International precedent: Crypto exchange sues North Korea for $1.5 billion
The Bybit exchange is suing North Korea in a Washington federal court, claiming that the Lazarus hacker group operates under the regime's sponsorship and stole half a million Ethereum coins worth $1.5 billion from it. The court ordered the freezing of assets, but most of the money has already been laundered and disappeared into the network.

Bybit, one of the world's largest cryptocurrency trading exchanges, is taking an unprecedented legal step and filing a lawsuit against the government of North Korea, its military intelligence agency (RGB), and the notorious hacker group Lazarus.
The lawsuit, filed in the U.S. District Court for the District of Columbia in Washington, marks the first time in history that a private commercial entity in the crypto industry has directly sued a sovereign state for a cyberattack and the theft of digital assets. In the legal world, the move is already being defined as an international precedent that could change the rules of the game in the fight against state-sponsored cyberterrorism.
Only 5% of the amount recovered
According to Bybit, in February 2025, Lazarus, identified by U.S. intelligence authorities as a hacker group operating under the sponsorship of the North Korean government, stole about 500,000 Ethereum coins — with a total value of $1.5 billion.
According to the suspicion, the hackers deceived Bybit's internal system, as the employees who were supposed to approve the transfer of funds saw on the screen that everything was in order and the money was supposed to reach its destination, but in practice, they approved — without knowing it — a transfer of hundreds of millions of dollars to the hackers' account.
Despite efforts to track the funds, most of them have already disappeared. According to estimates, about 90% of the funds are no longer traceable, after the hackers used sophisticated obfuscation methods: mixing the money with other funds, transferring between different blockchain networks, and selling through private parties — all to sever the trail between the stolen money and those who currently hold it. Along the way, most of the Ethereum was converted to Bitcoin.
Bybit did not settle for chasing the stolen funds, but filed a RICO lawsuit (a law originally intended to combat organized crime) against North Korea, the RGB, and Lazarus. The judge has already ruled that "Bybit has demonstrated a high probability of success in the lawsuit" and ordered the freezing of the stolen assets that were found.
However, North Korea does not recognize the authority of American courts and its representatives are not expected to appear at the hearings, so collecting $1.5 billion directly from Pyongyang, experts say, is a fantasy. However, so far Bybit has managed to recover about $48.4 million and freeze another $30.5 million across more than 28 exchanges — about 5% of the amount stolen.
At the same time, other countries are involved in the affair. Authorities in Germany recently shut down eXch, a crypto exchange that reportedly was used to launder stolen money from various sources, including, apparently, some of the money stolen from Bybit. In addition, a joint operation by German and Swiss authorities stopped the services of Cryptomixer.io, a platform designed to obscure the origin of stolen money.
Deepfakes on Zoom: North Korea upgrades its attacks
The Kimsuky hacker group, identified with North Korea, has begun to operate its own artificial intelligence (AI) systems to plan and execute cyberattacks against crypto companies — this is according to new research by the South Korean cybersecurity company Genians.
Unlike using common AI services like ChatGPT, the group runs the models directly on its own computers. The advantage for it is clear: sensitive information about targets does not pass through external servers that could expose the activity. It uses this infrastructure to write malicious software, analyze information about targets, and prepare forged documents that are difficult to distinguish from real ones.
This is not the only group adopting the new tools. Another group, BlueNoroff, also identified with the regime in Pyongyang, operates with a no less sophisticated method: it creates fake participants for Zoom calls, using a combination of faces created by AI with body movements copied from previous real meetings. The victim is invited to such a call without knowing that they are actually talking to an artificial character. At the end of the call, malicious software is installed on their computer that checks which crypto wallets they hold in their possession.
The data points to a clear trend: about 80% of the targets of these groups operate in the crypto industry, and founders and CEOs make up almost half of the identified targets. Beyond external attacks, North Korea also occasionally infiltrates employees under fake identities directly into crypto companies to gain internal access to systems.
Robbers directed by the regime
The Bybit lawsuit, it seems, is only the tip of the iceberg. According to a report published by the blockchain analysis company TRM Labs last month, hackers identified with North Korea stole about $600 million in crypto just between January and April 2026 — and they are responsible for about 76% of the total value of crypto stolen in the world during that period. Such a rate, according to experts, cannot stem from pirate activity by individual hackers, but from a system coordinated and directed by the intelligence arms of the dictatorial regime.
April was particularly notable: within two weeks, two crypto platforms, Drift Protocol and Kelp DAO, suffered hits of hundreds of millions of dollars each. In both cases, the attackers chose not to focus on technical code vulnerabilities, but struck directly at the authentication infrastructure and digital signature systems — similar to a method of operation that also characterized the hack of Bybit. The similarity in the attack method strengthens the assessment that this is the same attack infrastructure that is centrally managed by the Lazarus group and those who operate it.





