North Korea-linked actors accounted for 76% of all cryptocurrency hack losses in 2026 through April, stealing $577 million in two operations — the $285 million Drift Protocol breach and the $292 million KelpDAO bridge exploit. Cumulative DPRK-attributed theft now exceeds $6.75 billion since 2017,...
"North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea's crypto hacking campaign. This is no longer just a remote keyboard operation." — Ari Redbord, Global Head of Policy and Government Affairs, TRM Labs
North Korea-linked actors accounted for 76% of all cryptocurrency hack losses in 2026 through April, stealing $577 million in two operations — the $285 million Drift Protocol breach and the $292 million KelpDAO bridge exploit. Cumulative DPRK-attributed theft now exceeds $6.75 billion since 2017, according to TRM Labs, with a now-disbanded United Nations panel of experts estimating in 2024 that illicit cyber activity funds approximately 40% of Pyongyang's weapons development programs.
The operational signature has changed. Where North Korean hackers once targeted smart contract vulnerabilities and exchange hot wallets, the 2026 campaigns against Drift and KelpDAO were multi-month human intelligence operations involving in-person social engineering, compromised development tools, and manipulated infrastructure nodes. Q2 2026 simultaneously recorded the highest number of crypto exploits in any quarter — 83 incidents totaling $755 million — according to Immunefi data, with bridge protocols absorbing $351 million of those losses.
The shift from code exploits to human-targeted operations carries implications for every protocol that relies on multisig governance, third-party bridge infrastructure, or contributor trust networks.
North Korea's share of total annual cryptocurrency hack losses has increased in each of the last six years, according to TRM Labs data:
| Year | DPRK Share of Global Hack Losses | |------|----------------------------------| | 2020-2021 | Under 10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 (YTD, through April) | 76% |
DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase, driven primarily by the $1.46 billion Bybit cold wallet breach in February 2025 — the largest single cryptocurrency theft on record. Through April 2026, theft totaled $577 million across just two operations, representing 3% of total 2026 incident count but 76% of stolen value.
The concentration ratio is significant. North Korea is not attacking more frequently — the two 2026 operations represent a small fraction of the 83 incidents recorded in Q2 alone. The group is targeting more precisely, selecting higher-value targets and executing larger extractions per operation.
The April 1, 2026, breach of Drift Protocol — a Solana-based perpetual futures platform — resulted in $285 million in losses. Drift described the attack as "six months in the making," attributing it with medium confidence to a North Korean state-sponsored group designated UNC4736.
Phase 1: Human Infiltration (Fall 2025 – March 2026)
Individuals posing as representatives of a quantitative trading firm approached Drift contributors at international cryptocurrency conferences beginning in the fall of 2025. Over a six-month period, they built relationships with specific protocol engineers across multiple events and countries, operating under the pretext of integrating with the protocol.
One Drift contributor was compromised after cloning a code repository shared by the group under the guise of deploying a frontend for their vault. The repository exploited a known vulnerability in the VSCode and Cursor code editors, active between December 2025 and February 2026, which allowed arbitrary code execution without user prompts. A second contributor was manipulated into downloading a malicious TestFlight application framed as a new wallet product.
Phase 2: On-Chain Staging (March 10–30, 2026)
On March 10-11, a single 10 ETH withdrawal from Tornado Cash funded the attack infrastructure. Between March 23 and March 30, the attacker created durable nonce accounts on Solana and pre-authorized transactions. Through social engineering, the attackers obtained real Drift Security Council member signatures on these pre-authorized transactions, which contained instructions to transfer administrative control to an attacker-controlled address.
On March 26, Drift migrated to a new 2/5 threshold Security Council multisig with zero timelock — eliminating the delay window that might have allowed detection.
Phase 3: Execution (April 1, 2026)
Beginning at approximately 16:05 UTC, the pre-signed transactions were deployed and executed. Thirty-one withdrawals drained $285 million in USDC and JLP in approximately 12 minutes, wiping out more than 50% of Drift's total value locked. As of TRM Labs' reporting, the stolen funds remain dormant on Ethereum.
Eighteen days after Drift, on April 18, attackers drained approximately 116,500 rsETH — roughly $292 million and 18% of the token's circulating supply — from KelpDAO's LayerZero-powered bridge. LayerZero attributed the attack with preliminary confidence to the TraderTraitor subunit of North Korea's Lazarus Group.
The exploit targeted infrastructure rather than smart contract code. KelpDAO's rsETH bridge was configured with a single verifier: the LayerZero Labs Decentralized Verifier Network (DVN). The attackers compromised two internal RPC nodes that the DVN relied on for cross-chain transaction verification. The modified nodes fed forged data to the DVN while returning truthful data to other systems — including LayerZero's own monitoring service.
A simultaneous distributed denial-of-service (DDoS) attack disabled the external RPC node the DVN used as a backup. With external validation unreachable, the DVN failed over to the two compromised internal nodes, accepting the forged cross-chain message as legitimate. The malicious binaries were engineered to self-destruct once the attack window closed, wiping logs and configuration files.
OpenZeppelin's post-mortem, titled "$292 Million Lost, Zero Bugs Found," noted that no smart contract vulnerability was exploited. The contracts functioned exactly as designed. The failure was in the infrastructure assumptions underlying a single-verifier configuration.
KelpDAO paused contracts to block a second $95 million extraction. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of the attacker's downstream funds — approximately $75 million. KelpDAO subsequently migrated rsETH from LayerZero's OFT standard to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Approximately $175 million in ETH was converted to Bitcoin, primarily through THORChain.
