North Korea-linked hackers stole $577 million from two DeFi protocols in April 2026, accounting for 76% of all crypto hack losses year-to-date, according to blockchain intelligence firm TRM Labs. The two attacks — $285 million from Solana-based Drift Protocol on April 1 and $292 million from Kelp...
"What we are watching is not a North Korean campaign that is broader — it is one that is sharper." — Ari Redbord, Global Head of Policy and Government Affairs, TRM Labs
North Korea-linked hackers stole $577 million from two DeFi protocols in April 2026, accounting for 76% of all crypto hack losses year-to-date, according to blockchain intelligence firm TRM Labs. The two attacks — $285 million from Solana-based Drift Protocol on April 1 and $292 million from Kelp DAO on April 18 — pushed April's total crypto theft to approximately $629 million, the worst single month since the $1.4 billion Bybit breach in February 2025.
The Drift exploit is notable for its methodology: a six-month in-person social engineering campaign in which DPRK operatives posed as a quantitative trading firm, approached Drift contributors at multiple international conferences, and ultimately tricked two of five Security Council multisig signers into pre-signing malicious governance transactions. The attack exploited Solana's "durable nonce" feature, which allows signed transactions to remain valid indefinitely. It took 12 minutes to drain $285 million in USDC, SOL, and ETH.
Cumulative North Korea-attributed crypto theft now exceeds $6 billion since 2017, according to TRM Labs. The DPRK share of global crypto hack losses has risen from under 10% in 2020–2021 to 76% through April 2026, a trajectory that reflects increasing operational sophistication rather than increasing attack volume.
| Metric | Value | |---|---| | Total crypto hack losses (April) | ~$629M | | DPRK-attributed losses (April) | $577M | | DPRK share of 2026 YTD losses | 76% | | DeFi protocol losses (April) | $614M | | Separate DeFi incidents (Jan–Apr 2026) | 47 | | YoY increase in attack frequency | 68% | | Cumulative DPRK theft (since 2017) | >$6B | | DeFi TVL decline post-exploits | $13.2B |
April 2026 recorded the highest monthly crypto theft in over a year. According to CertiK, total losses reached $650.9 million when including smaller incidents. DeFi protocols absorbed $614 million of the total — 95% of which came from the Drift and Kelp DAO attacks alone.
The month's 47 separate DeFi incidents represent a 68% year-over-year increase compared to the same period in 2025, per DeFiLlama data. The figure is 3.7 times larger than the entire first quarter's combined losses of $165.5 million.
Beginning in approximately September 2025, individuals posing as representatives of a quantitative trading firm approached Drift Protocol contributors at major cryptocurrency conferences across multiple countries. According to CoinDesk's investigation, the operatives spent six months building personal relationships with specific Drift team members, attending in-person events, and conducting what TRM Labs described as "unprecedented in-person social engineering."
The objective was not code exploitation. It was human exploitation: gaining enough trust with two of Drift's five Security Council multisig members to obtain their signatures on transactions that appeared routine but contained malicious payloads.
On March 11, a single withdrawal of 10 ETH from Tornado Cash funded the deployment of CarbonVote Token (CVT), a fabricated asset with a total supply of 750 million tokens. The attackers seeded a Raydium liquidity pool and wash-traded CVT to anchor its price at approximately $1.00. They simultaneously deployed a custom price oracle they controlled, which fed the artificial CVT price to Drift's margin system.
On March 23, four durable nonce accounts were created on Solana. Two were associated with legitimate Drift Security Council members. Two were controlled by the attacker. This confirmed the attacker had already obtained valid signatures — locked into durable nonce transactions that would not expire — from two of the five council members.
At approximately 12:00 UTC on April 1, Drift ran a legitimate test withdrawal from its insurance fund. One minute later, the attacker submitted the pre-signed durable nonce transactions. Two transactions, four slots apart on the Solana blockchain, were sufficient to approve a malicious admin transfer and execute it.
With administrative control secured, the attackers whitelisted CVT as eligible collateral. They deposited 500 million CVT — valued at $500 million by their controlled oracle — and withdrew $285 million in USDC, SOL, and ETH through 31 withdrawals over approximately 12 minutes. Most stolen funds were bridged to Ethereum within hours and have remained dormant since.
The attack exploited a design feature, not a bug. Solana's durable nonces replace the standard expiring blockhash with a fixed nonce stored in an on-chain account, keeping signed transactions valid indefinitely until submission. According to BlockSec's analysis, once a signer approves a durable nonce transaction, they cannot revoke their signature unless the nonce authority manually advances the nonce account. This separates the moment of signing from the moment of execution — a feature designed for convenience that became an attack primitive for governance manipulation.
