The Democratic People's Republic of Korea has extracted $6.75 billion in cryptocurrency since 2017, according to cumulative data from Chainalysis, TRM Labs, and Elliptic. The operation is not slowing down. In the first half of 2026 alone, DPRK-linked groups accounted for approximately $643 millio...
"North Korean hackers accounted for 76% of all crypto hack value through April 2026." — TRM Labs, H1 2026 Crypto Hacks Report
The Democratic People's Republic of Korea has extracted $6.75 billion in cryptocurrency since 2017, according to cumulative data from Chainalysis, TRM Labs, and Elliptic. The operation is not slowing down. In the first half of 2026 alone, DPRK-linked groups accounted for approximately $643 million — 66% of all crypto hack losses tracked by TRM Labs — across a campaign that has grown more surgical, more patient, and more resistant to countermeasures.
CertiK's Hack3D report logged $1.31 billion in total Web3 security losses across 344 on-chain incidents in H1 2026. Nearly 44% of that sum traces to two DPRK-attributed operations: the $292 million KelpDAO bridge exploit and the $285 million Drift Protocol drain. Recovery rates have collapsed to 0.4% of stolen funds in Q1 2025, down from 21.2% a year earlier, per Immunefi data. The laundering infrastructure remains intact despite sanctions, OFAC designations, and an 11-nation advisory issued July 31, 2026.
This report examines the scale, methods, and economic structure of DPRK crypto theft operations, the industry's defensive response, and the measurable gaps that persist.
Chainalysis's 2026 Crypto Crime Report establishes the baseline: DPRK-linked actors stole $2.02 billion in 2025, a 51% year-over-year increase from the $1.34 billion recorded in 2024. That figure pushed the cumulative all-time total to $6.75 billion. A single incident — the $1.5 billion Bybit breach of February 21, 2025 — accounted for 74% of 2025's total and remains the largest cryptocurrency theft in history.
The FBI confirmed the Bybit attribution to Lazarus Group (also tracked as TraderTraitor and APT38) within days of the incident. Attackers compromised a developer machine connected to Safe{Wallet}'s multisig platform, intercepting a routine cold-to-hot wallet transfer of over 400,000 ETH and stETH.
Year-over-year totals, per Chainalysis, show an acceleration pattern:
| Year | DPRK Stolen (est.) | Share of Global Crypto Hacks | |------|-------------------|------------------------------| | 2022 | $1.7B | ~60% | | 2023 | $0.7B | ~33% | | 2024 | $1.34B | ~61% | | 2025 | $2.02B | ~65% | | H1 2026 | $643M | ~66% |
The DPRK's share of global crypto theft has stabilized between 60% and 76%, depending on the reporting firm and measurement window. The operation functions as a structural revenue source for Pyongyang's nuclear weapons and ballistic missile programs.
Drift Protocol — April 1, 2026 — $285 million
Attackers drained over half of Drift Protocol's total value locked from the Solana-based perpetual futures exchange in 12 minutes. TRM Labs attributed the attack to Lazarus Group. Elliptic logged it as the 18th DPRK-linked operation of 2026.
The intrusion began six months before the theft. North Korean operatives spent months building relationships with Drift's team, according to Chainalysis's post-incident analysis. They exploited Solana's "durable nonces" feature, convincing Drift Security Council multisig signers to unknowingly pre-sign transactions that eventually transferred admin control. Once in control, the attackers whitelisted a fabricated token — CarbonVote Token (CVT) — manipulated Drift's oracle into treating it as legitimate collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH.
The attack was the second-largest exploit in Solana's history, behind only the $326 million Wormhole bridge hack of February 2022.
KelpDAO — April 18, 2026 — $292 million
Lazarus Group's TraderTraitor subunit struck KelpDAO's rsETH bridge on the LayerZero protocol, draining approximately $292 million in under 46 minutes. The Arbitrum Security Council froze 30,766 ETH ($71 million) at an address linked to the exploit, marking one of the few successful on-chain intervention events.
Together, these two incidents accounted for $577 million — 44% of all H1 2026 Web3 losses per CertiK, and 90% of DPRK-attributed theft in the period.
