Wallets linked to North Korea's Lazarus hacking group moved $30 million in bitcoin through the decentralized exchange Hyperliquid, converting the funds to ethereum and solana before routing them to centralized platforms, according to blockchain analysis by Arkham researcher Emmett Gallic.
The sequence, entry as bitcoin on Hyperliquid, conversion to multiple tokens, and exit through Tron, Solana, and Ethereum networks to KuCoin, LBank, and Kraken, compressed the asset swaps across chains. Lazarus has been sanctioned by the US Treasury since 2019 and linked to major breaches including the 2014 Sony Pictures hack and the 2022 Ronin Bridge theft, which cost $625 million. The group's continued access to major exchanges despite sanctions enforcement demonstrates both operational resilience and gaps in platform compliance screening.
Hyperliquid, launched in 2023, has grown into one of the largest perpetuals exchanges by volume, exceeding $50 billion in daily turnover by mid-2026. The platform operates as a decentralized orderbook on Solana but maintains centralized risk management. KuCoin and Kraken both operate under regulatory oversight in multiple jurisdictions and maintain sanctions screening systems. Neither exchange has disclosed receiving flagged funds in connection with this activity. LBank operates primarily in Asia and has faced fewer direct US regulatory pressures than US-licensed competitors.

The $30 million movement represents a fraction of Lazarus's estimated annual theft volume, which the US Department of Justice assessed at $100 million or more in 2024. The use of Hyperliquid rather than more established DEXs may reflect the group testing newer platforms for compliance gaps or diversifying its laundering infrastructure as older routes face tighter monitoring.
Hyperliquid's founders have said they are interested in US regulatory approval as part of the Trump administration's broader push to establish American crypto infrastructure. The detection of Lazarus activity on the platform within months of that policy shift may complicate those discussions, though platform operators often argue they cannot prevent token transfers on decentralized systems without custodial control that would sacrifice their operational model.