Hyperliquid net outflows top $250M amid fears over North Korea hackers
Hyperliquid has suffered its largest single-day outflow after security experts said that North Korean hackers were trading on the new layer-1 crypto derivatives platform.ย
Metmask security researcher Tay Monahan said in a Dec. 23 X post that Democratic Peopleโs Republic of Korea (DPRK)-linked hackers had been using the platform from as early as October.ย
โYall, DPRK doesnโt trade. DPRK tests,โ Monhan added in a follow-up post.
Source: Tay Monahan
Net outflows from the derivatives platform have topped $256 million in the last 30 hours, according to data from Dune Analytics.ย
Outflows from Hyperliquid on Dec. 23 hit an all-time peak of $502.71 million, while inflows reached over $253.5 million.
Net outflows from Hyperliquid have topped $256 million in the last 30 hours. Source: Dune Analytics
Hyperliquid said on its Discord server that itโs โaware of reports circulating regarding activity by supposed DPRK addresses. There has been no DPRK exploit - or any exploit for that matter - of Hyperliquid. All user funds are accounted for.โ
North Korean hackers such as the Lazarus Group have stolen $1.3 billion worth of crypto so far this year โ doubling their haul from last year in an escalation of dictator Kim Jong Unโs effort to scrape together cash for the nation largely cut off from the world by sanctions.
Monahan further claimed that Hyperliquidโs security and infrastructure are largely centralized, relying on just four validators.
Monahanโs post triggered a broad set of reactions from crypto pundits, with Hyperliquid supporters accusing her of creating unnecessary fear.ย
The exchangeโs native Hyperliquid (HYPE) token was also hit by the fallout, falling 20% from its all-time high of $35 on Dec. 22, and is currently changing hands for $28, according to TradingView data.ย
However, other developers and security researchers supported Monahanโs reputation as a security expert in the crypto industry.ย
โYou might not like the way Tay communicates, but at least weโre talking now: Kim [Jong Unโs] goons showing up is always at least a two-alarm fire,โ wrote Wildcat Labs co-founder Laurence Day.
โIโve had run-ins with Lazarus before, and you do NOT want them doing anything that looks โsillyโ because itโs often not,โ Day added in a later post.ย
There are โtwo lines of defenseโ in case of major exploitย
Pseudonymous developer Cygaar said if North Korea were to attack Hyperliquid, there are two lines of defense that could be utilized to stop massive sums of USD Coin (USDC) from being stolen.
Source: Cygaar
USDC issuer Circle could blacklist addresses from moving tokens completely in a bid to freeze the movement of potential threat actors, Cyggar said.
โIf they act quickly enough, they can prevent the attacker from trading out of the stolen USDC and effectively freeze the funds. This should allow Circle to return funds back to the HL bridge,โ he added.ย
Secondly, Cygaar said the Arbitrum Chain โ the network Hyperqliuid is built on โ could roll back the chain the prevent the loss of funds. However, Day said an Arbitrum rollback was โabsolutely notโ going to happen unless there was an โexistentialโ threat to the chain.ย
Magazine: Comeback 2025 โ Is Ethereum poised to catch up with Bitcoin and Solana?