Points of Focus
- Lazarus-linked wallets moved more than $30 million through Hyperliquid without evidence that the platform itself was compromised.
- The transactions highlight the gap between blockchain traceability and the ability to stop sanctioned actors before they transact.
- Hyperliquid’s potential US pathway raises a key question: Where should compliance sit when the underlying market remains permissionless?
North Korea’s notorious Lazarus Group has laundered more than $30 million through Hyperliquid in recent weeks, according to Arkham Intelligence researcher Emmett Gallic, with activity tracing right through Aug. 31. The hackers executed a complex multichain obfuscation route.
This illicit flow hits at a critical juncture for the platform. As millions linked to the US-sanctioned cybercrime cartel moved through Hyperliquid’s plumbing, US policymakers and financial institutions were actively exploring pathways to give American traders regulated access to Hyperliquid-linked markets.
The episode lays bare decentralized finance’s (DeFi) central dilemma: exposing the fundamental challenge of how regulators can safely integrate permissionless financial infrastructure into an ecosystem built entirely around identity verification and sanctions compliance.
How $30 million moved through Hyperliquid
Gallic’s analysis, along with subsequent reporting based on Arkham data, identified a cluster of wallets responsible for $30 million.
Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.@zachxbt identified these addresses as Lazarus Group in 2024 linked to $61M in stolen fundshttps://t.co/RNJ4NMBrxA pic.twitter.com/CvivPLVnEL
— Emmett Gallic (@emmettgallic) August 31, 2026
A second cluster involving $5 million displayed similar characteristics, including periods of dormancy and comparable counterparty behavior, although the attribution appears less direct.
Bitcoin (BTC) entered Hyperliquid, primarily through HyperUnit, an infrastructure that enables native assets, including BTC, to interact with the Hyperliquid ecosystem. The funds were subsequently converted into Ether (ETH) and Solana (SOL) before being moved across Ethereum, Solana, and Tron.
From there, some assets reached KuCoin, LBank, and Kraken, while other transfers went to unidentified Tron-based services.
Blockchain analytics can trace tokens to deposit addresses, but an onchain trail does not necessarily identify the beneficial owner of an account held at a centralized exchange.
Hyperliquid appears to have functioned as a trading and routing venue rather than the target of an exploit.

Hyperliquid wasn’t hacked — that is the point
Users interacting directly with decentralized protocols generally do not pass through the same account-opening process associated with conventional financial institutions.
Banks and regulated exchanges attempt to establish who customers are before giving them access. Public blockchains make transactions visible, allowing investigators to reconstruct activity afterward. However, visibility does not automatically provide the ability to stop a transaction before it happens.
The Lazarus-linked movements demonstrate both sides of the equation.
Investigators could follow funds across assets and networks because the transactions left public trails. Yet the same open infrastructure enabled those assets to move without the kind of identity checks expected at a regulated US financial institution.
Lazarus raises the stakes
Lazarus Group is not simply another collection of suspicious crypto wallets.
The US Treasury’s Office of Foreign Assets Control sanctioned the North Korean hacking group in 2019, identifying it as controlled by the Reconnaissance General Bureau, North Korea’s primary intelligence organization.
The group has since become one of the most consequential actors in crypto cybercrime. It has been linked to major thefts, including the $625-million Ronin Network exploit in 2022, while US authorities have repeatedly targeted services allegedly used to move or obscure North Korean crypto proceeds.
That history turns the Hyperliquid transactions into more than a platform-specific compliance issue.
North Korean operators have repeatedly used the crypto ecosystem’s ability to move assets between wallets, tokens, protocols, and blockchains. Each additional step can complicate intervention, particularly when funds pass through infrastructure that does not require conventional customer accounts.
Washington considers the other side of Hyperliquid
While investigators followed Lazarus-linked money through the ecosystem, a very different conversation about Hyperliquid was developing in the US.
President Donald Trump said in August that Commodity Futures Trading Commission Chair Mike Selig was working on a pathway to bring Hyperliquid into the US market in a “fully compliant and legal manner.”
Kraken parent Payward is reportedly in advanced discussions with Hyperliquid Labs over a structure that could give eligible US traders access to a limited selection of Hyperliquid-linked perpetual futures.
Under the proposed arrangement, the products would be offered through Bitnomial, Payward’s CFTC-regulated derivatives exchange and clearing infrastructure, subject to regulatory approval.
A US pathway would not necessarily mean opening the permissionless Hyperliquid protocol directly to American traders under its existing model. Instead, a regulated intermediary could sit between US customers and markets connected to Hyperliquid.
Such a structure could preserve much of Hyperliquid’s open global infrastructure while placing identity verification, sanctions screening, surveillance, and other compliance requirements at the regulated US access point.
In effect, regulators may be considering whether a compliant gateway can be built around a market whose underlying infrastructure remains permissionless.
Where should compliance actually happen
If Hyperliquid-linked markets reach American land, the central question may not be whether the entire protocol can be made compliant.
It may be where compliance should sit.
One possibility is the protocol itself. Infrastructure could attempt to restrict addresses associated with sanctioned entities. But that approach raises difficult questions about who controls those restrictions and how quickly blockchain intelligence can identify prohibited addresses.
Another option is the interface layer, where websites and applications can restrict jurisdictions or wallets while the underlying smart contracts remain accessible independently.
A third model places the compliance burden on regulated intermediaries. A company such as Payward or a regulated venue such as Bitnomial may perform customer identification, sanctions screening, and transaction monitoring.
A regulated front door to a permissionless market
Hyperliquid has grown into one of crypto’s most important decentralized derivatives venues partly because it offers an alternative to conventional exchange infrastructure.
The same architecture becomes harder to reconcile with sanctions enforcement once regulators attempt to connect it to the US financial system.
The answer may ultimately be a two-layer market.
Hyperliquid’s underlying infrastructure could remain globally accessible, while American customers enter through a regulated gateway subject to identity checks, surveillance, and product restrictions. Such a model would resemble neither traditional DeFi nor a conventional centralized exchange.
But the Lazarus transactions expose the limitation before that experiment has even begun.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share
Most read articles



