North Korean hackers route tens of millions through Hyperliquid
Regulation & Gov ·
US officials are reportedly weighing whether to bring the derivatives platform under domestic oversight even as DPRK-linked funds keep flowing through it.
Tens of millions of dollars tied to North Korean hacking operations have moved through Hyperliquid, according to Coindesk, which reported that US officials are simultaneously considering steps to bring the platform onshore. A related account puts a sharper figure on part of that activity, noting that over $30 million in Bitcoin moved through Hyperliquid's derivatives venue within a three-week span.
The overlap between illicit flows and regulatory interest is notable. Hyperliquid operates as a decentralized derivatives platform, and its use by North Korean-linked actors comes as the same wallets and laundering networks have been documented moving through a much wider set of crypto infrastructure. Analysts tracking the broader Lazarus Group ecosystem say DPRK-linked actors have stolen more than $6 billion in crypto since 2017, with North Korea driving roughly 70% of exploits recorded in 2026, underscoring that Hyperliquid is only one node in a much larger laundering apparatus rather than an isolated target.
That apparatus has recently touched DeFi teams directly rather than just exchange rails. Researchers found North Korean developers embedded in more than 40 DeFi teams, including one case in which operatives spent six months inside Drift before a $285 million heist. Separately, the Solana DEX Stabble urged liquidity providers to withdraw funds after identifying a former employee with North Korean ties, and Consensys confirmed a North Korea-linked contractor had accessed MetaMask code for one month, though it found no evidence of stolen assets or data. On the workforce-infiltration side, two New Jersey men were sentenced to 9 and 7.5 years for running laptop farms that placed North Korean IT workers inside more than 100 US companies.
Taken together, these cases point to a pattern in which North Korean operatives pursue parallel tracks: direct exploits of protocols, infiltration of development teams, and use of liquid derivatives venues like Hyperliquid to move proceeds. What remains unclear is the precise mechanism by which the tens of millions cited in the Hyperliquid case were laundered, how much of that sum has since been traced or frozen, and what form onshoring discussions among US officials might take. Also unresolved is whether increased oversight of platforms like Hyperliquid would meaningfully disrupt DPRK laundering given the scale of infiltration already documented across DeFi and traditional tech employment channels.