DPRK-linked threat actors stole $577 million from two DeFi protocols in April 2026 — Drift Protocol ($285 million) and KelpDAO ($292 million) — accounting for 76% of all crypto hack losses through the first four months of the year, according to data published by TRM Labs. The figure extends North...
"North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea's crypto hacking campaign. This is no longer just a remote keyboard operation." — Ari Redbord, Global Head of Policy, TRM Labs
DPRK-linked threat actors stole $577 million from two DeFi protocols in April 2026 — Drift Protocol ($285 million) and KelpDAO ($292 million) — accounting for 76% of all crypto hack losses through the first four months of the year, according to data published by TRM Labs. The figure extends North Korea's cumulative attributed crypto theft past $6 billion since 2017.
The concentration is stark. Two attacks, one state actor, three-quarters of global losses. The trajectory is accelerating: DPRK's share of total crypto exploit value rose from under 10% in 2020–2021 to 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and now 76% through April 2026. The attacks themselves have shifted from remote code exploits toward long-duration social engineering and infrastructure compromise — tactics that fall outside the scope of conventional smart contract audits.
Total crypto exploit losses for January–May 2026 exceeded $840 million, according to aggregated data from CryptoTimes, CCN, and PeckShield. April alone accounted for more than $600 million across an estimated 28–30 separate incidents, making it the most-hacked month in crypto history by incident count. May losses dropped sharply to $68–84 million depending on the source, but the structural vulnerabilities that enabled the largest thefts remain largely unresolved.
Drift Protocol — $285 million, April 1, 2026. The Solana-based decentralized exchange was drained in approximately 12 minutes. TRM Labs attributed the attack with medium confidence to UNC4736, a DPRK state-sponsored group also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces. The attack followed six months of social engineering that began in fall 2025, when operatives — using third-party intermediaries rather than DPRK nationals — made in-person contact with Drift personnel and established a Telegram group for ongoing communication about trading strategies and vault integrations.
Between December 2025 and January 2026, the group onboarded an Ecosystem Vault on Drift, depositing over $1 million of their own funds and engaging multiple contributors with detailed product questions. Between March 23 and 30, 2026, the attackers used Solana's durable nonce feature to create pre-signed transactions that appeared routine but contained instructions to transfer administrative control to an attacker-controlled address. Drift Security Council members signed these transactions unknowingly. On April 1, the attacker executed the drain.
KelpDAO — $292 million, April 18, 2026. Attackers linked to North Korea's Lazarus Group drained 116,500 rsETH — approximately 18% of the token's circulating supply — from KelpDAO's LayerZero-powered cross-chain bridge. The exploit targeted off-chain infrastructure rather than smart contract code. According to Chainalysis, the attackers compromised two RPC nodes used by the LayerZero Labs Decentralized Verifier Network (DVN), then launched a DDoS attack against uncompromised nodes to force failover to the poisoned ones. The DVN then validated transactions that had not actually occurred on the source chain.
The core vulnerability was a 1-of-1 verifier configuration — KelpDAO's rsETH bridge relied on a single DVN (the LayerZero Labs DVN) to verify all cross-chain messages. LayerZero's own documentation recommended a multi-DVN model, but the single-verifier setup was approved during onboarding. OpenZeppelin's post-incident analysis noted that smart contract audits do not typically examine whether infrastructure components such as RPC nodes, relayers, or oracle setups introduce single points of failure.
The Drift and KelpDAO exploits illustrate a shift in DPRK attack methodology. Neither relied on traditional smart contract vulnerabilities.
Drift: The human layer. The six-month social engineering campaign involved in-person meetings, sustained Telegram communications, legitimate fund deposits, and gradual trust-building with protocol contributors. The attackers' intermediaries had verifiable professional backgrounds and demonstrated technical fluency with Drift's product. According to CoinDesk reporting, this marks the first publicly documented case of North Korean operatives conducting months-long, face-to-face relationship building to compromise a DeFi protocol.
The technical exploitation phase leveraged Solana's durable nonce mechanism, which allows transactions to be signed in advance and executed later. This is a legitimate feature, but in this context it enabled the attacker to obtain valid signatures from Security Council members under the guise of routine operations.
KelpDAO: The infrastructure layer. No code was exploited. The attack compromised the operational infrastructure — RPC nodes — that fed data to the verification system. The 1-of-1 DVN configuration meant a single point of verification failure could authorize fraudulent cross-chain messages. This attack vector sits outside the perimeter of standard code audits.
TRM Labs' Ari Redbord noted that AI tools are compounding the threat: "North Korean operators have long been capable social engineers, but AI is dismantling the constraints that historically limited their precision, such as language barriers, the time required to build convincing personas, the difficulty of personalizing attacks at scale."
