Lazarus Group Launders Stolen Crypto via Hyperliquid

We may earn commissions from affiliate links or include sponsored content, clearly labeled as such. These partnerships do not influence our editorial independence or the accuracy of our reporting. By continuing to use the site you agree to our terms and conditions and privacy policy.

Article Details

US-sanctioned Lazarus Group moves millions in stolen BTC through Hyperliquid and HyperUnit, converting assets to Ethereum and Solana before off-ramping.

Recent on-chain movements have been traced back to addresses that Arkham links to the Lazarus Group, a US-sanctioned hacking entity associated with North Korea.

According to data published by Emmett Gallic on August 31, this activity spanned approximately three weeks. The identified wallets transferred BTC to Hyperliquid and the HyperUnit infrastructure, where the Bitcoin was subsequently swapped for Ethereum or Solana.

After conversion, the funds were bridged across various blockchains. The tracked routes included Ethereum, Solana, and Tron before the assets reached addresses on centralized trading platforms.

Final destinations identified through on-chain analysis include Kraken, KuCoin, and LBank, along with several unidentified services operating on the Tron network.

Complex Routes Complicate Asset Tracking

Moving from BTC to other assets and subsequently transferring them across multiple networks highlights the complexity of fund routing used by sanctioned entities. In this instance, HyperUnit facilitates the transfer of assets like BTC, ETH, and SOL into the Hyperliquid ecosystem via 1:1 representations. This mechanism allows capital to shift from Bitcoin into other liquid assets before being moved out to different blockchains.

It is crucial to distinguish between the use of a protocol and the compromise of a protocol. Available data does not suggest that Hyperliquid was hacked or that user funds were stolen from the platform. Instead, the infrastructure was used as a conduit for assets originating from addresses identified by analysts as linked to Lazarus.

Lazarus Behind the Largest Crypto Theft, FBI Confirms

These new transactions are drawing scrutiny due to the group’s history. Lazarus has been linked to several of the largest digital asset thefts, though the most significant case remains the attack on Bybit in February 2025.

A major correction to earlier reports has been made: responsibility for the attack is no longer merely a suspicion. The FBI has officially attributed the theft of approximately $1.5 billion in virtual assets from Bybit to North Korea, identifying this specific activity under the name “TraderTraitor.”

Following the breach, the FBI warned that the stolen assets were being converted into Bitcoin and other cryptocurrencies, then distributed across thousands of addresses on various blockchains with the eventual goal of being laundered into fiat currency.

Hyperliquid Faces Renewed Regulatory Scrutiny

The timing of these findings is sensitive for Hyperliquid. The platform is currently pursuing a deeper connection with the regulated US market as authorities explore ways for some of its products to reach American investors while complying with local rules.

This situation brings the issue of controlling sanctioned funds to the forefront of the debate surrounding decentralized financial infrastructure. While public blockchains make capital movement visible and allow for tracking, the use of asset swaps, bridges, and multi-network transfers can significantly complicate the work of exchanges and regulators.

For Hyperliquid, the case does not indicate a technical breach, but it arrives at a moment when future access to regulated markets places a sharper focus on sanctions compliance and the origin of funds.

Leave Reaction
Share Article
Nikolay is a cryptocurrency analyst and market writer with years of experience tracking digital asset trends and emerging blockchain technologies. A long-time crypto enthusiast, he actively trades across major exchanges and specializes in identifying early-stage projects and meme tokens. His analysis combines technical insight with a strategic, long-term investment perspective.
comment-icon Commentaries
Add your comment

Fill in necessary fields and publish