North Korean hackers moved $30 million in stolen cryptocurrency on Hyperliquid, according to blockchain analytics firm Arkham, as the Trump administration accelerates efforts to onshore the decentralized derivatives platform.
The activity occurred on Hyperliquid, a decentralized exchange that operates without geographic restrictions and has become a primary venue for high-volume trading in digital assets. The movement of funds tied to North Korean state-sponsored theft introduces operational risk precisely as U.S. officials seek to migrate Hyperliquid's core trading infrastructure onto American soil.
Arkham's analysis identified the $30 million transfer through on-chain data, tracing the movement of stolen assets through Hyperliquid's settlement and custody mechanisms. The firm's findings were reviewed by CoinDesk and published on August 31. Hyperliquid processes roughly $1 billion in notional daily volume according to public market data, making it one of the largest unregulated perpetual futures venues accessible globally.
The White House issued a statement on August 19 indicating the Trump administration would support onshoring Hyperliquid, positioning the platform as a potential centerpiece of a more crypto-friendly regulatory posture. Onshoring would require Hyperliquid to relocate operational control and matching engines to U.S. jurisdiction and submit to existing commodity futures and securities oversight. That process typically takes 18 to 36 months and involves substantial infrastructure redesign.

North Korean threat actors have stolen approximately $1.3 billion in cryptocurrency since 2020, according to U.S. Treasury and international law enforcement assessments. The Lazarus Group, a unit linked to North Korean military intelligence, has used decentralized exchanges and privacy tools to convert stolen digital assets into fiat currency or deploy them for operational funding. Hyperliquid's lack of user verification mechanisms and its architectural separation from traditional banking rails have made it a transit point for illicit proceeds.
The $30 million movement is one transaction among potentially dozens the regime conducts monthly across multiple platforms. Arkham's detection capability depends on address clustering heuristics and behavioral analysis; not all North Korean transfers are reliably identified in real time. The amount moved identifiably indicates either deliberate operational tempo or incomplete obfuscation by the attackers.
The concurrent timing of the Hyperliquid activity and the Trump administration's onshore push creates a policy tension: regulatory integration could improve surveillance of illicit flows, but onshoring alone does not require retroactive transaction freezing or seizure of assets already in transit. Hyperliquid has not published a response to the Arkham findings or stated whether it froze the wallets or accounts involved.