- Crypto wallets linked to North Korea’s Lazarus Group moved approximately $30 million in digital assets through Hyperliquid and HyperUnit.
- The funds were converted into assets including ETH and SOL before being bridged across Ethereum, Solana and Tron.
- Some of the assets eventually reached exchanges including KuCoin, Kraken and LBank, along with several unidentified Tron-based services.
Crypto wallets linked to North Korea’s state-affiliated Lazarus Group have moved approximately $30 million in digital assets through decentralized trading platform Hyperliquid.
According to blockchain data shared by Arkham analyst Emmett Gallic, Lazarus-tagged wallets transferred funds through Hyperliquid and HyperUnit using Bitcoin before converting portions into Ether or Solana.

The assets were then bridged across multiple blockchain networks, including Ethereum, Solana and Tron.
The activity highlights how sophisticated threat actors continue using decentralized exchanges, bridges and multiple blockchains to move crypto across the ecosystem.
Funds Eventually Reached Crypto Exchanges
After moving through several networks, portions of the funds were deposited into centralized cryptocurrency exchanges.
The destinations included KuCoin, Kraken and LBank, according to the blockchain analysis.
Other funds were transferred to several unidentified services operating on the Tron network.
Moving assets between different cryptocurrencies, networks and platforms can make transaction flows more complex to follow, although blockchain analytics firms can still track much of the activity through public transaction data.
Hyperliquid Faces Growing U.S. Attention
The transfers come as Hyperliquid receives increased attention from U.S. policymakers and regulators.
Weeks earlier, President Donald Trump said CFTC Chair Michael Selig was working on a regulatory pathway that could bring Hyperliquid into the U.S. market.
Hyperliquid has become one of the most prominent decentralized trading platforms, particularly for perpetual futures and other onchain markets.

The Lazarus-linked activity does not itself indicate involvement by Hyperliquid in the movement of illicit funds, but it highlights the compliance challenges facing decentralized financial infrastructure as institutional and regulatory attention grows.
Lazarus Remains a Major Crypto Security Threat
The Lazarus Group has been linked to some of the largest cryptocurrency thefts in the industry’s history.
The group remains the primary suspect behind the $1.4 billion Bybit hack in 2025, currently the largest known crypto theft.
North Korea-linked threat actors were also connected to at least $578 million of the $634 million stolen through crypto-related incidents in April.
The latest movements show that tracking stolen or potentially illicit crypto does not end with the original exploit. Investigators increasingly have to follow assets across exchanges, bridges, decentralized protocols and multiple blockchain networks as threat actors attempt to move and convert their holdings.











