More than $30 million moved through Hyperliquid’s HyperUnit service from addresses linked to the OFAC-sanctioned Lazarus Group, according to an August 31 report by Arkham researcher Emmett Gallic.
Gallic said the activity continued through the day before his report. The reported figure is limited to funds routed through Hyperliquid and does not represent the full value of the identified wallet cluster’s outflows.
Available reporting does not establish that Hyperliquid itself was exploited.
Arkham tracks more than $30M through HyperUnit
Arkham’s reported finding puts a specific platform in the path of funds tied to the North Korean hacking group. HyperUnit was one stage in a sequence of conversions and cross-chain transfers, based on the transaction trail described in subsequent reporting.
The Crypto Times reported that four Lazarus Group outflows identified in Arkham-linked transaction data took place between July 30 and August 28 and totalled more than $52 million at the reported valuations. That total should not be treated as a second estimate of the Hyperliquid flows; the $30 million figure is the amount reported as routed through Hyperliquid during the period.
The distinction matters because onchain movement can involve several transactions, assets and networks before funds arrive at a final service. A platform appearing in that route does not, on its own, show a loss by users or a compromise of the platform.
Bitcoin-to-altcoin conversions and cross-chain exits
The funds reportedly entered Hyperliquid as Bitcoin before being converted into Ether and Solana. They were then bridged across the Tron, Solana and Ethereum networks, according to CoinDesk.
From there, transfers were sent to exchanges including KuCoin, LBank and Kraken, as well as unidentified services on Tron. The reported route shows the use of asset conversion and multiple chains before transfers reached centralised venues and other destinations.
Neither the reported $30 million routed through Hyperliquid nor the more than $52 million in identified outflows describes a single transfer. They are separate measurements of activity in the reported cluster and timeframe, with the former limited to the Hyperliquid leg.
The wallet cluster’s prior Lazarus attribution
The attribution underlying the new report was not presented as a new identification of the wallets. Blockchain investigator ZachXBT had linked the relevant wallet cluster to Lazarus Group in 2024 and associated it with approximately $61 million in stolen funds, according to an Arkham repost of the attribution.
Lazarus Group has long been subject to U.S. sanctions. The Treasury Department designated it in September 2019 as a North Korean state-sponsored malicious cyber group, saying it was controlled by North Korea’s Reconnaissance General Bureau and had carried out cyber theft and attacks in support of illicit weapons programmes.
That designation provides the sanctions context for Arkham’s description of the addresses as Lazarus-linked. It does not change the narrower onchain question in this case: which wallets moved funds, through which services and networks, and in what amounts.
Hyperliquid’s earlier response to DPRK-linked activity
Hyperliquid has previously faced scrutiny over alleged DPRK-linked activity. In December 2024, the platform said reports at that time did not reflect an exploit and that no user funds had been lost, according to The Block.
That earlier statement concerned separate reports from 2024. Arkham’s August 31 account instead concerns the reported routing of more than $30 million through HyperUnit, while the broader set of four identified outflows was valued at more than $52 million.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.