
This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is
Bybit sued North Korea, its Reconnaissance General Bureau, and Lazarus Group in the US District Court for the District of Columbia. The exchange won a preliminary injunction blocking unnamed defendants from moving or...
Bitcoin 1 Minute
An important story is making waves across the blockchain ecosystem. Bybit sued North Korea, its Reconnaissance General Bureau, and Lazarus Group in the US District Court for the District of Columbia. The exchange won a preliminary injunction blocking unnamed defendants from moving or selling stolen crypto. Public court reporting describes the order as covering those identified assets, without confirming the full $1.
5 billion stolen in February 2025 or disclosing the dollar value the injunction protects. This injunction landed roughly 532 days after the hack—about 17 months after North Korean hackers pulled off the largest crypto theft on record. Chainalysis tracked a consistent laundering pattern by DPRK-linked groups after a major theft, moving stolen funds through exchanges, bridges, mixers, and laundering services over roughly 45 days.
Market Dynamics
Coordinated action by industry partners froze $42. 9 million in the first days after the theft, and mETH Protocol recovered another 15,000 cmETH, worth nearly $43 million. Combined, that early save came to about $85.
9 million, roughly 5. Elliptic, citing a six-month review from zeroShadow, said more than $1 billion of the stolen funds had already moved through the laundering pipeline well before this new court order existed. Whatever value the injunction protects now probably represents a small residue that never fully escaped that pipeline.
21, 2025 Starting point of the largest crypto theft on record Reported court injunction timing ~532 days later Legal process arrived roughly 17 months after the theft DPRK laundering cycle ~45 days Stolen funds often move through the main laundering pipeline far faster than courts move Early frozen funds $42. 9 million Industry coordination worked immediately after the hack cmETH recovered ~$43 million Token/protocol-level recovery was possible early Total early save ~$85. 46 billion theft Funds reportedly laundered by six-month mark $1 billion+ Most value likely moved before the new injunction existed Why a blockchain never has to reverse anything Stolen crypto becomes stoppable the moment it lands somewhere a court order can reach: an exchange, a stablecoin issuer, a custodian, or any other operator capable of freezing what passes through it.
Market Impact
That is why the FBI asked exchanges, bridges and RPC operators to block Lazarus-linked transactions within days of the hack. It is also why Bybit's own stolen stETH and cmETH were swapped into native ETH almost immediately. Elliptic says token issuers can often freeze wallets holding their own tokens, but no central party directly controls ETH or Bitcoin balances.
Converting stolen liquid-staking tokens into native ETH removes one of the easiest tools available to victims for freezing assets. Native ETH or Bitcoin sitting in self-custody is nearly impossible to freeze directly, while stablecoins sit at the other end, since issuers can blocklist addresses depending on the chain and contract design. Centralized exchanges sit close behind, able to block withdrawals or comply with a warrant.
Bridges, swap services and DAO-controlled recovery wallets fall somewhere in between, and OTC brokers operating across borders remain the hardest targets of all. A Lazarus-linked theft from the crypto platform Rain drew a similar response. The FBI froze roughly 2,204 SOL at the exchange WhiteBIT and served a seizure warrant.
Crypto markets are watching this development closely as investors weigh its potential impact on prices.




