Bybit, one of the world’s largest cryptocurrency exchanges, is taking an unprecedented legal step and filing a lawsuit against the North Korean government, its military intelligence agency (RGB) and the notorious hacker group Lazarus.
The suit, filed in federal court in the District of Columbia in Washington, marks the first time in history that a private commercial entity in the crypto industry has directly sued a sovereign state for a cyber attack and theft of digital assets. In the legal world, the step is already being defined as an international precedent, which may change the rules of the game in the fight against state-sponsored cyber terrorism.
Only 5% of the amount was returned
According to Bibit, in February 2025, Lazarus, identified by American intelligence agencies as a group of hackers operating under the auspices of the North Korean government, stole approximately 500,000 Ethereum coins – with a total value of 1.5 billion dollars.
Allegedly, the hackers cheated Bibit’s internal system, when the employees who were supposed to approve the transfer of funds saw on the screen that everything was in order, and that the money was supposed to reach its destination, but in practice they approved – without knowing – the transfer of hundreds of millions of dollars to the account of the hackers.
Despite efforts to trace the funds, most of them have already disappeared. According to estimates, about 90% of the funds are no longer traceable, after the hackers used sophisticated obfuscation methods: mixing the money with other funds, transferring it between different blockchain networks and selling it through private parties – all in order to cut off the traces between the stolen money and who currently owns it. Along the way, most of the Ethereum was converted to Bitcoin.
Bibit was not satisfied with the pursuit of the stolen funds, but as mentioned filed a RICO lawsuit (a law originally designed to fight organized crime) against North Korea, RGB and Lazarus. The judge has already determined that “Bibit has demonstrated a high probability of success in the lawsuit”, and ordered the freezing of the stolen assets that were found.
However, North Korea does not recognize the authority of the American courts, and its representatives are not expected to attend the hearings, so collecting 1.5 billion dollars directly from Pyongyang, experts say, is a fantasy. However, so far Bibit has managed to return about 48.4 million dollars and freeze another 30.5 million dollars across more than 28 exchanges – about 5% of the stolen amount.
At the same time, other countries are involved in the affair. German authorities recently shut down eXch, a crypto exchange that was reportedly used to launder stolen funds from various sources, including apparently some of the money stolen from Bibit. In addition, a joint action by the German and Swiss authorities stopped the services of Cryptomixer.io, a platform designed to obscure the source of the stolen money.
Zoom deepfake: North Korea is upgrading its attacks
The hacker group Kimsuky (Kimsuky), which is associated with North Korea, has started to use its own artificial intelligence systems to plan and carry out cyber attacks against crypto companies – according to a new study by the South Korean cyber security company Genians.
Unlike using common AI services like ChatGPT, the group runs the models directly on their computers. The advantage for her is clear: the sensitive information about the targets does not go through external servers that could reveal the activity. It uses this infrastructure to write malware, analyze information about the targets and prepare fake documents that are hard to distinguish from the real thing.
This is not the only group adopting the new tools. Another group, BlueNoroff, also identified with the regime in Pyongyang, operates with an equally sophisticated method: it creates fake participants for Zoom conversations, using a combination of AI-generated faces with body movements copied from previous real meetings. The victim is invited to such a conversation without knowing that he is actually talking to an artificial character. At the end of the conversation, malicious software is installed on his computer that checks which crypto wallets he has in his possession.
The data indicates a clear trend: about 80% of the targets of these groups operate in the crypto industry, and founders and CEOs make up almost half of the identified targets. In addition to outside attacks, North Korea also occasionally infiltrates employees under false identities directly into crypto companies, in order to gain internal access to systems.
Robbers directed by the regime
Bibbitt’s lawsuit, it seems, is only the tip of the iceberg. According to a report published by the blockchain analysis company TRM Labs last month, hackers identified with North Korea stole about $600 million in crypto between January and April 2026 alone – and they are responsible for about 76% of all crypto value stolen in the world during that period. Such a rate, according to experts, cannot result from the piratical activity of individual hackers, but from a coordinated and directed system by the intelligence arms of the dictatorial regime.
The month of April stood out in particular: within two weeks, the two crypto platforms Drift Protocol and Kelp DAO took hits of hundreds of millions of dollars each. In both cases, the attackers chose not to focus on technical code breaches, but directly damaged the authentication infrastructure and digital signature systems – similar to the method of operation that also characterized the Bibit hack. The similarity in the attack method reinforces the assessment that this is the same attack infrastructure that is centrally managed by the Lazarus group and whoever operates it.
For your attention: The Globes system strives for a diverse, relevant and respectful discourse in accordance with the code of ethics that appears in the trust report according to which we operate. Expressions of violence, racism, incitement or any other inappropriate discourse are filtered out automatically and will not be published on the site.
Cash Discounting To Offset Credit Card Processing Fees: Payment Solution Updated | FWNBC
Caterina's Club Serves Its 12 Millionth Meal | FWNBC
Certified Security Systems Hits 200 Five-Star Reviews|Trusted Security Installer | FWNBC
Combining Yoga & Qigong: Benefits of Mixed Mind-Body Practice | FWNBC
Content Marketing Service for AI Search Visibility & Brand Mentions Announced | FWNBC
Cost to Build Custom Home in Missouri: Price Guide Released | FWNBC
DFY Social Media Marketing for SMB Visibility: Holistic Content Campaigns Update | FWNBC
Electrical Sourcing Partner Selection for Industrial Projects: Resource Released | FWNBC
Experts Release 5 Steps That Work For Small Business Phishing Protection | FWNBC
Frequency Specific Microcurrent Pro Device: Pain Management Protocols Updated | FWNBC
Frisco, TX HVAC Repair Company Selection: Guide For Homeowners Announced | FWNBC
FSM Training for Neuropathic Pain & Myofascial Therapy: Online Course Announced | FWNBC
Group Health Insurance Houston Highlights Expanded Affordable Coverage Options | FWNBC
Lead Response Time Impact on Close Rates: Why Slow Follow-Up Costs You the Job | FWNBC
Living Will Guide To End-Of-Life Medical Decision Making For Seniors Released | FWNBC
News
News
News
News
News
News
Stock Market
News
News
News