The composition of crypto exploits has shifted. CertiK's data shows 125 of 207 H1 2026 incidents were smart contract exploits, but they accounted for only a small portion of total value stolen. Wallet compromise and operational security failures drove 74% of stolen value, according to QuillAudits.
DPRK operations reflect this shift. The group's primary attack vector is no longer code — it is people.
Social engineering phases documented in Drift and KelpDAO:
Chainalysis noted in its Drift post-mortem that "compromised accounts now account for more than 50% of all DeFi attacks by incident count — overtaking traditional smart contract exploits as the primary source of losses for the first time."
Parallel to direct theft, DPRK operates a systematic IT worker infiltration scheme that generated approximately $800 million in 2024, per OFAC disclosures. On March 12, 2026, OFAC designated six individuals and two entities for facilitating these schemes, including Amnokgang Technology Development Company, a DPRK-managed IT operation, and Nguyen Quang Viet, a Vietnamese national whose firm converted approximately $2.5 million in IT worker earnings into cryptocurrency between mid-2023 and mid-2025.
The operation has evolved. On July 31, 2026, eleven allied nations — the United States, Japan, South Korea, Australia, Canada, New Zealand, and, for the first time, France, Germany, Italy, the Netherlands, and the United Kingdom — issued a joint advisory warning that North Korean operatives now use real-time AI deepfake video during live job interviews. The technology maps a stolen or synthetic face onto the operative's actual video feed via a virtual camera driver that video-conferencing platforms treat as a standard webcam.
North Korea dismissed the advisory on August 4, 2026, calling the multinational cyber watchdog a "ghost mechanism."
The IT worker pipeline serves dual purposes: direct revenue generation and access to insider systems at crypto firms, creating reconnaissance opportunities for larger theft operations.
DPRK laundering tactics have shifted measurably. TRM Labs data shows bridge-related theft laundering rose 66% between 2023 and 2025, while mixer-related activity fell 37%. The decline in mixer use correlates with OFAC's August 2022 sanctions on Tornado Cash, which had processed more than $455 million in Lazarus-linked funds per the Treasury Department.
Current laundering flows documented by Chainalysis follow a consistent pattern:
The group rarely cashes out in a single operation. Lazarus still holds identifiable tranches from hacks dating back to 2022, suggesting either patience or bottlenecks in fiat conversion channels.
Recovery rates tell the starkest story in the dataset. Immunefi reported only 0.4% of Q1 2025 stolen funds recovered, down from 21.2% in Q1 2024. PeckShield logged $334.9 million returned across all hacks in 2025 versus $488.5 million in 2024. For state-sponsored thefts specifically, recovery rates remain well below 5%, per Wilson Center and CSIS analyses.
Exceptions exist but are narrow:
The fundamental constraint is speed. DPRK operatives execute initial fund dispersal within minutes. Cross-chain movement follows within hours. By the time forensic firms produce attribution reports and law enforcement obtains freezing orders, the majority of stolen funds have already passed through multiple jurisdictions and blockchain networks.
Protocol-level responses have focused on three areas:
Blockaid's H1 2026 report noted crypto hacks hit a record 207 incidents despite total losses declining 57% from H1 2025's $2.3 billion to $972 million (by their methodology). The drop is misleading. CertiK observed that stripping out the $1.45 billion Bybit outlier from 2025 puts the adjusted figure at roughly $1.03 billion, making 2026 approximately 28% higher on a comparable basis.
The data describes a state-level adversary that has adapted faster than the industry's defensive capabilities. DPRK operations have migrated from smart contract exploits to social engineering and governance manipulation — attack surfaces that code audits do not cover. The $6.75 billion cumulative figure continues to grow, while recovery rates have effectively collapsed.
The 11-nation advisory of July 31, 2026, signals growing political recognition of the threat but offers no enforcement mechanism beyond voluntary screening. DeFi protocols face a structural vulnerability: decentralized governance is designed to resist centralized control, which is precisely the property DPRK operatives exploit when manipulating multisig signers and governance processes.
The economic question is whether the cost of enhanced operational security — hardware-isolated signing, extended timelocks, mandatory multi-party verification — is less than the expected loss from a sector that loses $643 million per half-year to a single threat actor. The data suggests it is. Whether the industry acts on that calculation remains to be observed.