Crypto wallet addresses linked to the North Korean cyber syndicate Lazarus Group moved $30 million in assets through the decentralized exchange Hyperliquid on September 1, 2026. The organization remains under sanctions by the US Office of Foreign Assets Control.
On-chain transaction data showed that the identified wallets routed initial deposits in Bitcoin to Hyperliquid and the bridging platform HyperUnit. The operators subsequently traded the assets into Ether and Solana within the protocol ecosystem.
Following the conversion, the funds were bridged across the Tron, Solana, and Ethereum blockchains. This multi-chain routing was designed to split the transaction volume and obscure transaction histories across separate distributed networks.
The layered transfers fragmented the capital into smaller allocations. By moving assets through different decentralized bridging protocols, the operators altered the initial digital footprint before routing the funds to custodial exchange endpoints.
Transfer paths to centralized exchanges and unlabeled destinations
Addresses linked to OFAC Sanctioned Lazarus Group (North Korea) have been actively moving $30M+ through Hyperliquid (HyperUnit) as recent as yesterday.@zachxbt identified these addresses as Lazarus Group in 2024 linked to $61M in stolen fundshttps://t.co/RNJ4NMBrxA pic.twitter.com/CvivPLVnEL
— Emmett Gallic (@emmettgallic) August 31, 2026
According to on-chain tracking shared in a post by analyst Emmett Gallic on X, the swapped tokens were ultimately deposited into accounts at centralized exchanges KuCoin, Kraken, and LBank.
The analysis also identified transfers directed to several unlabeled services on Tron network. These intermediary deposit points received portions of the bridged capital following the automated token swaps executed on Hyperliquid.
Hyperliquid functions as a decentralized order-book exchange operating on its dedicated layer-1 blockchain. The protocol allows users to execute perpetual swaps and spot trades directly through self-custodial smart contracts without mandatory identification requirements.
The exploiters utilized the platform’s order-book liquidity to convert large quantities of Bitcoin into tokens supported across various cross-chain bridges, streamlining the relocation of assets toward secondary withdrawal accounts.
Regulatory developments in the United States and criminal record
The transactions occurred weeks after US President Donald Trump stated during an August 16, 2026 White House event that CFTC Chair Michael Selig was developing a regulatory pathway for Hyperliquid within domestic financial markets.
That initiative aims to establish formal compliance frameworks for decentralized derivatives platforms. However, the movement of sanctioned funds illustrates technical challenges facing regulatory models designed to supervise non-custodial decentralized finance protocols.
Lazarus Group remains the primary suspect in the $1.4 billion Bybit hack in 2025, which stands as the largest recorded security breach in the history of the digital asset industry.
Additionally, North Korea-affiliated cyber actors were tied to $578 million of the $634 million stolen across all cryptocurrency-related security exploits recorded in April 2026.
The routing techniques mirror patterns documented in FBI tracking of Lazarus funds, where illicit operators used sequential token conversions and cross-network bridges to evade asset freezes by centralized compliance teams.
Blockchain analytics firms continue tracking the recipient deposit addresses at KuCoin, Kraken, and LBank to determine whether the transferred funds have been frozen by exchange compliance departments.
Representatives for Hyperliquid and the recipient exchanges have not released public statements regarding specific account freezes or asset recovery efforts tied to the incident.
This article is for informational purposes only and does not constitute financial advice.

