North Korean Wallets Probe Hyperliquid's Four-Validator Bridge, Sparking $210M in Withdrawals
Security researcher Tayvano raised an alarm on December 23, 2024, after identifying several DPRK-linked wallet addresses actively trading on Hyperliquid. The pattern, she argued, looked less like ordinary speculation and more like a state-sponsored group probing a protocol's defenses ahead of a larger move. Tayvano previously led security at MEW/MyCrypto before joining MetaMask, and has built a reputation over several years for flagging threats before they escalate into losses.
Her warning landed on a protocol that, according to DeFi Llama data, secures more than $2 billion in total value locked with a bridge overseen by just four validators. Hyperliquid's own documentation confirms the setup: four validators in total, with only three signatures needed to authorize movement of the entire pool. Industry watchers were quick to draw a comparison to Ronin's $624 million bridge hack, where attackers needed to compromise just five of nine validators to drain funds.

Compounding the unease, ZachXBT had separately flagged that the Radiant Capital attacker — the same actor behind October's $50 million exploit of Radiant Capital — had been trading on Hyperliquid, reportedly clearing roughly $600,000 on a long ETH position.
News of the DPRK-linked activity spread quickly, and the market reacted before Hyperliquid's team could respond in detail: HYPE dropped 21% and the protocol saw more than $210 million in outflows within a short window — its largest single-day withdrawal on record. This came just weeks after Hyperliquid's $1.6 billion airdrop had pushed HYPE's market capitalization above $11 billion.
Hyperliquid's official response, posted on Discord, rejected the concern outright: "There has been no DPRK exploit – or any exploit for that matter – of Hyperliquid. All user funds are accounted for." The team maintained that "no vulnerabilities have been shared by any party."
01Community response split sharply
Rather than treating Tayvano's warning as a prompt to review infrastructure, a segment of Hyperliquid's community dismissed it as attention-seeking. One user went so far as to suggest she was fishing for a job offer. Tayvano herself later described being met with "insults and profanity" and eventually muted the thread, stating plainly: "this isn't a thing that is up for debate... HL either acts to harden their system. Or they don't."
Established figures in security and crypto pushed back on the dismissal. Viktor Bunin wrote that he and his wife had been targeted by North Korean actors multiple times and that "Tayvano is the first person I turn to and she has been nothing but incredible at every turn. If she's proactively trying to protect you... Take the help." Samczsun, Laura Shin, and David Phelps offered similar support. Phelps summarized the criticism bluntly: "the correct way to respond to one of the top security minds telling you she'd like to give you her time because of extreme concerns that north korea is deep inside your $30B platform is not to tell her that you don't like her tone."
A former a16z security lead, Nass Eddequiouaq, offered a starker read of the situation, saying his instinct was that the attackers were already inside Hyperliquid's infrastructure and using the access to study how to maximize a future exploit.
02A narrow set of keys guarding billions
The structural concern centers on custody design. As one breakdown put it, "Hyperliquid's bridge is controlled by two 3-of-4 hot wallet multisigs, managed by a single binary" — a single point of failure sitting in front of billions in user funds. With just four validators securing the bridge, against a group that Cointelegraph estimates stole $1.34 billion across various crypto targets in 2024 alone, the margin for error is thin.
Contingency options aren't much more reassuring. ZachXBT noted that getting Circle to freeze assets outside standard 9-to-5 ET business hours is difficult, and the fallback of having Arbitrum's security council vote to roll back the chain is widely regarded as a last-resort, nuclear option. Hyperliquid's Discord did signal plans to expand to 16 validators "soon," though no firm timeline was given.

Questions about operational security are also colored by recent history: Radiant Capital's October breach began with a single malicious PDF attachment and resulted in a $50 million loss. As for Hyperliquid's own vulnerability disclosure process, the closest thing to a bug bounty is an "open-ticket" button on Discord, and the only formal security documentation is a single page inside a GitHub repository — not the main website, not the docs. There is no published rewards structure and no formal disclosure process.
03Divided interpretations
Some in the community characterized the entire episode as a coordinated "psyop" meant to damage Hyperliquid's reputation. Others argued that DPRK-linked wallets are known to interact with a wide range of DeFi protocols, and that their presence alone doesn't prove malicious intent toward Hyperliquid specifically.
Security-focused observers were less willing to write it off. With a state-sponsored group that spent 2024 refining techniques that netted an estimated $1.34 billion — and with Radiant Capital's PDF-based breach still fresh — the consensus among that group was that a four-validator bridge, a three-of-four signing threshold, and a Discord ticket system do not constitute an adequate response to a threat actor operating around the clock. Whether Hyperliquid's promised expansion to sixteen validators arrives soon enough remains an open question.
Get new scam files the moment we publish them — usually 2–3 emails a week.