Bybit Sues DPRK and Lazarus Group Over $1.5B Hack, Wins Asset Freeze
Bybit, the world's second-largest cryptocurrency exchange by trading volume, has filed a civil lawsuit in a US federal court against the Democratic People's Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB) intelligence agency, and the state-linked hacking organisation known as the Lazarus Group. The action, filed in the US District Court for the District of Columbia, follows the February 2025 theft of approximately $1.5 billion in Ethereum from the Dubai-based exchange. Alongside the lawsuit, Bybit has secured a preliminary injunction ordering certain unnamed defendants not to move or liquidate identified stolen assets while the litigation is ongoing. For accounting firms, auditors, and CFOs managing digital asset portfolios, this development carries direct implications for counterparty risk, stolen-asset accounting, and AML screening protocols.
What Happened and What the Court Has Ordered
The February 2025 Theft
On 21 February 2025, attackers linked to the Lazarus Group executed what has been described as the largest cryptocurrency theft in history. They drained approximately 400,000 ETH and staked ETH (stETH) from Bybit's cold wallet infrastructure, with the total value at the time of the hack placing the loss at roughly $1.5 billion. North Korean state-sponsored actors have since been widely attributed responsibility by US law enforcement and blockchain analytics firms. According to data cited in the CoinDesk report from Chainalysis, North Korean hackers stole $2.02 billion in crypto across all incidents last year, with the Bybit heist accounting for the bulk of that figure. Cumulative theft attributed to North Korean actors now stands at $6.75 billion, funds that US authorities and allied governments believe are channelled into weapons development programmes.
The Civil Lawsuit and Preliminary Injunction
Bybit's legal team filed the civil action independently of any ongoing criminal investigation conducted by US law enforcement authorities. The exchange made clear that the two tracks, civil and criminal, run in parallel rather than one depending on the other. The preliminary injunction, granted by a federal judge, prohibits a group of currently unidentified defendants (listed as John Doe respondents) from transferring, selling, or otherwise dissipating the specific digital assets identified as proceeds of the hack. The order is designed to preserve those assets in place while the court proceedings continue, giving Bybit and its legal team time to build a fuller case and seek additional relief.
Ben Zhou, Bybit's co-founder and CEO, described the action as part of a broader effort coordinated with investigators, fellow exchanges, regulators, and law enforcement. His public statement framed the Lazarus attack not merely as a theft from one platform but as an assault on industry-wide trust, signalling that Bybit intends to pursue accountability rather than simply absorb the loss.
Why This Matters for Accounting Firms and CFOs
Stolen-Asset Accounting and Balance Sheet Treatment
When a digital asset custodian or exchange loses funds to theft, the accounting questions are immediate and consequential. Under US GAAP, crypto assets are currently measured under the FASB's fair-value guidance introduced in ASU 2023-08, which requires mark-to-market recognition of gains and losses. A theft of this magnitude forces a write-down of the stolen assets at the point of loss, with any subsequent recovery treated as a separate recognised gain in the period it is realised.
For firms that held Bybit as a custodian, or that had counterparty exposure to Bybit in any form, the period immediately following February 2025 required a careful assessment of whether any balance sheet positions needed to be restated, impaired, or disclosed. The new civil lawsuit and the asset-freeze injunction introduce a second layer of accounting judgement: if frozen assets are eventually returned, how and when does a recovering entity recognise that inflow? In most cases, recovery income is recognised only when it is substantially certain and measurable, conditions that a preliminary injunction alone does not satisfy.
Counterparty and Custodial Risk Reviews
The scale of the Bybit hack, and the fact that the attackers reportedly compromised cold wallet signing infrastructure rather than a hot wallet, has forced a reappraisal of custodial risk across the industry. Accounting firms advising corporate treasury teams or digital asset funds should be revisiting the due-diligence frameworks applied to exchange and custodian selection. Key questions include the robustness of multisig and MPC key management, insurance coverage limits versus actual asset values, and the adequacy of business continuity disclosures in financial statements.
Robust crypto compliance reporting workflows are no longer optional for firms with material digital asset exposure. Auditors in particular need to understand the on-chain provenance of assets under custody, because an asset freeze order of the kind granted here could, in a different fact pattern, affect a client's own holdings if they inadvertently received tainted funds through a chain of transactions.
AML and OFAC Screening Implications
Sanctions Exposure Through Tainted Funds
The Lazarus Group and associated DPRK entities are designated under US Treasury OFAC sanctions. Any US person or entity that receives, holds, or facilitates a transaction involving funds traceable to a sanctioned party is potentially in violation of the International Emergency Economic Powers Act (IEEPA) and related sanctions regulations, regardless of whether they knew the funds were tainted. The asset-freeze injunction in the Bybit case names John Doe defendants, which means the court has already accepted that identifiable assets connected to the theft exist and can be located in specific wallets or accounts.
For accounting firms and CFOs, this creates a concrete screening obligation. Any crypto bookkeeping software or digital asset accounting software used by the firm needs to be capable of producing transaction histories that can be cross-referenced against OFAC's Specially Designated Nationals (SDN) list and against known Lazarus Group wallet clusters. Firms that cannot demonstrate they performed this screening at the time of receiving or processing a digital asset transaction face potential regulatory exposure if those funds are later found to have a North Korean nexus.
Our earlier analysis of OFAC sanctions on crypto facilitators and what firms must act on set out the practical steps for building an SDN screening workflow into digital asset operations. The Bybit action reinforces every point made there: the volume of sanctioned crypto flowing through secondary and tertiary wallets is large enough that passive reliance on an exchange's own compliance is not sufficient due diligence.
