Bybit Recovers $48.4M of Its $1.5B Lazarus Hack

Bybit has recovered $48.4 million of the $1.5 billion stolen in February's Lazarus attack, with another $30.5 million frozen across exchanges, court filings show.
Bybit says it has recovered $48.4 million of the roughly $1.5 billion stolen in the February 2025 hack attributed to North Korea's Lazarus Group. Another $30.5 million remains frozen at more than 28 exchanges and custodians, according to the exchange's latest update following the August 6 unsealing of its U.S. federal case against North Korea, the Reconnaissance General Bureau, the Lazarus Group and 20 unidentified defendants.
The distinction between "recovered" and "frozen" matters. Recovered funds represent about 3.2% of the stolen total, while frozen assets add roughly 2%, putting the combined preserved or returned pool at about 5.3%. A freeze prevents an asset from moving while legal ownership is resolved, but it does not mean the funds are back under Bybit's control and can still face challenges from account holders, intermediaries or other claimants.
Legal Timeline and Current Status
Bybit filed its case under seal on June 18 in the U.S. District Court for the District of Columbia. Judge John Bates granted expedited discovery and a temporary restraining order on June 19, renewed the restraint on July 16 and partially granted a preliminary injunction on July 30. The record was unsealed on August 6. The preliminary injunction applies to identified stolen assets connected to the John Doe defendants, but it is not a final judgment against North Korea or Lazarus. The judge found Bybit had shown a likelihood of success on its Computer Fraud and Abuse Act and conversion claims, an interim standard used when deciding whether assets should be preserved during litigation.
Bybit is seeking the return of stolen assets, about $1.5 billion in compensatory damages, punitive damages and treble damages under federal racketeering law. None of those damages has been awarded, and direct collection from North Korea would be difficult even with a win. The practical focus is on wallets, account holders and service providers.
The FBI attributed the theft to North Korea on February 26, 2025, calling the activity TraderTraitor. Bybit told the court in June that 90.2% of the stolen assets had become untraceable after passing through mixers, cross-chain bridges and over-the-counter dealers, leaving only 9.8% connected to identifiable wallets at the time of filing.
German authorities seized €34 million and closed eXch in May 2025 over links to the Bybit theft, and German and Swiss authorities later shut Cryptomixer and seized €25 million in Bitcoin. Bybit also launched a bounty programme offering up to 10% of recovered funds, with a potential ceiling of $140 million, and introduced a security programme covering wallet controls, audits and threat monitoring.
Bybit CEO Ben Zhou said, "Our focus has never changed: protect our users first, recover what we can, and make sure the people behind these attacks are held accountable." The court case improves Bybit's ability to pursue the identifiable portion of the haul, but about 94.7% of the original $1.5 billion remains outside the recovered-or-frozen total. Converting the $30.5 million freeze into returned assets is the next measurable test.
Source: FinanceFeeds