$30M in Digital Assets Funneled Through Hyperliquid by Lazarus Group-Associated Wallets

$30M in Digital Assets Funneled Through Hyperliquid by Lazarus Group-Associated Wallets

Digital wallets associated with the OFAC-sanctioned Lazarus Group transferred approximately $30 million worth of cryptocurrency via Hyperliquid, coming just weeks following regulatory announcements about potential US market integration for the platform.

Cryptocurrency wallet addresses connected to the North Korean state-sponsored hacking organization known as the Lazarus Group successfully channeled $30 million worth of digital currencies through the decentralized trading platform Hyperliquid.

According to blockchain data provided by Arkham analyst Emmett Gallic in an X platform post published on Monday, the wallets bearing Lazarus tags transferred assets to Hyperliquid and HyperUnit using Bitcoin (BTC), subsequently converting these holdings into Ether (ETH) or Solana (SOL) before utilizing bridge protocols to transfer them to Tron, Solana or the Ethereum blockchain networks.

The funds were eventually routed to cryptocurrency trading platforms including KuCoin and Kraken, in addition to Lbank, alongside multiple unidentified services operating on the Tron blockchain infrastructure.

These transactions took place several weeks following statements made by US President Donald Trump indicating that Commodity Futures Trading Commission (CFTC) Chair Michael Selig was developing a regulatory framework designed to facilitate Hyperliquid's entry into US markets, based on remarks delivered during a White House gathering on Aug. 16.

The Lazarus Group stands as the primary suspect behind several of the most significant cryptocurrency security breaches in history, including the $1.4 billion exploitation of Bybit exchange in 2025, which represents the industry's most substantial incident to date.

Threat actors with connections to North Korea were linked to a minimum of $578 million out of the total $634 million that was stolen through cryptocurrency-related security incidents during the month of April.

← Back to Blog