What a Preliminary Injunction Signals to the Broader Market
The issuance of a preliminary injunction against unnamed defendants holding identified stolen assets is procedurally significant. It demonstrates that US federal courts are willing to use civil mechanisms to freeze crypto in situations where criminal prosecution of a sovereign state is practically impossible. DPRK cannot be extradited, and its government will not appear voluntarily. The civil route, combined with an asset freeze targeting specific on-chain holdings, is therefore the most operationally useful tool available. If the identified assets are held at or routed through any exchange or intermediary operating under US jurisdiction, those entities will now face court orders compelling them to act, and non-compliance would expose them to contempt proceedings.
For exchanges, OTC desks, and DeFi protocols with any US nexus, this action sets a precedent. Compliance teams should review their ability to respond to court-ordered asset freezes rapidly, including the internal processes required to flag, hold, and report on specific wallet addresses when a freeze order is received.
Broader Enforcement Context and Financial Statement Disclosure
North Korean Crypto Theft at Scale
The cumulative $6.75 billion attributed to North Korean state actors is not a background statistic. It represents a systematic and ongoing threat to any institution holding or transacting in digital assets. For listed companies and funds required to disclose material risks under SEC reporting obligations, the persistence and scale of state-sponsored crypto theft constitutes a risk factor that must be addressed explicitly in filings. Boilerplate cybersecurity risk language is unlikely to satisfy auditors or regulators if a company has material digital asset holdings and has not conducted specific due diligence on custodial security.
The Bybit case also illustrates the reputational and operational consequences of being the victim of a large-scale hack, even when the exchange itself acted swiftly and transparently. Bybit reportedly covered the shortfall and maintained operations, but the legal costs, reputational damage, and ongoing litigation burden are real costs that should inform how CFOs model contingent liabilities around digital asset custody arrangements.
Implications for Audit Engagements
Auditors working on engagements where a client held assets on Bybit during the period of the hack, or received assets that may have passed through wallets later identified as connected to the theft, face a heightened duty of inquiry. ISA 240 (and its PCAOB equivalent AS 2401) requires auditors to assess the risk of material misstatement arising from fraud, and a theft of this magnitude at a major exchange is precisely the kind of event that should trigger enhanced procedures. These include obtaining confirmations of year-end balances, tracing on-chain receipts against blockchain records, and documenting the firm's assessment of whether any received funds have a plausible connection to tainted addresses.
Cases like this one also highlight the growing value of crypto fraud enforcement actions as a reference point for audit risk assessments. Each successful civil or criminal action in this space produces court findings that can inform the materiality thresholds and risk indicators auditors use in subsequent engagements.
Practical Steps for Accounting Firms and CFOs
Immediate Actions to Consider
First, review any client or corporate exposure to Bybit as a custodian or counterparty in the period around February 2025. Determine whether any balance sheet positions were affected and whether disclosures in financial statements for that period were adequate. Second, run transaction histories through OFAC SDN screening, specifically checking for wallet addresses publicly attributed to the Lazarus Group by US law enforcement or confirmed blockchain analytics providers. Third, review custodial contracts to understand what rights the firm or its clients have in the event of a theft and what insurance, if any, applies.
Fourth, ensure that any digital asset accounting software in use can export transaction-level data in a format suitable for legal proceedings or regulatory requests. The Bybit litigation is a reminder that court-ordered discovery in a crypto context means producing blockchain records, wallet addresses, and timestamped transaction logs, not just general ledger summaries. Firms whose crypto bookkeeping software cannot produce this level of detail are underequipped for the current enforcement environment. Fifth, update risk disclosures in financial statements to reflect the demonstrated reality of state-sponsored crypto theft as a specific and material risk category, not merely a generic cybersecurity footnote.
Frequently Asked Questions
Does the Bybit lawsuit create any direct legal obligations for US accounting firms?
The lawsuit itself does not directly bind third-party accounting firms. However, if a firm or its clients hold assets that a court later identifies as proceeds of the hack, they could receive a court order requiring them to freeze or hand over those assets. Separately, existing OFAC sanctions obligations already require US persons to avoid transacting with DPRK-linked entities and to screen for tainted funds.
How should a CFO account for digital assets that may be subject to an asset-freeze injunction?
If a company holds assets that are the subject of a court-ordered freeze, those assets should be disclosed as restricted and should not be included in readily available liquidity measures. The accounting treatment depends on whether the company is the victim seeking recovery or a holder of potentially tainted funds. In either case, the notes to the financial statements should describe the nature and estimated value of the restricted assets and the expected timeline for resolution.
What does the preliminary injunction mean for exchanges and OTC desks operating in the US?
Any exchange or intermediary operating under US jurisdiction that holds wallet addresses named or subsequently identified under this injunction will be legally required to comply with the freeze order. Non-compliance risks contempt of court proceedings. Compliance teams should have a documented process for receiving and acting on such orders promptly.
Is OFAC screening against Lazarus Group wallets already a legal requirement for US firms?
Yes. The Lazarus Group and associated DPRK entities are listed on OFAC's SDN list. US persons are prohibited from engaging in transactions with designated parties or their property. This means that any firm knowingly or unknowingly receiving funds traceable to those wallets is potentially in violation of US sanctions law, and ignorance of the source is not a complete defence, making proactive screening essential.
How does the civil lawsuit track differ from the criminal investigation?
Bybit has confirmed that the civil action runs independently of any criminal investigation by US law enforcement. The civil route allows Bybit to pursue asset recovery and accountability through the courts without waiting for a criminal prosecution that may never materialise given DPRK's sovereign status. The civil court can issue asset-freeze orders and, ultimately, judgements requiring asset transfer, even in the absence of a criminal conviction.
Source: CoinDesk Policy
