
Lazarus Group Funds Exploit Decentralized Exchange Hyperliquid: $30M Moved
Vexoda Newsroom
Wallet addresses associated with the Lazarus Group have moved approximately $30 million in cryptocurrency through the decentralized exchange Hyperliquid. The transactions occurred amidst regulatory di
Addresses linked to the notorious Lazarus Group, a state-affiliated hacking collective, have recently been observed moving a significant volume of digital assets, totaling around $30 million, through the decentralized exchange (DEX) known as Hyperliquid. This activity raises concerns within the cryptocurrency community, particularly given the group's history of sophisticated cyberattacks and illicit financial operations. The movement of these funds through a decentralized platform highlights the ongoing challenges in tracking and preventing the flow of illicit cryptocurrency.
The specific details of the transactions reveal a multi-step process initiated by Lazarus-linked wallets. These wallets first deposited funds, primarily Bitcoin (BTC), onto the Hyperliquid platform. The assets were then reportedly converted into other cryptocurrencies such as Ether (ETH) or Solana (SOL) within the Hyperliquid ecosystem. Subsequently, these converted digital assets were bridged out to other networks, including Tron (TRX), Solana, and the Ethereum network, indicating a deliberate effort to obscure the trail.
Following the outbound transfers from Hyperliquid, the funds were directed towards several known cryptocurrency exchanges, including KuCoin, Kraken, and Lbank. Additionally, some of the assets found their way to various unlabelled services operating on the Tron network. This final leg of the journey suggests an attempt to liquidate or further obfuscate the origin and ultimate destination of the $30 million moved, a common tactic employed by illicit actors to launder cryptocurrency.
This financial activity by the Lazarus Group is particularly noteworthy as it occurred mere weeks after reports indicated that US regulators, specifically the Commodity Futures Trading Commission (CFTC) Chair Michael Selig, were exploring a regulatory pathway for Hyperliquid to potentially enter the US market. The timing could be coincidental, but it places Hyperliquid under increased scrutiny, especially concerning its security protocols and the oversight of assets transacting on its platform.
The Lazarus Group is a well-documented entity, widely suspected by international authorities to be responsible for some of the largest cryptocurrency hacks in history. Notable incidents attributed to the group include the massive $1.4 billion hack of the Bybit exchange in 2025, and substantial involvement in other large-scale thefts, underscoring their capability and persistent threat to the digital asset ecosystem. Their involvement in moving such a large sum through a DEX further emphasizes their adaptation to evolving financial technologies.
For traders and market participants, this event underscores the inherent risks associated with decentralized finance (DeFi) platforms and the persistent challenges of combating illicit actors in the crypto space. While DEXs offer benefits like user control and censorship resistance, they also present potential avenues for obfuscation if not adequately secured or monitored. The market reaction to such news can be varied, but increased scrutiny on DeFi protocols and security measures is a likely outcome.
Moving forward, traders should closely monitor any official statements or actions from regulatory bodies regarding Hyperliquid and other DEXs. Additionally, observing the blockchain analytics firms' continued tracking of these Lazarus-linked wallets will be crucial in understanding whether further funds are moved or if authorities successfully intervene. Developments in cross-chain security and enhanced transaction monitoring on decentralized platforms will also be key areas to watch for their impact on future security.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.