Wallets linked to the notorious North Korean state-sponsored hacking group, Lazarus Group, have reportedly moved in excess of $30 million through the decentralized perpetual exchange Hyperliquid. This revelation, brought to light by blockchain researcher Emmett Gallic, places the illicit financial activity in direct juxtaposition with Hyperliquid’s ongoing efforts to secure a regulated pathway into American markets, a move supported by U.S. policymakers and major crypto entities like Kraken’s parent company, Payward. The funds were routed through Hyperliquid’s HyperUnit service, with activity documented as recently as August 31, underscoring the persistent challenge of combating illicit finance within the rapidly evolving decentralized finance (DeFi) landscape.
Deep Dive into Sanctioned Wallet Activity on Hyperliquid
Emmett Gallic’s investigation specifically identified a cluster of wallets as belonging to the Lazarus Group, an entity officially sanctioned by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) due to its role in financing North Korea’s weapons programs through cybercrime. The modus operandi observed involved the funneling of Bitcoin into Hyperliquid, where it was subsequently converted into other major cryptocurrencies, primarily Ethereum (ETH) and Solana (SOL). Following these conversions, the assets were then strategically bridged across multiple blockchain networks, including Tron, Solana, and Ethereum, a common tactic employed by illicit actors to obfuscate transaction trails and complicate tracing efforts.
This recent activity gains additional gravity from previous intelligence. The same wallet cluster was notably flagged earlier in 2024 by prominent blockchain sleuth ZachXBT, who at that time linked these addresses to a staggering $61 million in stolen funds. The continuity of observation across different researchers and timeframes reinforces the attribution to the Lazarus Group and highlights their sustained use of various platforms to launder stolen assets. The repeated identification of these wallets by independent researchers underscores the persistent efforts within the blockchain intelligence community to track and expose illicit financial flows, even as sophisticated hacking groups attempt to evade detection.
From Hyperliquid, the converted assets did not remain static but were further distributed to a variety of centralized exchanges (CEXs) and other services. Recipients included well-known platforms such as KuCoin, LBank, and even Kraken, alongside an unspecified number of Tron-based services that often provide less stringent "know your customer" (KYC) protocols, making them attractive conduits for money laundering. The strategy of dispersing funds across numerous platforms is a classic technique designed to break the chain of custody, dilute the volume of funds at any single point, and ultimately make it significantly harder for law enforcement agencies to freeze or recover the illicit proceeds. Gallic disseminated his findings via the social media platform X, explicitly referencing ZachXBT’s 2024 identification as the foundational basis for attributing the wallets to the Lazarus Group, thereby providing a robust evidentiary chain for his claims.
The Broader Context: North Korea’s Cyber Warfare and Financial Imperative
The Lazarus Group is not merely a criminal enterprise; it is a sophisticated state-sponsored hacking collective operating under the direct purview of North Korea’s Reconnaissance General Bureau. Its primary objective is to generate revenue for the DPRK regime, specifically to circumvent international sanctions and fund its illicit nuclear weapons and ballistic missile programs. Over the past decade, the group has been implicated in some of the largest cryptocurrency heists in history. Notable incidents include the 2017 WannaCry ransomware attack, the $625 million Ronin Bridge hack in March 2022, and the $100 million Harmony Horizon bridge exploit in June 2022. The total estimated value of cryptocurrency stolen by the Lazarus Group runs into billions of dollars, making it one of the most prolific cybercrime entities globally.
The use of DeFi platforms like Hyperliquid by the Lazarus Group underscores a critical challenge for global financial security. While decentralized exchanges offer innovative financial services, their pseudonymous nature and often less stringent onboarding requirements, compared to regulated centralized exchanges, can inadvertently create vulnerabilities exploited by bad actors. North Korea’s reliance on these illicit financial gains has intensified as international sanctions tighten, making cyber theft a cornerstone of its economic strategy. The continuous adaptation of their methods, from traditional bank hacks to sophisticated crypto exploits and subsequent laundering techniques, highlights the dynamic cat-and-mouse game between state-sponsored cybercriminals and international law enforcement.
Simultaneous Pursuit of Regulated U.S. Market Entry
The timing of Gallic’s disclosure is particularly salient, as it coincides with Hyperliquid’s active pursuit of formal access to the highly regulated U.S. financial markets. In August, President Donald Trump publicly indicated that Commodity Futures Trading Commission (CFTC) Chairman Mike Selig was actively working on developing a compliant pathway for Hyperliquid to operate within the United States. This announcement signaled direct federal engagement with the platform’s prospects, hinting at a potentially landmark development for decentralized finance in America. The U.S. government, through its various agencies, has been grappling with how to integrate DeFi innovation while ensuring robust consumer protection and combating illicit finance.
Adding another layer to this complex narrative, Kraken’s parent company, Payward, is reportedly in advanced discussions with Hyperliquid Labs. These talks are centered on a groundbreaking proposal: allowing U.S. users to trade a carefully curated subset of Hyperliquid-linked perpetual futures. The structure envisioned would leverage the regulatory expertise and infrastructure of Bitnomial, a regulated exchange and clearinghouse, which would support the entire framework, subject to stringent regulatory approval from relevant U.S. authorities. This potential partnership signifies a significant step towards bridging the gap between decentralized protocols and traditional financial regulation, offering a potential model for how DeFi products could be brought to a broader, regulated market.

