 Billion Crypto Theft at Summit.
Bybit’s own recovery framing predates this lawsuit: the exchange announced a recovery bounty program with rewards of up to 10% of stolen funds, showing that tracing and reclaiming assets was already a stated objective. Coincu has also covered another North Korea-linked theft report involving Solana assets, though that separate case does not verify any extra facts about Bybit’s filing.
What is still unclear
The research brief does not include a complaint, docket entry, or courtroom order, and it does not identify who granted the freeze or how broadly it applies. That means readers can responsibly say Bybit reported a lawsuit and an asset freeze, per the Aug. 7, 2026 CoinDesk report, but not yet specify venue, defendants’ response, or recoverable balances. For related coverage, see Bybit.eu Expands European Offering as Bybit Payments GmbH Secures Electronic Money Institution Licence.
FAQ
What is Bybit suing over? The available reporting says the exchange linked the case to the alleged hack identified in the FBI’s 2025 Bybit alert and restated in CoinDesk’s Aug. 7, 2026 coverage.
Why is Lazarus Group central to the story? The lawsuit, as reported by CoinDesk, names Lazarus alongside North Korea, and the FBI alert is the brief’s main official attribution source for tying the theft to North Korea-linked actors.
What should readers watch next? The next evidence threshold is a public filing or order that identifies the court and scope of the freeze; until then, the sourced facts remain narrower than the headline. That caution matters amid Coincu’s earlier coverage of address overlap tied to the Bybit hack and international policy attention around the case, both of which add context but not fresh proof of the lawsuit’s mechanics.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.








