Industry News

North Korean Hackers Linked to $30M Laundered Through Crypto Platform

Crypto Daily · 1 Sept 2026
Key Takeaway If your business handles cryptocurrency payments, implement basic due diligence checks on counterparties and monitor for unusual transaction patterns linked to known threat actor wallets.

On-chain analytics firm Arkham has identified addresses associated with North Korea's Lazarus Group moving more than $30 million through Hyperliquid, a decentralised crypto trading platform, via its HyperUnit service during August. Lazarus is a well-documented state-sponsored hacking group tied to numerous high-profile cryptocurrency thefts, and researchers track its wallet activity to understand how stolen funds are laundered and moved into usable currency.

While this incident centres on cryptocurrency infrastructure rather than a typical business network, it highlights the scale and sophistication of state-backed cybercrime groups that also target businesses through phishing, malware, and fraudulent invoicing schemes to fund their operations. Small businesses that accept or hold cryptocurrency, or that work with crypto-adjacent clients, should be aware that funds linked to sanctioned actors can move through mainstream-looking platforms, creating compliance and reputational risks.

This development is a reminder that cybercrime proceeds, once stolen, don't simply disappear — they get laundered through legitimate-looking financial rails, sometimes implicating unwitting businesses along the way. Security teams and finance departments should stay alert to unusual transaction patterns and maintain awareness of sanctions-related risks when dealing with digital assets.

Summarised by CISO AI from Crypto Daily. We link back to every original so you can read it yourself.