- Bybit’s June 2026 complaint says about $75.5 million (5.3%) of the $1.5 billion stolen in February 2025 had been frozen or recovered.
- An August 8 press release put the combined total at roughly $78.9 million, a gain of about $66,700 a day over the 51 days between the two figures.
- That rate is nearly identical to the pace Bybit posted before the lawsuit even existed, based on its own 2025 disclosures.
- At the current pace, clearing the remaining $1.42 billion would take on the order of 58 years.
The Recovery Numbers Barely Moved Between June and August
Bybit’s own court filings show that the pace of recovering funds stolen in the largest cryptocurrency theft in history has changed little in the seven weeks since the exchange sued North Korea. The complaint Bybit Technology Limited filed June 18, 2026 in the U.S. District Court for the District of Columbia states that approximately $75.5 million, about 5.3%, of the $1.5 billion stolen in February 2025 had been frozen or recovered as of that filing. An Aug. 8, 2026 press release announcing a preliminary injunction in the same case put the combined total at roughly $78.9 million: $48.4 million recovered plus $30.5 million frozen across more than 28 exchanges and custodians. That’s a gain of about $3.4 million over 51 days, or roughly $66,700 a day, against $1.42 billion still outstanding.
Recovery Timeline
| Date | Frozen / Recovered | Gone Dark (Unrecoverable) | Source |
|---|---|---|---|
| Feb. 23, 2025 | $42.89 million | – | Bybit’s own timeline |
| Mar. 4, 2025 | 3% | 20% | Zhou’s public update |
| Apr. 21, 2025 | 3.84% | 27.59% | Zhou’s public update |
| Jun. 18, 2026 | 5.3% ($75.5 million) | – | Complaint, filed |
| Aug. 8, 2026 | ~5.26% ($78.9 million) | – | Press release |
What the Injunction Actually Freezes
The case, Bybit Technology Limited v. Democratic People’s Republic of Korea (Case 1:26-cv-02173-JDB), names DPRK, its Reconnaissance General Bureau, the Lazarus Group and 20 unidentified wallet holders as defendants. A sovereign state normally can’t be sued in a U.S. court at all. The Foreign Sovereign Immunities Act blocks it by default. The complaint’s jurisdictional section exists specifically to engineer around that immunity, arguing the theft counts as “commercial activity” and an “expropriation” of property now traceable to U.S. exchanges, which triggers FSIA’s narrow exceptions. Bybit also leans on the Alien Tort Statute and civil RICO. A judge found Bybit “has demonstrated a likelihood of success on the merits” and granted the preliminary injunction. To establish why that immunity fight matters, the complaint cites TRM Labs data showing DPRK-linked actors stole $2.02 billion in cryptocurrency in 2025, a 51% jump from 2024, and were behind 76% of all crypto stolen globally through April 2026, or $577 million of a $759 million total. That scale isn’t isolated to Bybit. Just months earlier, North Korea-linked hackers were tied to a $286 million drain from the Drift Protocol, one of several 2026 incidents feeding into that same total.
“The Lazarus attack wasn’t just an attack on Bybit. It was an attack on trust in our industry.”
CEO Ben Zhou has said that. That framing does specific work for Bybit: it turns the $1.5 billion loss Bybit had to absorb itself into an industry cautionary tale, not a security failure. The injunction itself doesn’t change what’s already been laundered.
How the Hack Happened, Briefly
On Feb. 21, 2025, hackers drained roughly 401,347 ETH and other Ethereum-based assets from Bybit during what was supposed to be a routine transfer. The intrusion began around Feb. 4, when Lazarus Group hackers used social engineering to compromise a software developer’s workstation at Safe Wallet, the third-party platform Bybit used for multisig cold-wallet transactions (multisig meant multiple Bybit executives had to sign off before funds moved). From there, the attackers reached Safe Wallet’s AWS-hosted infrastructure and planted malicious code that altered what those signing executives saw on screen, tricking them into approving what looked like a routine transfer while actually authorizing a backdoored smart-contract upgrade. That approval step is exactly what multisig exists to protect. Bybit didn’t freeze customer withdrawals, honoring more than $4 billion in requests within 12 hours, and had fully replenished its ETH reserves within three days through bridge loans. It also launched a 10% recovery bounty program and a Lazarus-specific bounty platform that has since paid out more than $2.3 million to blockchain investigators.
Why the Plateau Predates the Lawsuit
The flat trend line didn’t start with the lawsuit. According to Zhou’s own public updates, just 3% of the stolen funds had been frozen as of March 4, 2025, with 77% still traceable and 20% already “gone dark,” his term for funds laundered beyond recovery. By April 21, 2025, Zhou put the frozen share at 3.84% and the gone-dark share at 27.59%, with 68.57% still traceable.
Read against the June 2026 complaint and August 2026 press release figures, the frozen or recovered percentage has crept from roughly 3% to about 5.3% over roughly 15 months. More than a quarter of the total was already unrecoverable within about two months of the theft.
The dollar-per-day pace of freezing tells the same story. Funds grew from Bybit’s own Feb. 23, 2025 figure of $42.89 million frozen to the June 2026 complaint’s $75.5 million at roughly $67,900 a day; the 51 days after that, through the August PR, added funds at about $66,700 a day. Those two rates, one from well before the lawsuit existed and one from just after the injunction, are close enough to suggest the injunction hasn’t yet changed the underlying rate. At that rate, clearing the remaining $1.42 billion would take on the order of 58 years.
Much of what could be recovered from this theft likely was already locked in, one way or the other, well before Bybit ever filed suit. That doesn’t make the legal case pointless: it creates standing authority to freeze and seize wherever traceable proceeds surface next, which matters for the funds that haven’t moved yet. It does mean the injunction is better read as a ceiling on further loss than as a mechanism that’s about to unlock a large share of what’s missing.
Separately, German and Swiss authorities dismantled two exchanges, eXch and Cryptomixer.io, on allegations they laundered part of the stolen funds. That action sits outside Bybit’s own case. The 5-to-6% figure Bybit reports counts only funds tied directly to its own theft, not this wider laundering infrastructure. Independent on-chain investigator ZachXBT has separately mapped a broader DPRK payment network moving illicit remittances well beyond this one case.
What We Don’t Know Yet
The docket shows a filing dated Aug. 6, 2026, two days before the press release. What that filing actually says isn’t public yet, so it isn’t clear whether that entry is the injunction order itself or something else in the case. The 20 John Doe defendants named as holders of stolen funds remain unidentified. Two questions the available record doesn’t answer: why Bybit waited roughly 16 months after the hack to file suit, and why Safe Wallet, whose compromised infrastructure was the actual attack vector, isn’t named as a defendant alongside DPRK, RGB and the Lazarus Group. Bybit hasn’t addressed either point publicly.
What Would Confirm or Break the Plateau
A future Bybit disclosure showing the frozen or recovered percentage jump meaningfully above the roughly 5-to-6% trend line, or the text of the Aug. 6 docket filing once it’s available, would settle whether this is a genuine plateau or a difference in how the figures were measured.
FAQ
Did any Bybit customers lose money?
No. Bybit says it covered the $1.5 billion loss itself and honored all withdrawal requests.
Will North Korea actually pay anything?
Almost certainly not directly. DPRK won’t appear in a U.S. court. The value of the suit is establishing legal authority to freeze and seize traceable proceeds as they surface, similar to the 2018 default judgment the same D.C. court entered against DPRK in the Otto Warmbier case.
AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.
We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.
















