How the Bybit hack was laundered so fast

As of August 2026: Only about 3% of the stolen funds (~$40–65 million) was frozen in the weeks after the theft; the rest is considered laundered. eXch's infrastructure was seized by Germany's BKA on April 30, 2025. No authoritative larger recovery had been announced.

On February 21, 2025, attackers stole roughly $1.5 billion in ether from the exchange Bybit: about 500,000 ETH, the largest crypto theft on record. Five days later the FBI formally attributed it to North Korea’s TraderTraitor operation, better known as Lazarus Group, and published 51 Ethereum addresses already busy moving the money.

What happened next is the part worth studying. Within about ten days, essentially the entire haul had been moved. For comparison: the 2016 Bitfinex thieves sat on their coins for years and still got caught. Lazarus treats laundering as a race, and in 2025 it ran the race in record time.

The pipeline

Step one: fragment. The ETH was immediately split across hundreds of fresh wallets, standard practice to multiply the tracing work before analytics firms can label addresses.

Step two: hop chains. The bulk was converted from ether to bitcoin using THORChain, a decentralized cross-chain swap protocol with no operator to serve papers on and no KYC to fail. Analysts tracking the flows reported THORChain processed over $5.5 billion in volume in that window, with roughly 86% of the stolen funds ending up as ~12,800 BTC spread across some 9,100 wallets.

Step three: wash through no-KYC services. A meaningful share passed through eXch, a swap service that openly declined to block the FBI-flagged addresses. That decision had a price: German federal police seized eXch’s servers on April 30, 2025, taking 8 terabytes of data and €34 million in crypto, and stating the service had laundered about $1.9 billion overall.

Step four: cash out slowly. From thousands of BTC wallets, the funds drip toward OTC brokers and buyers: the patient retail end of the operation, where North Korea’s networks convert coins into currency and goods.

Why it was so fast

Three structural reasons, each covered in depth in the technique pages linked below.

First, cross-chain infrastructure has no chokepoint: a decentralized protocol cannot freeze funds even when the FBI names the addresses on day five. Second, speed beats attribution: freezing requires a cooperative service holding the funds at the moment of the request, and Lazarus simply outran the paperwork, leaving only ~3% frozen. Third, state sponsorship removes the usual constraint: an ordinary criminal needs to cash out without being identified; Lazarus is already identified, indicted, and sanctioned, and simply does not care.

The Bybit laundering run is the strongest version of an argument that runs through the whole crypto section of this site: the ledger is public, the analytics are excellent, the attribution took days, and the money still left. Detection is not the same as recovery.

Related reading

Sources

  1. PSA250226: North Korea Responsible for $1.5 Billion Bybit Hack (FBI / IC3, February 2025).
  2. Germany takes down eXch cryptocurrency exchange, seizes servers (BleepingComputer, May 2025).
  3. Lazarus laundered Bybit hack funds via THORChain (BeInCrypto / Arkham data, March 2025).