The trend line is unambiguous. DPRK-attributed theft as a percentage of total global crypto hack losses:
| Year | DPRK Share | Notable Context | |------|-----------|-----------------| | 2020 | <10% | Primarily exchange-focused attacks | | 2021 | <10% | Early DeFi exploit era | | 2022 | 22% | Ronin Bridge ($625M) | | 2023 | 37% | Increased bridge targeting | | 2024 | 39% | IT worker infiltration emerges | | 2025 | 64% | Bybit ($1.5B), cumulative $2B for year | | 2026 (Jan–Apr) | 76% | Drift + KelpDAO = $577M of $760M total |
Source: TRM Labs, Chainalysis
Cumulative DPRK-attributed crypto theft now exceeds $6 billion since 2017, according to TRM Labs. The increase in share is not primarily a function of more attacks — it reflects larger per-incident hauls from fewer, more precisely targeted operations. In 2025, Chainalysis documented $2.02 billion stolen by DPRK-linked actors, a 51% year-over-year increase, driven largely by the $1.5 billion Bybit exploit.
Recovery rates for the two April exploits remain low.
KelpDAO: Arbitrum's Security Council froze 30,766 ETH ($71 million) at an address linked to the exploit, per Cybernews reporting. An additional $4 million in stablecoins was frozen by issuers. The remaining proceeds — estimated at over $210 million — were laundered primarily through THORChain, a cross-chain liquidity protocol that has emerged as a preferred laundering vector for state-sponsored actors. THORChain was also used to process a significant portion of the 2025 Bybit hack proceeds, according to Chainalysis.
Drift: Approximately 130,259 ETH (roughly $293 million) remained concentrated across four Ethereum wallets that have been flagged and are actively monitored. Two transfers via the Wormhole bridge were delayed by the protocol's governor until late July, effectively locking funds in transit. Circle froze $3.36 million in stablecoins. Drift issued a public bounty for recovery and established a compensation pool; users can redeem tokens once the pool exceeds $5 million, though early redemption requires forfeiting future claims.
The pattern is consistent with prior DPRK laundering operations: rapid dispersion across chains, conversion through privacy-preserving protocols, and exploitation of the time lag between theft detection and exchange-level blocking.
Cross-chain bridges remain the largest single-point-of-failure vector in DeFi. PeckShield tracked eight major bridge exploits in 2026, totaling $328.6 million. The KelpDAO incident alone accounts for 89% of that figure.
The structural problem is well-documented. Bridges aggregate large pools of locked assets and rely on verification mechanisms that, if compromised, can authorize the release of those assets to attackers. The KelpDAO case demonstrated that even when the smart contract code is sound — OpenZeppelin titled its analysis "$292 Million Lost, Zero Bugs Found" — the infrastructure surrounding the contracts can be fatally weak.
The fallout has been immediate. KelpDAO migrated its rsETH bridge from LayerZero to Chainlink's Cross-Chain Interoperability Protocol (CCIP). Solv Protocol moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero. LayerZero's ZRO token declined following the exodus.
LayerZero ultimately issued a public apology, stating: "We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions. We didn't police what our DVN was securing, which created a risk we simply didn't see." The admission reversed weeks of public finger-pointing between LayerZero and KelpDAO over responsibility for the exploit.
Protocol-level changes. LayerZero published updated security requirements barring single-DVN configurations for high-value bridges. Solana's ecosystem began discussing governance reforms around durable nonce usage following the Drift exploit.
Regulatory attention. The U.S. Treasury's Office of Foreign Assets Control (OFAC) has maintained sanctions against Lazarus Group-linked addresses. TRM Labs' Redbord has testified before the House Committee on Homeland Security on DPRK cyber operations. The scale of 2026 losses — a single state actor responsible for three-quarters of all stolen funds — may accelerate regulatory pressure on DeFi protocols to implement mandatory security standards beyond code audits.
Insurance and risk. The DeFi insurance market remains underdeveloped relative to the risk. Most protocols carry no hack coverage. The Drift and KelpDAO exploits — both involving operational rather than code-level vulnerabilities — fall outside the scope of most existing audit frameworks, suggesting that the industry's primary risk mitigation tool (smart contract audits) addresses only a subset of actual attack vectors.
May data. Exploit losses dropped sharply in May 2026 to $68.3 million (CryptoTimes) or $84.2 million across 41 incidents (Cryip), a 90% decline from April. The decline reflects the absence of a mega-exploit rather than improved security infrastructure. The Alephium bridge ($815,000) and Gravity bridge ($5.4 million) were the largest May incidents.
The data through May 2026 presents a market in which a single state actor — North Korea — is responsible for more than three-quarters of all crypto exploit losses. The attacks are fewer in number but larger in impact, and they target layers of protocol operations that conventional security practices do not cover.
The Drift and KelpDAO exploits represent two distinct failure modes: human trust (social engineering of protocol signers) and infrastructure trust (compromise of verification nodes). Both sit outside the perimeter of smart contract audits. The industry's security model, built primarily around code review, is demonstrably incomplete.
For protocols managing significant TVL, the implication is that security budgets and practices must expand to include operational security assessments, multi-party verification requirements, infrastructure redundancy audits, and governance design reviews. For regulators, the concentration of losses in state-sponsored operations strengthens the case for mandatory security standards that extend beyond code.
The $577 million stolen by DPRK-linked actors in April 2026 alone exceeds the total stolen from all crypto exploits in several prior calendar years. The scale has shifted. The security model has not.