AiCoin中文
AiCoin中文|Sep 02, 2026 02:35
Hyperliquid has not officially entered the United States yet, and North Korean hackers have completed a compliance stress test for it first? Recently, ZachXBT discovered addresses related to the North Korean hacker group Lazarus, which had transferred over $30 million in funds to HyperUnit and completed asset conversions in Hyperliquid related links The news quickly sparked controversy: Is Hyperliquid becoming a new channel for hackers to transfer funds? But before discussing, it is necessary to separate the confirmed facts from the on chain speculation In 2024, ZachXBT released a batch of Bitcoin addresses related to the past 25 Lazarus attacks. These attacks involved approximately $200 million in stolen funds, some of which were subsequently frozen The latest on chain tracking shows that multiple addresses in this batch of marked addresses have recently resumed activity and transferred Bitcoin to HyperUnit related channels According to public records, some of the larger transfers include: On July 30th, approximately 121.5 BTC worth around 7.74 million US dollars were transferred On August 6th, approximately 136.3 BTC worth around 8.83 million US dollars were transferred On August 13th, approximately 262.2 BTC worth approximately $16.63 million were transferred On August 28th, approximately 244.1 BTC worth approximately 19.42 million US dollars were transferred These numbers are transfer records that occurred at different times and cannot be directly added together to be understood as independent new funds, as they may contain repeated movements of the same batch of assets But what has been confirmed on the chain is that at least one address cluster that brought in over $30 million in inflows can be traced back to Lazarus related Bitcoin addresses previously marked by ZachXBT In addition, ZachXBT also discovered another cluster with a scale of approximately $5 million, whose sleep cycle, address type, and counterparty behavior are very similar to the confirmed Lazarus wallet So, where did the money go after passing through HyperUnit? From the on chain path, funds enter HyperUnit related channels in BTC, which are then converted into assets such as ETH and SOL, and then transferred to Ethereum, Solana, and Tron through cross chain bridges Part of the assets ultimately flowed into Kraken, KuCoin, LBank, and several unmarked Tron service addresses Simply put, it is: BTC enters → converts into assets that are easier to flow across chains → disperses across multiple chains → and then flows to different trading platforms and service addresses This is a typical cross asset and cross chain fund transfer path, but it cannot prove that every step alone belongs to money laundering, nor can it prove that the platform along the way knows the true source of the funds We also need to distinguish between HyperUnit and HyperCore here The main function of HyperUnit is to bring external assets such as BTC, ETH, SOL into the Hyperliquid ecosystem, and complete recharge, withdrawal, and asset conversion The funds passing through HyperUnit does not necessarily mean that these addresses have been traded in perpetual contracts in the HyperCore order book The current public evidence mainly proves that funds flow through HyperUnit related links, and cannot be directly written as' Lazarus traded $30 million on Hyperliquid ', let alone' Hyperliquid helped North Korean hackers launder money ' Similarly, there is currently no evidence to suggest that the Hyperliquid protocol has been attacked, or that the team knowingly provided assistance despite knowing that the funds came from sanctioned organizations What is truly worth considering is why this happened at a critical stage when Hyperliquid was preparing to enter the United States In the past period, the US mainline of Hyperliquid has been rapidly advancing Trump publicly stated that he hopes Hyperliquid can enter the United States in a fully compliant and legal manner. The Hyperliquid Policy Center continues to submit opinion letters to the SEC and CFTC, discussing on chain trading, stock perpetuity, and regulatory classification. The testnet has added address whitelist and account control functions Recently, it has been revealed that Hyperliquid is in deep negotiations with Kraken's parent company Payward, hoping to provide some encrypted perpetual contracts to US users through the regulated Bitnominal exchange and clearing system The Lazarus related funding incident has brought to the forefront the most concerning issue for US regulators: how can a permissionless global agreement prevent sanctioned funds from entering? On chain transparency solves the problem of "seeing after the fact", leaving public records of all transfers, addresses, asset conversions, and cross chain paths. Researchers can restore the complete process along the flow of funds. Compared with anonymous accounts in traditional finance, this traceability is actually an advantage of on chain systems But what US regulators require is not just post tracking, but 'pre emptive prevention' Regulatory agencies need to complete identity verification, sanction list screening, and funding source review before funds enter; After discovering high-risk addresses, it is necessary to be able to refuse transactions, freeze accounts, restrict withdrawals, and submit suspicious activity reports That's also why the US version of Hyperliquid is unlikely to completely replicate the current global version. A more realistic structure is that HyperCore continues to provide order book, matching, margin, and settlement technologies; Payward, Bitnomial, or other licensed institutions are responsible for KYC, sanction screening, account management, and regulatory reporting for US users; The licensing market restricts participation addresses through whitelist, while the global market continues to operate independently without the need for licensing But relying solely on a static blacklist is far from enough, organizations like Lazarus will not use the same address for a long time. They will constantly change wallets, split funds into multiple transactions, transfer them between different assets and blockchains, and then use cross chain bridges, exchanges, and unmarked services to hide paths. By the time an address is publicly marked, the funds may have already been transferred to the next set of wallets So what the American version of Hyperliquid really needs to establish is not just a "ban on a few known addresses", but a continuously updated on chain risk identification system: Real time synchronization of OFAC and other sanction lists • Identify funds that are directly or indirectly linked to high-risk addresses • Track asset paths before and after cross chain bridges • Conduct risk scoring for abnormal splitting, coin mixing, and quick coin exchange behaviors Review existing accounts again after tag updates • Reserve the ability for licensed operators to restrict transactions, cancel orders, and reduce positions This will weaken some of the permissionless experiences, but it is also a cost that regulated funds cannot bypass when entering the on chain market Therefore, this incident cannot simply prove the existence of security vulnerabilities in Hyperliquid. It exposes a more fundamental contradiction: the pursuit of any address that can be used without a license agreement, while the regulated financial system requires the platform to know who the user is, where the funds come from, and who is responsible in case of problems Transparency on the chain allows everyone to see where the money goes, but what US regulations really require is to know who the money is before it comes in If Hyperliquid wants to transform from a global Perp DEX to a financial bottom layer that can be used by licensed institutions in the United States, the emergence of Lazarus related funds may be the first real compliance stress test it must pass HYPE Hyperliquid HyperUnit Lazarus DeFi
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads