North Korean Hackers Steal 77M in 2026: 76% of All Crypto Hack Losses

North Korean hacking groups have stolen approximately $577 million in cryptocurrency through just two attacks in 2026—accounting for a staggering 76% of all crypto hack losses year-to-date, according to a new analysis from TRM Labs.

The findings reveal a troubling trend: North Korea’s share of crypto theft has accelerated dramatically, from under 10% in 2020-2021 to 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and now 76% through April 2026. This represents the highest sustained share on record, driven not by increased attack frequency but by unprecedented precision and scale.

The Two Heists That Dwarfed Everything Else

Through April 2026, the cryptocurrency industry experienced numerous hacks and exploits. Yet two incidents—the Drift Protocol breach on April 1 ($285 million) and the KelpDAO bridge exploit on April 18 ($292 million)—represent just 3% of incident count but 76% of stolen value.

This ratio—small number of attacks, outsized share of losses—has characterized North Korea’s approach since 2017, when cumulative attributed thefts began accumulating toward what now exceeds $6 billion.

Drift Protocol: $285 Million Stolen via Unprecedented Social Engineering

The Drift Protocol attack represents one of the most sophisticated crypto heists ever executed. TRM Labs attributes the breach to a North Korean group distinct from the notorious Lazarus Group, though specific subgroup attribution remains under investigation.

Three Weeks of Staging, Months of Manipulation

On-chain staging began March 11 with a single 10 ETH withdrawal from Tornado Cash. However, the campaign against Drift began much earlier, involving in-person meetings between North Korean proxies and Drift employees over a period of months—an unprecedented tactic in North Korea’s lengthy crypto hacking campaign.

The technical mechanism exploited a Solana-native feature called a durable nonce. Standard Solana transactions expire within roughly 90 seconds if not confirmed on-chain. Durable nonces extend that window indefinitely, allowing transactions to be pre-signed and held before broadcast—a feature designed for offline hardware signing.

The Exploit Unfolded

Between March 23 and March 30, the attacker created durable nonce accounts and induced Drift’s Security Council multisig signers into pre-authorizing transactions using this mechanism. On March 27, Drift migrated its Security Council to a new 2/5 threshold configuration with zero timelock—a change the attacker subsequently exploited.

In parallel, the attacker manufactured CarbonVote Token (CVT)—a fictitious asset seeded with a small amount of liquidity and inflated through wash trading—which Drift’s oracles treated as legitimate collateral.

On April 1, the pre-signed transactions were deployed: 31 withdrawals executed in approximately 12 minutes, draining real assets including USDC and JLP. Most stolen funds were bridged to Ethereum within hours, where they have remained dormant since the day of the theft.

“The responsible group tends to take a more measured and cautious approach to laundering its heists,” TRM analysts noted. “We anticipate a months or years-long liquidation of the Drift proceeds.”

KelpDAO: $292 Million via Single-Verifier Bridge Vulnerability

The KelpDAO breach on April 18 targeted its rsETH LayerZero bridge on Ethereum, exploiting a critical architectural flaw: a single-verifier configuration.

How the Attack Worked

The attackers first compromised two internal RPC (Remote Procedure Call) nodes, swapping out the node software to make them report false blockchain data. They then launched a distributed denial-of-service (DDoS) attack against external, uncompromised RPC nodes, forcing the bridge’s verifier to fail over to the two poisoned internal nodes.

Those compromised nodes falsely reported that rsETH had been burned on the source chain when no such burn had occurred. The single verifier, reading from the compromised data source, confirmed the fraudulent cross-chain message as legitimate. The attacker drained approximately 116,500 rsETH—worth approximately $292 million—from the Ethereum bridge contract.

The Single-DVN Vulnerability

The single-DVN (Decentralized Verifier Network) configuration is the defining vulnerability. LayerZero’s security model supports configuring multiple independent verifiers for cross-chain message validation; KelpDAO’s rsETH deployment used only one—the LayerZero Labs DVN. With no second verifier required to agree, a single poisoned data source was sufficient to approve a fraudulent transaction at scale.

Attribution Through Laundering Trails

TRM Labs attributed this exploit to North Korea based on on-chain analysis of both pre-funding and subsequent laundering patterns. Notably, a portion of the initial funding for the exploit was traceable as far back as 2018 to a Bitcoin wallet controlled by Wu Huihui, a Chinese crypto broker indicted in 2023 for laundering Lazarus crypto thefts. Other funds used to finance the attack were sourced more directly to the BTCTurk hack, another recent TraderTraitor theft.

Two Hacks, Two Laundering Strategies

Drift and KelpDAO demonstrate distinct laundering approaches shaped by different operational conditions and threat actor preferences.

Drift Laundering: Speed Coupled with Patience

Stolen tokens were converted to USDC via Jupiter, bridged to Ethereum, and swapped into ETH—distributed across fresh wallets before going dormant. The stolen ETH has not moved since the day of the theft.

This follows a well-documented North Korean pattern: hold proceeds for months or years, then execute a structured, multi-phase cashout. The group responsible for Drift—assessed as distinct from Lazarus Group—tends toward caution rather than rapid liquidation.

KelpDAO Laundering: Resilience First

After the theft, the TraderTraitor hackers left approximately 30,766 ETH on Arbitrum—a Layer 2 network with far higher centralization than Ethereum. The Arbitrum Security Council exercised emergency powers to freeze these ETH (worth roughly $75 million)—an action that alerted the hackers and triggered a mad laundering scramble.

Approximately $175 million in ETH—a portion of the unfrozen total—were swapped to Bitcoin, mostly through THORChain, a cross-chain liquidity protocol with no KYC requirement. Umbra, an Ethereum privacy tool, was also used to obscure some wallet linkages before the conversion to Bitcoin.

“So far, the KelpDAO laundering process is unfolding according to the well-worn TraderTraitor playbook,” TRM noted. “The ongoing laundering phase is handled almost entirely by Chinese intermediaries, not the North Koreans themselves.”

THORChain: North Korea’s Bridge of Choice

THORChain has processed the vast majority of proceeds from both the Bybit breach (2025) and the KelpDAO hack (2026), converting hundreds of millions in stolen ETH to Bitcoin with no operator willing to freeze or reject transfers.

In 2025, the vast majority of stolen Bybit funds were converted from ETH to BTC via THORChain between February 24 and March 2—an unprecedented surge in cross-chain volume that the protocol processed without intervention. KelpDAO followed the same playbook in April 2026: approximately $175 million in ETH moved through THORChain after the Arbitrum Security Council froze a portion of the stolen funds.

THORChain’s developers and validators claim it is a decentralized protocol with no central operator and that it cannot reject transactions or centrally disable the platform. Recent statements on social media by project members suggest this is not, or has not, always been the case.

For North Korea, THORChain functions as a reliable, high-capacity exit ramp: assets enter as ETH and emerge as BTC, beyond the reach of traditional freezing mechanisms.

What Compliance Teams Need to Monitor

TRM Labs outlines four monitoring priorities following from the 2026 pattern:

1. THORChain Flows from KelpDAO-Linked Addresses

Exchanges receiving BTC inflows from THORChain pools should screen against known KelpDAO and Lazarus Group address clusters. TRM Wallet Screening covers North Korea-attributed addresses across Ethereum, Solana, TRON, and Bitcoin, with updates propagated as attribution is confirmed.

“Attribution for specific KelpDAO addresses is ongoing—retroactive re-screening in 30 days will capture addresses labeled after the initial response,” TRM advised.

2. Solana Multisig and Governance Contract Exposure

The Drift attack targeted governance infrastructure, not application logic. Protocols using Solana Security Council multisig with durable nonce authorization should treat this as a template attack that will be replicated.

