• 5 mins read
  • Published

Bybit Hack Shows Why Stolen Crypto Is So Hard to Recover

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Bybit Hack Shows Why Stolen Crypto Is So Hard to Recover EgonCoin © egoncoin.com
Bybit Hack Shows Why Stolen Crypto Is So Hard to Recover © egoncoin.com

A $1.5 billion crypto theft tied to North Korea highlights the limits of legal action and blockchain transparency, as most stolen funds vanish before courts can intervene and only a fraction is ever frozen or recovered

The aftermath of the $1.5 billion Bybit hack is exposing the practical limits of recovering stolen cryptocurrency, even as exchanges and law enforcement pursue aggressive legal action. Bybit filed suit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, securing a preliminary injunction to block the movement or sale of certain stolen assets. Yet, the court order came more than 17 months after the February 2025 breach, long after most of the stolen funds had already been laundered through a complex web of exchanges, bridges, and mixing services.

Legal Action vs. Blockchain Speed

According to public court records, the injunction covers only the assets that could be identified and reached, without confirming whether the full $1.5 billion is protected. Blockchain analytics firms like Chainalysis and Elliptic have documented how North Korean-linked groups typically move stolen crypto through laundering pipelines within about 45 days-far faster than the legal system can respond. In the Bybit case, industry partners managed to freeze $42.9 million in the immediate aftermath, and mETH Protocol recovered another $43 million in cmETH tokens. Combined, these early interventions secured roughly $85.9 million, or just under 6% of the total stolen. Elliptic's review found that over $1 billion had already been laundered within six months of the hack, well before the court order was issued.

Where Stolen Crypto Gets Stuck

The ability to freeze or recover stolen crypto depends heavily on where the assets end up. Tokens held in self-custody as native ETH or Bitcoin are nearly impossible to freeze, since no central party controls those balances. In contrast, stablecoins and liquid-staking tokens can sometimes be blocked by their issuers, and centralized exchanges can freeze withdrawals or comply with court orders. The Bybit hackers quickly swapped stolen stETH and cmETH into native ETH, removing one of the few levers available to victims. Law enforcement agencies, including the FBI, have urged exchanges and infrastructure providers to block transactions linked to Lazarus Group, but the effectiveness of these efforts depends on how quickly the stolen funds move through the system.

Competing Claims and Recovery Limits

Even when stolen crypto is frozen, the question of who ultimately receives the assets can become contentious. In a separate incident involving the Kelp protocol, holders of terrorism judgments against North Korea served legal notices to claim frozen ETH, illustrating how multiple parties may compete for the same pool of seized funds. The U.S. Treasury Department has designated Lazarus Group and related entities as North Korean-controlled, citing their role in funding weapons programs. Chainalysis estimates that North Korean hackers stole more than $2 billion in crypto in 2025 alone, with cumulative thefts exceeding $6.75 billion. The trend points toward fewer but larger attacks, and the Bybit case underscores how quickly stolen assets can disappear beyond the reach of courts and compliance systems.

What Recovery Looks Like Now

The best-case scenario for Bybit and similar victims is that additional stolen funds surface at exchanges, stablecoin issuers, or custodians willing to cooperate, allowing recovery to rise above the $85.9 million already secured. More likely, the injunction will preserve only a small residual balance, with most of the $1.5 billion already laundered and out of reach. The legal process may provide a template for future recovery efforts, but the 17-month delay between the hack and the court order highlights the challenge of matching blockchain speed with legal remedies. As the crypto industry continues to grapple with large-scale thefts, the practical limits of asset recovery remain a central concern for exchanges, users, and regulators alike. For broader context on how liquidity pressures can affect crypto markets, see EgonCoin's analysis of U.S. Treasury reserve changes and Bitcoin liquidity.

Based on data from blockchain analytics firms and court filings, the Bybit hack remains one of the largest crypto thefts on record. Of the $1.46 billion in assets stolen in February 2025, only about $85.9 million was frozen or recovered in the first weeks after the incident. More than $1 billion was reportedly laundered within six months, and the court injunction arrived roughly 532 days after the breach. These figures highlight the speed at which stolen crypto can move through laundering channels compared to the pace of legal intervention.

Unlike traditional financial assets, most cryptocurrencies are designed to be irreversible once transferred, making recovery after a hack especially difficult. While stablecoins and some tokenized assets can be frozen by issuers, native tokens like ETH and Bitcoin offer little recourse once they leave a centralized platform. This structural feature of blockchain technology means that legal and compliance tools are often limited to assets that pass through exchanges, custodians, or other chokepoints. As a result, the effectiveness of asset recovery depends not only on legal action but also on the technical and operational realities of how crypto moves across networks and jurisdictions.

Related articles