North Korean Hackers Move Millions: Crypto Platform at Risk
The Lazarus Group, North Korea's state-sponsored hacking apparatus responsible for billions in crypto theft since 2016, has been using Hyperliquid as a liquidation channel.
Lazarus Group wallets sold more than $30 million in bitcoin on Hyperliquid in three weeks, according to blockchain data reviewed by CoinDesk — and the timing could not be worse for a platform that Donald Trump is actively pushing to bring onshore into the US financial system.
The Lazarus Group, North Korea's state-sponsored hacking apparatus responsible for billions in crypto theft since 2016, has been using Hyperliquid as a liquidation channel. The wallets don't hide. They move at scale, they move fast, and they move with the confidence of actors who have calculated that the compliance architecture isn't ready for them.
That calculation may be correct. Hyperliquid has been positioning itself as a legitimate decentralised exchange at exactly the moment Washington is deciding which crypto platforms get to operate inside the regulated perimeter. Trump's push to onshore the platform creates a political paradox: you cannot simultaneously court presidential favour and provide exit liquidity for sanctioned state actors without someone eventually forcing you to choose.
The OFAC exposure here is not theoretical. Any US platform — or platform seeking US legitimacy — that processes transactions traceable to Lazarus Group wallets faces sanctions liability that no amount of decentralisation architecture eliminates. The blockchain doesn't lie, and regulators can read it as well as CoinDesk can.
Hyperliquid has not publicly responded to the findings.
Your move: If you hold assets on any DEX currently seeking US regulatory approval, search its name alongside "OFAC" and "Lazarus" before the regulators do it for you.