Lazarus Group Routes $30M Through Hyperliquid Amid US Regulatory Push
OFAC-sanctioned North Korean hackers moved $30 million through the decentralized exchange Hyperliquid, raising fresh concerns about security and compliance just weeks after US regulators began working on a pathway to integrate the platform into American markets.
Sanctioned Hackers Target Major DEX
Blockchain addresses linked to the Lazarus Group, an OFAC-sanctioned collective attributed to North Korea, have moved $30 million in digital assets through the decentralized exchange Hyperliquid, according to blockchain analysis released by Arkham. The illicit transfers began with funds deposited in Bitcoin, which were then converted to Ether or Solana before being bridged across multiple networks including Tron, Solana, and Ethereum.
The final destinations of these sanctioned funds included the major trading venues KuCoin, Kraken, and Lbank, along with several unidentified services operating on the Tron blockchain. This incident demonstrates a critical vulnerability in decentralized exchange infrastructure, where illicit capital can move through platforms despite the immutable nature of blockchain transactions making the flow clearly visible to observers.
Regulatory Timing Creates Additional Complications
The movement of sanctioned funds through Hyperliquid occurred just weeks after US President Donald Trump announced that Commodity Futures Trading Commission Chair Michael Selig was working to establish a regulatory framework that would allow Hyperliquid to operate within American markets. During a White House event on August 16, Trump emphasized the administration’s commitment to developing clear pathways for decentralized finance platforms to achieve compliance and legitimacy within the existing regulatory structure.
The appearance of Lazarus Group activity on Hyperliquid during this critical moment in regulatory negotiations raises significant concerns about the exchange’s ability to implement robust compliance measures and identify suspicious transactions before they complete. Such incidents could potentially undermine confidence in Hyperliquid’s operational readiness and complicate the path toward regulatory approval.
Escalating North Korean Cyber Activity Against Crypto
The Lazarus Group has established itself as one of cryptocurrency’s most dangerous and persistent threats. The collective is believed to be responsible for some of the industry’s most devastating attacks, including a $1.4 billion theft from Bybit exchange in 2025, which currently stands as the largest cryptocurrency hack on record. The pattern of North Korean state-linked cyber activity remains alarming, with threat actors associated with the regime accounting for at least $578 million of the $634 million in total cryptocurrency losses across security incidents in April alone.
The recurring exploitation of exchange vulnerabilities and the ability to move illicit proceeds through decentralized platforms underscore growing regulatory concerns about operational security within the crypto ecosystem. These challenges highlight the compliance hurdles that decentralized exchanges must address as they pursue mainstream institutional adoption and regulatory approval.
Source: Arkham, via Cointelegraph. Not financial advice.