On April 18, attackers drained 116,500 rsETH — approximately $292 million — from Kelp DAO by compromising internal RPC nodes in the protocol's LayerZero-powered cross-chain bridge. The attackers launched a denial-of-service attack against Kelp's verifier infrastructure, then exploited a single-verifier design flaw to authorize fraudulent cross-chain messages.
LayerZero attributed the attack with preliminary confidence to North Korea's Lazarus Group.
Arbitrum's Security Council froze 30,766 ETH (approximately $71 million) linked to the attackers on April 20, placing the funds in a governance-controlled wallet. This recovered roughly one quarter of the stolen assets. The remaining $175 million in ETH was swapped to Bitcoin via THORChain before the freeze could take effect.
On April 30, Arbitrum DAO opened voting — through May 7 — on a proposal to allocate the frozen ETH to the DeFi United recovery initiative. Early voting showed 16.9 million ARB tokens in favor, with no opposition recorded. The freeze itself triggered debate about centralization: a Layer 2 Security Council unilaterally immobilizing assets raises questions about the decentralization guarantees that DeFi protocols claim to provide.
The combined impact of the Drift and Kelp DAO exploits extended far beyond the directly stolen funds. Total DeFi TVL dropped from $99.5 billion on April 17 to $86.3 billion by April 20 — a $13.2 billion decline in 48 hours.
Aave, the largest DeFi lending protocol, lost $8.45 billion in deposits over that same period, falling from $26.4 billion to approximately $20 billion. Borrowing demand collapsed on April 29 after the Kelp DAO exploit triggered a broader confidence crisis. By April 26, approximately $160 million had been committed toward an Aave rescue fund targeting $300 million.
The contagion ratio was stark: for every $1 stolen in the Kelp DAO exploit, $45 of additional capital exited the DeFi sector within 48 hours.
Carrot, a Solana-based yield protocol with $28 million in TVL before the Drift hack, saw its deposits collapse 93% to $1.99 million. On April 30, Carrot announced a full shutdown, giving users until May 14 to withdraw before forced deleveraging begins. Carrot was not directly exploited; its exposure to the Drift ecosystem through liquidity strategies created a second-order collapse.
Approximately 15 to 20 Solana-based projects that used Drift for liquidity, vaults, or yield strategies reported varying degrees of impact, according to news.bitcoin.com.
The stablecoin market shed $892 million in the immediate aftermath of the Kelp DAO breach, as automated DeFi unwind mechanisms triggered liquidation cascades.
North Korea's share of global crypto hack losses has followed a consistent upward curve:
| Year | DPRK Share of Global Crypto Hack Losses | |---|---| | 2020–2021 | <10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 (through April) | 76% |
TRM Labs attributed $2.02 billion to DPRK-linked actors in 2025, a 51% year-over-year increase. Chainalysis independently reported a closely matching $1.92 billion figure. The dominant 2025 incident was the $1.5 billion Bybit Ethereum theft on February 21, 2025, officially attributed to the Lazarus Group by the FBI within five days.
The 2026 data shows a shift in methodology. Rather than targeting centralized exchanges, DPRK operators are now attacking DeFi governance infrastructure and cross-chain bridges with prolonged social engineering campaigns. The Drift attack, which took six months of in-person preparation, represents a level of operational patience that complicates standard cybersecurity defenses — firewalls and code audits cannot counter an adversary that manipulates human trust at physical conferences.
TRM Labs analysts have noted that DPRK operators may be incorporating AI tools into reconnaissance and social engineering workflows. The Wasabi Protocol exploit on April 30 — which drained $4.5 million through a similar admin key compromise with no timelock or multisig — suggests that the playbook established in the Drift attack is being replicated across the ecosystem, though attribution for Wasabi has not been confirmed.
The Solana Foundation announced "Stride" and the Solana Incident Response Network (SIRN) on April 7, days after the Drift exploit. Led by Asymmetric Research, Stride will evaluate Solana DeFi protocols against eight security pillars and publish its findings.
Recommended structural changes following the Drift incident include:
These recommendations are not novel. They reflect well-known security best practices that many DeFi protocols have chosen not to implement, often citing speed and operational convenience.
April 2026 established a data point that the DeFi sector will need to reckon with: a single nation-state actor now controls the majority of all crypto theft value in a given year through a small number of high-value, methodically planned attacks. The economic cost is not limited to the $577 million directly stolen. The $13.2 billion in TVL outflows, the collapse of dependent protocols like Carrot, and the $892 million stablecoin drawdown represent the second-order damage of a sector that has not yet internalized basic governance security practices.
The structural vulnerability is clear. Most DeFi protocols still lack timelocks on admin actions. Multisig thresholds remain low. Human-layer security — vetting signers, securing governance processes against social engineering — is largely absent. These are not unsolved problems. They are unimplemented solutions.
Until the cost of implementing governance safeguards falls below the expected loss from not having them — a threshold that April 2026 may have crossed — the attack surface will persist.