On June 8, 2026, Humanity Protocol — a proof-of-humanity platform using palm scans and zero-knowledge proofs — lost approximately $36 million in H tokens. Blockchain security firm Quantstamp attributed the attack to DPRK actors based on malware analysis, flagging that the malicious software was signed with a South Korean Hancom digital certificate — a pattern Quantstamp characterized as "characteristic of DPRK intrusions."
The attack vector was a phishing email masquerading as a "token lockup schedule" update from South Korean exchange Bithumb. The email delivered malware granting full remote access to a project director's laptop. From that single device, the attackers obtained three of six Ethereum keys and three of five BNB Chain keys — all stored on the same machine.
On Ethereum, the attackers upgraded the H token bridge contract and drained approximately 141 million H tokens. On BNB Smart Chain, they seized control of a ProxyAdmin contract and minted 300 million unauthorized H tokens. The attacker swapped most tokens for ETH and dumped the remainder on decentralized exchanges, causing the H token to decline 80-90% within 12 hours.
The operational security failure is notable: six multisig keys for two separate chains stored on a single device eliminates the security benefit that multisig architecture is designed to provide.
According to Immunefi data, Q2 2026 recorded 83 crypto hack incidents — the highest count for any quarter on record — with total losses of approximately $755 million. Cross-chain bridge exploits accounted for $351 million, making bridges the costliest attack vector of the quarter.
The incident frequency is increasing even as the per-incident median value declines. Immunefi CEO Mitchell Amador attributed the increase partly to the "proliferation of new AI models" shifting the cybersecurity advantage toward attackers. Attackers are also broadening their target surface beyond smart contracts. According to industry reporting, validators, RPC nodes, and governance systems are increasingly targeted alongside — or instead of — contract-level vulnerabilities.
Monthly loss data for 2026:
| Month | Estimated Losses | |-------|-----------------| | January | ~$73M | | February | ~$35M | | March | ~$42M | | April | ~$630M | | May | ~$68-84M | | June (through mid-month) | ~$42M+ |
April's $630 million — driven almost entirely by the Drift and KelpDAO operations — made it the single most destructive month in crypto hack history. The contrast between April's state-sponsored mega-operations and the smaller, more frequent exploits in surrounding months illustrates a bifurcated threat landscape: a small number of state-backed actors extracting outsized value while a growing number of smaller operators conduct opportunistic attacks.
THORChain, the cross-chain decentralized exchange, has emerged as a primary laundering conduit for DPRK-attributed theft proceeds. The protocol processed the vast majority of Bybit hack proceeds in 2025 and served as the primary conversion pathway for KelpDAO funds in April 2026 — approximately $175 million in ETH converted to Bitcoin.
According to TRM Labs, THORChain "refuses to consider freezing or 'censoring' incoming transactions from known illicit actors." The protocol's permissionless architecture and cross-chain swap capability — specifically ETH-to-BTC conversion without intermediaries — makes it functionally irreplaceable for DPRK laundering operations at scale.
Pre-funding analysis for the KelpDAO exploit traced initial capital to a Bitcoin wallet controlled by Wu Huihui, a Chinese crypto broker indicted in 2023 for laundering Lazarus Group proceeds. Additional funding came from BTCTurk hack proceeds, demonstrating that DPRK operations recycle prior theft capital to fund subsequent attacks.
The 2026 operations mark a structural evolution in DPRK crypto theft methodology. The shift can be summarized across three dimensions:
Attack surface migration. Drift was compromised through social engineering of protocol contributors over six months of in-person contact. KelpDAO was compromised through infrastructure node manipulation. Humanity Protocol was compromised through a single phishing email. None of these attacks exploited a smart contract bug.
Increasing operational patience. The Drift operation involved months of conference attendance, relationship building, and in-person meetings across multiple countries before any on-chain activity occurred. TRM Labs' Ari Redbord described it as "unprecedented" in North Korea's crypto hacking campaign: "What we are watching is not a North Korean campaign that is broader — it is one that is sharper. North Korea is moving faster and more precisely than ever."
Governance architecture exploitation. Both Drift (2/5 multisig with zero timelock) and Humanity Protocol (six keys on one laptop) had governance structures that, while technically functional, contained single points of failure that social engineering could exploit. The lesson for the industry is that multisig security is only as strong as the operational security of its individual signers.
The Bybit breach in February 2025 — $1.46 billion extracted from a cold wallet via a compromised Safe{Wallet} signing interface — established the template. The 2026 operations refined it, demonstrating that DPRK units are capable of sustained, months-long intelligence operations rather than solely technical exploits.
The data points to a structural shift in the threat model facing crypto protocols. North Korea's operations in 2026 are fewer in number but larger in scale, more patient in preparation, and increasingly focused on human and infrastructure targets rather than code-level vulnerabilities. The Drift Protocol attack — where state-sponsored operatives spent six months attending conferences and building relationships before extracting $285 million in 12 minutes — represents a category of threat that smart contract audits cannot address.
For protocols, the implication is that security must extend beyond code. Operational security of multisig signers, timelock enforcement on governance changes, redundant verification infrastructure, and counterintelligence awareness for contributors are no longer optional. For the broader ecosystem, the concentration of laundering activity through permissionless cross-chain protocols like THORChain raises unresolved questions about the boundary between protocol neutrality and facilitation of state-sponsored theft.
The U.N. estimate that 40% of North Korea's weapons program funding derives from crypto theft places these incidents in a context that extends beyond financial loss. Each successful extraction funds sanctioned activities, making crypto security an increasingly intertwined concern with national security policy.