North Korean Hackers Exploit Hyperliquid's Permissionless Design for $30 Million
North Korean state-sponsored hackers have moved over $30 million through the decentralized platform Hyperliquid in recent weeks, according to blockchain data reviewed by analytics firm Arkham. The Lazarus Group's activity on the platform was first reported by CoinDesk.
The funds were converted from Bitcoin into Ether and Solana before being transferred to centralized exchanges such as Kraken, LBank, and KuCoin. This is not the first time North Korea-linked wallets have appeared on Hyperliquid, with similar activity reported in December 2024.
Hyperliquid's permissionless design allows users to trade perpetual futures without identity verification requirements, creating a 'screening gap' that sanctioned actors can exploit.
The platform's growth has been significant, with over $5 trillion in cumulative perpetual futures volume and open interest currently around $13.3 billion. However, its entry into the US market is complicated by regulatory concerns, including derivatives exchange regulations and sanctions evasion risks.