Exchanges with Solana DeFi deposit exposure should flag inflows from bridge contracts used in the Drift dispersal—including specific Jupiter and Wormhole routes identified in TRM Transaction Monitoring.

3. Multi-Hop Bridge Deposit Screening

Both KelpDAO and Bybit involved bridge or cross-chain infrastructure as the attack surface or laundering route. Bridge-to-exchange flows are a priority monitoring channel for North Korean proceeds.

“First-hop address screening alone will not catch funds that passed through intermediary wallets before reaching an exchange,” TRM warned. “Multi-hop analysis across the full transaction chain is required.”

4. Beacon Network Enrollment for Real-Time Alerts

Both major 2026 North Korean hacks targeted DeFi protocols—and DeFi protocols are now Beacon Network members alongside major exchanges including Coinbase, Binance, Kraken, OKX, and Crypto.com.

When investigators flag attacker-controlled addresses in TRM, Beacon auto-traces funds in real time and sends immediate alerts across all 30+ member platforms. Individual screening catches known addresses; Beacon Network closes the gap between attribution and action—converting a screening lag measured in days into an alert measured in minutes.

Why North Korea Dominates Crypto Theft

TRM Labs addresses the central question: why does North Korea account for such a disproportionate share of crypto hack losses?

Precision Over Volume: North Korea’s elite hacking teams run a small number of high-precision attacks against large infrastructure targets rather than a high volume of smaller exploits. In 2026 YTD, two incidents accounted for 76% of all tracked hack losses.

Heavy Pre-Attack Investment: North Korean hackers increasingly invest heavily in pre-attack staging—the Drift campaign involved three weeks of on-chain preparation and months of targeted social engineering. They target environments where a single vulnerability produces nine-figure outcomes, such as bridge validator networks and multisig governance contracts.

AI-Enhanced Operations: TRM analysts have begun to speculate that North Korean operators are incorporating AI tools into their reconnaissance and social engineering workflows—a development consistent with the increasing precision of attacks like Drift, which required weeks of targeted manipulation of complex blockchain mechanisms, rather than North Korea’s traditional emphasis on simple private key compromises.

The Growing Threat Landscape

The 2025 spike in North Korean crypto theft was driven almost entirely by the Bybit breach in February—$1.46 billion extracted from a cold wallet via a compromised Safe{Wallet} signing interface. Bybit remains the largest single crypto hack in history.

Following that, KelpDAO and Drift together now represent one of the largest North Korean hauls in any comparable window. The trend is clear: North Korea’s crypto theft operations are becoming more sophisticated, more targeted, and more devastating with each passing year.

Key Takeaways

  • $577 million stolen in 2 attacks: 76% of all crypto hack losses through April 2026
  • Drift Protocol ($285M): Exploited Solana durable nonce feature after months of social engineering
  • KelpDAO ($292M): Single-verifier bridge vulnerability allowed fraudulent cross-chain messages
  • THORChain’s role: Processed hundreds of millions in stolen funds from both Bybit and KelpDAO
  • $6 billion total: North Korea’s cumulative attributed crypto theft since 2017
  • AI integration suspected: Increasing sophistication suggests AI-assisted reconnaissance and social engineering
  • Compliance priorities: THORChain flows, Solana multisig exposure, multi-hop bridge screening, Beacon Network enrollment

The Road Ahead

As North Korean hacking groups continue to refine their tactics, incorporating AI tools and investing in long-term social engineering campaigns, the cryptocurrency industry faces an evolving threat that demands equally evolved defenses.

The Drift and KelpDAO heists demonstrate that traditional security measures—while necessary—are insufficient against state-sponsored actors with patient capital, sophisticated tooling, and willingness to invest months in preparation for a single attack.

For exchanges, DeFi protocols, and compliance teams, the message is clear: real-time intelligence sharing, multi-hop transaction analysis, and proactive screening are no longer optional. They are existential requirements in an era where two attacks can steal more than all other hacks combined.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer