Crypto: Lazarus Sells More Than $30 Million in Bitcoin on Hyperliquid
Wallets linked to Lazarus sold more than $30 million in Bitcoin through Hyperliquid. North Korean hackers have stolen at least $6.75 billion.

More than $30 million worth of Bitcoin linked to the Lazarus Group was sold on Hyperliquid in just three weeks. The funds were then converted into Ethereum and Solana before moving to several centralized platforms. Behind these transactions is one of crypto’s most profitable hacking operations: hackers linked to North Korea have stolen at least $6.75 billion since their first documented campaigns.
Crypto: Lazarus Uses Hyperliquid
Wallets analyzed by Arkham sold more than $30 million worth of BTC on Hyperliquid over the past three weeks. Some had been identified as early as 2024 by investigator ZachXBT as being linked to the Lazarus Group.
This new activity extends the concerns already raised by Bref Crypto over North Korean thefts and their funding of the regime.
The path followed by the money also highlights the difficulty of tracking it. Bitcoin enters Hyperliquid and is then exchanged for ETH and SOL. The assets subsequently move to several networks and platforms, including Kraken, LBank and KuCoin.
CoinDesk notes, however, that it was unable to determine who controlled the recipient accounts on these exchanges or whether they had accepted the funds. Kraken says it uses monitoring tools capable of detecting assets associated with sanctioned addresses.
Pyongyang Has Already Stolen at Least $6.75 Billion
The $30 million represents only a fraction of the problem.
According to Chainalysis’ report, North Korean groups stole $2.02 billion in crypto in 2025 alone, bringing their minimum historical total to $6.75 billion.
The Bybit attack remains their most spectacular operation. In February 2025, approximately $1.5 billion disappeared from the exchange. The FBI officially attributed the theft to North Korean cyber actors involved in the activity it tracks under the name TraderTraitor.
Ronin Bridge had previously lost $620 million. DMM Bitcoin, $308 million. Harmony Horizon, $100 million.
The methods are evolving as well. Fake recruitment schemes, social engineering, developer compromise, the infiltration of IT workers and multichain laundering now make it possible to generate enormous gains with fewer attacks.
Bref Crypto recently reported that 70 hacks had already marked the second quarter of 2026. Lazarus, however, operates in a different category: behind the thefts is a state subject to international sanctions.
Hyperliquid Inherits an Explosive Problem
The timing is particularly bad for Hyperliquid.
The platform is seeking closer ties with the U.S. market. Kraken and Hyperliquid are reportedly discussing a way to offer certain perpetual contracts to U.S. investors within a regulated framework.
Hyperliquid, meanwhile, allows users to connect a wallet directly and conduct transactions without a traditional KYC process.
That is precisely what regulators are interested in.
Bref Crypto recently showed how a few microtransactions from sanctioned addresses were enough to block Kraken accounts. With Lazarus, the amounts this time run into the tens of millions of dollars.
Hyperliquid was not hacked, and nothing indicates that the protocol deliberately facilitated these transactions. Rather, the episode reveals the conflict inherent in permissionless finance: a blockchain can determine that a transaction is valid without asking whether its owner appears on a sanctions list.
For Hyperliquid, this technical distinction could now become a political problem. The more the platform seeks to enter regulated U.S. finance, the harder it will be to view Lazarus’ $30 million as merely another on-chain activity.


