North Korean Hackers Linked to $30M Laundered Through Crypto Platform
On-chain analytics firm Arkham has identified addresses associated with North Korea's Lazarus Group moving more than $30 million through Hyperliquid, a decentralised crypto trading platform, via its HyperUnit service during August. Lazarus is a well-documented state-sponsored hacking group tied to numerous high-profile cryptocurrency thefts, and researchers track its wallet activity to understand how stolen funds are laundered and moved into usable currency.
While this incident centres on cryptocurrency infrastructure rather than a typical business network, it highlights the scale and sophistication of state-backed cybercrime groups that also target businesses through phishing, malware, and fraudulent invoicing schemes to fund their operations. Small businesses that accept or hold cryptocurrency, or that work with crypto-adjacent clients, should be aware that funds linked to sanctioned actors can move through mainstream-looking platforms, creating compliance and reputational risks.
This development is a reminder that cybercrime proceeds, once stolen, don't simply disappear — they get laundered through legitimate-looking financial rails, sometimes implicating unwitting businesses along the way. Security teams and finance departments should stay alert to unusual transaction patterns and maintain awareness of sanctions-related risks when dealing with digital assets.