Blockchain analysts have discovered that wallets linked to the North Korean hacker group Lazarus have moved over $30 million in Bitcoin through Hyperliquid over the past three weeks. This activity surfaces at a critical moment as the platform prepares for regulatory approval and a potential entry into the U.S. market.
The traces of these operations were tracked thanks to attribution previously published by renowned on-chain researcher ZachXBT. According to my analysis, the funds were first converted into Ethereum (ETH) and Solana (SOL), then distributed through centralized exchanges such as Kraken, LBank, and KuCoin. This is a classic money laundering scheme that Lazarus uses to bypass sanctions restrictions.
Political context and pressure on regulators
The situation becomes particularly acute against the backdrop of a recent mention of Hyperliquid by U.S. President Donald Trump. At a White House event, he stated that Commodity Futures Trading Commission (CFTC) Chairman Michael Selig is actively working to ensure the platform "comes to the U.S. in a lawful and fully compliant manner." This statement underscores the high level of political attention on the project.
However, such Lazarus activity calls into question Hyperliquid's readiness for rigorous scrutiny. At the time of writing this analysis, the HYPE token is trading around $84, showing a 5% increase over the day. Notably, the price reached an all-time high of $86.71 before the data on suspicious transactions was published, suggesting that the market has not yet priced sanctions risks into the asset's value.
The CFTC, under Selig's leadership, has already approved a perpetual Bitcoin contract on one regulated exchange this year. This precedent could serve as a benchmark for Hyperliquid, but now the regulator will be forced to also account for risks associated with North Korean hackers.
Scale of the threat and regulatory pressure
It is worth recalling that OFAC imposed sanctions on the Lazarus Group back in 2019. The group is responsible for the Ronin Network hack in 2022, as well as the record-breaking $1.5 billion theft from Bybit in 2025. In the first half of 2025, North Korean hackers stole approximately $1.6 billion in cryptocurrency—this accounts for about 70% of all industry losses during that period.
This data surfaced precisely during Hyperliquid's negotiations with Payward regarding entry into the U.S. market through its subsidiary Bitnomial. In May, the organization closed a deal to acquire Bitnomial for $550 million, immediately obtaining three CFTC licenses. Now that the platform is on the verge of legalization, each such incident becomes not just a technical issue, but a serious reputational and regulatory challenge.
My conclusion: The market's disregard for these signals is a temporary phenomenon. If the CFTC perceives Lazarus activity as a sign of insufficient oversight, the timeline for Hyperliquid's entry into the U.S. market could be significantly delayed. Traders should closely monitor regulatory statements in the coming weeks.