Market reaction to the news of Hyperliquid’s potential U.S. entry was swift and positive. Coin Bureau reported a nearly 50% surge in the value of HYPE, Hyperliquid’s native token, which climbed from approximately $57 to $84 following the news of the U.S. talks. The account cited a Bloomberg report detailing Payward’s involvement, emphasizing that Kraken, which holds CFTC licensing, could be instrumental in bringing on-chain perpetual futures to American traders for the first time. This would represent a significant milestone, opening up a new asset class to a regulated investor base within the U.S. market.
Further evidence of these strategic moves emerged approximately two weeks prior to the public announcements, when a "Kraken HIP-3 test DEX" was reportedly spotted on Hyperliquid’s testnet. This test deployment was observed to include specific permission controls, suggesting an intentional design to support U.S. compliance needs and regulatory requirements. Such features would be crucial for segregating U.S. users, implementing KYC/AML procedures, and adhering to specific trading restrictions mandated by U.S. law. Following the Bloomberg report on these advanced talks, Coin Bureau noted an additional 5% gain for the HYPE token, reflecting continued investor optimism about Hyperliquid’s regulatory prospects.
Regulatory Scrutiny and Compliance Challenges
The revelation of Lazarus Group’s activity on Hyperliquid injects a significant layer of complexity and scrutiny into the platform’s U.S. market entry ambitions. U.S. regulators, particularly the CFTC, SEC, and OFAC, are increasingly focused on preventing illicit finance and ensuring market integrity within the cryptocurrency space. The presence of sanctioned entities utilizing a platform directly undermines efforts to portray it as compliant and secure. For the CFTC, which regulates derivatives markets, ensuring that any perpetual futures offerings are free from money laundering and terrorist financing risks is paramount. The agency’s commitment to consumer protection and market stability would necessitate a thorough review of Hyperliquid’s anti-money laundering (AML) and counter-terrorist financing (CTF) protocols.
The U.S. Treasury’s OFAC, specifically tasked with enforcing sanctions, would view the reported Lazarus Group activity with extreme concern. Any platform facilitating transactions for sanctioned entities, even inadvertently, risks secondary sanctions or enforcement actions. While Hyperliquid is a decentralized platform, the involvement of its HyperUnit service and the subsequent movement of funds to centralized exchanges (some of which are regulated) creates identifiable touchpoints for regulatory intervention. The challenge for Hyperliquid and its potential partners like Kraken/Payward will be to demonstrate robust, verifiable, and effective mechanisms to prevent, detect, and report illicit financial activity, particularly from state-sponsored actors.
Implications for Kraken, Bitnomial, and the Broader DeFi Landscape
For Kraken and Payward, the news of Lazarus Group activity on Hyperliquid presents a significant due diligence hurdle. As a CFTC-licensed entity, Kraken operates under strict regulatory obligations. Any partnership or integration with Hyperliquid would require an exhaustive assessment of Hyperliquid’s security, compliance frameworks, and historical transaction data. The reputational risk alone could be substantial if U.S. regulators perceive that a Kraken-backed initiative could inadvertently become a conduit for sanctioned funds. Their ability to ensure a clean and compliant environment for U.S. users will be critical for regulatory approval.
Bitnomial, as a regulated exchange and clearinghouse, also faces heightened scrutiny. Its role in supporting the proposed structure would demand ironclad assurances that all transactions meet U.S. regulatory standards, including robust AML/CTF controls, trade surveillance, and risk management. The challenge lies in integrating a decentralized protocol, which inherently operates with a degree of permissionlessness, into a highly centralized and regulated financial ecosystem. This incident underscores the urgent need for innovative compliance solutions that can operate effectively within DeFi environments without stifling innovation.
More broadly, this situation highlights the persistent tension between the ethos of decentralization and the imperative for regulatory oversight. While DeFi champions transparency through public ledgers, the pseudonymous nature of wallets and the complexity of cross-chain transactions can be exploited. This incident will likely intensify calls from regulators for greater accountability and more proactive measures from DeFi platforms to combat illicit finance. It serves as a stark reminder that as the crypto industry matures and seeks mainstream adoption, it must unequivocally demonstrate its commitment to operating within legal and ethical boundaries, particularly when it comes to preventing state-sponsored criminal enterprises from exploiting its infrastructure.
Expert Commentary and Future Outlook
Blockchain security experts and financial crime analysts often emphasize that the cat-and-mouse game with sophisticated hacking groups like Lazarus is perpetual. "These groups constantly evolve their tactics, leveraging new platforms and services as they emerge," noted a cybersecurity analyst, who preferred to remain anonymous given the sensitive nature of the topic. "For DeFi platforms seeking mainstream legitimacy, proactive collaboration with blockchain intelligence firms and a robust, adaptive compliance framework are no longer optional, they are existential necessities."
The path forward for Hyperliquid’s U.S. market entry is now undeniably more challenging. While the discussions with CFTC Chairman Selig and Payward indicate a willingness from both the industry and some regulatory bodies to find a compliant solution, the reported Lazarus Group activity will undoubtedly lead to a more stringent and protracted review process. Regulators will demand concrete evidence of effective controls, and the burden of proof will fall heavily on Hyperliquid and its partners to demonstrate that they can effectively wall off illicit actors while serving legitimate users. The outcome of this situation will not only shape Hyperliquid’s future but could also set a precedent for how other decentralized platforms navigate the complex landscape of global financial regulation, balancing innovation with the critical need for security and integrity.















