According to crypto influencer on X ai_9684xtpa, Lazarus Group has moved 262.2 BTC, which is worth $16.64 million into a new wallet. According to the X post, the transfer happened today, August 13, 2026, and as of now, no one knows why the group made this move. Wallets that are linked to Lazarus Group still hold more than $73.06 million in on-chain assets (mostly include BTC, USDT, and ETH). This latest transfer comes as Bybit’s efforts to recover back funds from the February 2025 hack enter a new legal phase.
Bybit CEO Ben Zhou announced recently that the exchange has filed a civil suit in the U.S. District Court for the District of Columbia, naming the Democratic People’s Republic of Korea (DPRK), its Reconnaissance General Bureau (RGB), and Lazarus Group as defendants.
Bybit Takes the Fight to Court
Bybit’s legal push marks a new phase in the recovery process. The exchange filed its civil case against DPRK, RGB, and Lazarus Group, which U.S. authorities have identified as the DPRK-linked hacking group responsible for the February 2025 cyberattack.
Moreover, Bybit got a preliminary injunction freezing the stolen assets, even those held by unidentified people and entities, named as “John Doe” defendants. The order blocks these assets from being moved or hidden while the court litigation continues.
The company says the court agreed that the exchange has a high chance of winning on the case’s merits. This civil suit is separate from ongoing criminal investigations led by U.S. law enforcement. Bybit says it is still working with agencies like the FBI, sharing blockchain intelligence and findings. So far, Bybit has recovered roughly $48.4 million in stolen funds. There is another $30.5 million frozen at more than 28 exchanges and custodians, awaiting further legal or investigative action.
Recovery Effort Relies on Industry Cooperation
The recovery process depends on industry wide teamwork. Bybit says exchanges, blockchain analytics firms, custodians, and international law enforcement have all helped trace these stolen assets and disrupt laundering channels. The exchange also pointed to enforcement moves against platforms suspected of aiding crypto laundering. German authorities took down the exchange eXch, and later, German and Swiss agencies disrupted Cryptomixer.io. Bybit sees these actions as proof that public and private cooperation can target criminal networks moving stolen crypto.
Bybit also calls this hack a warning sign for the whole digital asset industry, and not just a single exchange’s problem. The company’s approach mixes blockchain intelligence, partnership with industry partners, and legal action to safeguard whatever assets remain recoverable. Lazarus Group’s latest Bitcoin transaction shows their wallets still are not inactive. Meanwhile, Bybit’s court action adds another layer to the effort to trace, freeze and recover funds connected to the February 2025 attack.
Lazarus Workers Trapped by Fake DeFi Company
In other news, researchers have managed to turn Lazarus-linked workers’ own recruitment methods against them. According to details shared by PANewsCN, cybersecurity firm ANY.RUN set up a fake DeFi company and used it as a bait to recruit members of the Famous Chollima subgroup that is tied to Lazarus. Three suspected hackers landed jobs through this scheme where one started working on front-end development, one on the back-end, and another one focused on smart contract development. From their point of view, they had landed legitimate positions at a tech company.
But the company wasn’t real. ANY.RUN kept these workers inside a controlled environment and tracked everything they did for several weeks. Researchers watched as the suspects went about their work, believing they were a part of a genuine DeFi project. This setup gave the cybersecurity team an inside look at the tools and methods the Lazarus-linked workers use. According to the findings, monitoring revealed the group’s full “crime” toolkit. Here, the roles are reversed, rather than Lazarus infiltrating companies with fake recruitment, this time, the researchers created the company and watched as the suspects walked right in themselves.
