Bybit stated that it is expanding collaboration with law enforcement and industry partners to strengthen accountability for crypto-related cybercrime . The civil asset freeze and discovery orders directly support law enforcement's ability to track and eventually recover stolen funds still moving through the crypto ecosystem.
Bybit's civil suit runs parallel to ongoing FBI-led criminal investigations. The FBI publicly attributed the Bybit hack to North Korea on February 26, 2025, naming the specific malicious cyber activity as "TraderTraitor" (also tracked as APT38) . Bybit has confirmed that the civil case remains separate from the ongoing U.S. criminal investigations
.
The dual-track approach—civil asset recovery and criminal prosecution—is a standard strategy in major financial crimes, allowing Bybit to pursue immediate asset freezes while law enforcement builds its criminal case.
The Bybit heist is the largest single incident in a much larger pattern. According to blockchain intelligence firm Chainalysis, North Korean hackers stole at least $2.02 billion in cryptocurrency in 2025, a 51% year-over-year increase that raised the DPRK's lower-bound cumulative crypto theft total to $6.75 billion . Globally, total cryptocurrency theft reached $3.4 billion in 2025
.
The thefts continued into 2026. In the first half of the year alone, North Korean-linked hackers stole roughly $643 million, accounting for about two-thirds of all crypto funds stolen worldwide . In April 2026, two precisely executed heists on decentralized finance platforms—a $285 million breach of Drift Protocol and a $292 million exploit of Kelp DAO—together accounted for 76% of all crypto hack losses tracked through that month
.
North Korean hacking groups have developed a sophisticated toolkit. The Bybit hack itself involved manipulation of a multisig signing interface during a routine Ethereum transfer from Bybit's cold wallet to a warm wallet, tricking signers into approving a malicious contract that drained the wallet .
Other methods include:
As of August 2026, BlueNoroff remains highly active. Researchers describe this operator-driven phishing platform as deploying AI deepfake video and wallet-scanning malware with a CVSS severity score of 9.5 (critical) S. The group continues to target Web3 executives, cryptocurrency exchanges, and DeFi platforms through increasingly sophisticated social engineering campaigns . Over five months starting in late 2025, more than 80 fake domains were registered for these attacks, and stolen video footage was combined with AI-generated images to enhance credibility
. Arctic Wolf's research identified more than 100 victims across more than 20 countries, including 41% in the United States
S.
These ongoing campaigns underscore why Bybit's civil lawsuit, the FBI's criminal investigation, and industry-wide collaboration all matter: the same state-sponsored infrastructure that stole $1.5 billion from Bybit is actively targeting the next victim right now.