More than $30 million tied to wallets associated with North Korea’s Lazarus Group passed through Hyperliquid’s HyperUnit service, according to blockchain analytics researcher Emmett Gallic of Arkham.
Gallic reported the activity on August 31 and said the transfers were still occurring shortly before his report.
The figure covers funds that moved through Hyperliquid, not the total amount leaving the wallet cluster. Just as importantly, the reported transactions do not establish that Hyperliquid was hacked or that customer funds were stolen from the platform.
$30 Million Through Hyperliquid, More Than $52 Million in Broader Outflows
Arkham’s findings place HyperUnit within a larger chain of transactions involving wallets previously associated with Lazarus Group.
According to reporting by The Crypto Times, four identified outflows from the cluster between July 30 and August 28 were worth more than $52 million at the valuations cited in the report.
That figure should not be added to the $30 million Hyperliquid figure as though they represent separate pools of money.
They measure different things.
- More than $30 million: Funds reportedly routed through HyperUnit
- More than $52 million: The combined value of four identified outflows from the broader wallet cluster
- Time period: The reported activity occurred across multiple transactions and dates
A single pool of cryptocurrency can move through several assets, networks and services, so counting each stage as separate money would inflate the total.
Bitcoin Went In. Other Assets Came Out.
The transaction trail reportedly began with Bitcoin entering Hyperliquid.
The assets were then converted into Ether and Solana, according to CoinDesk.
From there, the funds moved across several blockchain networks, including:
- Tron
- Solana
- Ethereum
The trail eventually reached centralised exchanges including KuCoin, LBank and Kraken, alongside other unidentified Tron-based destinations.
The pattern illustrates how cryptocurrency can be moved through multiple networks and converted between assets before reaching its eventual destination.
The Wallets Were Previously Linked to Lazarus
The Lazarus attribution itself is not new.
Blockchain investigator ZachXBT linked the relevant wallet cluster to Lazarus Group in 2024 and associated it with approximately $61 million in stolen cryptocurrency, according to an Arkham repost of that analysis.
The U.S. government has sanctioned Lazarus Group since 2019, identifying it as a North Korean state-sponsored cyber organisation controlled by the country’s Reconnaissance General Bureau.
U.S. authorities have accused the group of conducting cyberattacks and cryptocurrency theft to support North Korea’s illicit activities, including programmes connected to weapons development.
That sanctions history explains why the wallets are being described as Lazarus-linked.
But attribution and platform responsibility are separate questions.
What the Transactions Do—and Don’t—Show
The on-chain trail establishes that wallets associated with the reported cluster interacted with HyperUnit.
It does not, by itself, demonstrate that Hyperliquid was compromised.
Nor does it establish that Hyperliquid users lost money.
That distinction is important in analysing blockchain transactions. A decentralised or centralised service can appear somewhere in a transaction path without being the source of the funds or the victim of an exploit.
In this case, the available reporting points to asset conversion and cross-chain movement, rather than evidence that Hyperliquid itself was breached.
Hyperliquid Has Faced Similar Scrutiny Before
Hyperliquid has previously been mentioned in reports concerning alleged activity connected to North Korea.
In December 2024, the platform said separate reports circulating at the time did not indicate an exploit and that no user funds had been lost, according to The Block.
That earlier episode involved different activity.
The latest report instead centres on the movement of more than $30 million through HyperUnit and a wider group of transactions involving wallets that had previously been attributed to Lazarus.
The Bigger Issue Is the Money Trail
The latest findings highlight one of cryptocurrency’s defining features: transactions can be publicly traced even when the identities behind the wallets remain obscured.
For investigators, the challenge is following those funds as they move between assets, blockchains, bridges, exchanges and other services.
For platforms, the challenge is preventing sanctioned or illicit funds from passing through their infrastructure.
And for observers, the crucial distinction is simple:
Funds linked to Lazarus moving through a platform is not, on its own, evidence that the platform was attacked.
The available reporting shows a complex transaction trail.
It does not show a Hyperliquid exploit.