BTC ETH SOL Current Affairs Security

Lazarus Just Moved $30M Through Hyperliquid—Right as It's Courting the U.S.

2026-09-01

North Korean hackers just moved $30 million through Hyperliquid while the platform's actively negotiating its way into U.S. markets. You couldn't script the timing worse if you tried.

Blockchain investigators tracked the activity across a three-week window ending August 31. Wallets linked to the Lazarus Group deposited Bitcoin into Hyperliquid's HyperUnit service, converted it into Ether and Solana, then routed the assets across Ethereum, Tron, and Solana networks toward deposit addresses at KuCoin, Kraken, and LBank. A neat little wash cycle, really—exactly the kind of thing regulators lose sleep over.

The wallets had been previously attributed to Lazarus by ZachXBT back in 2024, when they were sitting on roughly $61 million in stolen crypto. But the group's been busy since then. In February 2025, they orchestrated the Bybit hack—$1.4 to $1.5 billion gone in one swoop. Largest single heist in crypto history. The FBI's confirmed the connection runs straight back to North Korea's state apparatus. Same outfit behind the 2022 Ronin Network bridge exploit that drained $625 million.

And here's where it gets awkward for Hyperliquid. Just weeks before this $30 million appeared on the chain, Trump announced that CFTC Chair Michael Selig was actively working to carve out a compliant pathway for the platform into American markets. The Hyperliquid Policy Center's been in regulatory conversations with both the CFTC and SEC for months, trying to figure out how decentralized perpetual futures platforms can operate without blowing up existing market structure rules whilst staying non-custodial.

The core problem is structural. Decentralized exchanges are a completely different beast from traditional venues. Hyperliquid's permissionless architecture means users connect their own non-custodial wallets and trade derivatives without opening a brokerage account. That's privacy and freedom for legitimate traders. It's also a surveillance nightmare for regulators trying to catch bad actors moving stolen funds.

This isn't hypothetical. When you can't force account verification on everyone, when settlement happens on-chain in ways that don't require intermediaries, enforcement becomes exponentially harder. The asset flow tracking Arkham did proves the point—the wallets got in, moved the money around, and dispersed it across multiple networks before exiting to traditional exchanges. All of it visible if you're looking, but none of it stoppable without consent-based architecture.

The tension here is real. Policymakers want to modernize rules that were written for centralized intermediaries. Hyperliquid's proposed solutions—like permissioned deployment structures they're testing with Payward—could theoretically layer in compliance controls while keeping blockchain settlement intact. But then $30 million of sanctioned North Korean money flows straight through anyway.

Neither Hyperliquid Labs nor Payward have commented on the Arkham findings. The CFTC hasn't issued formal approval or detailed guidance. The announcement from Trump's team was regulatory exploration, not authorization. That distinction matters quite a bit as conversations advance.


Source & further reading:

Sources