North Korean state-backed hackers extracted USD 577 million from decentralized finance protocols in the first four months of 2026, accounting for 76% of all crypto hack losses during the period, according to blockchain intelligence firm TRM Labs. The theft occurred across just two operations — th...
"North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea's crypto hacking campaign. This is no longer just a remote keyboard operation." — Ari Redbord, Global Head of Policy, TRM Labs
North Korean state-backed hackers extracted USD 577 million from decentralized finance protocols in the first four months of 2026, accounting for 76% of all crypto hack losses during the period, according to blockchain intelligence firm TRM Labs. The theft occurred across just two operations — the Drift Protocol exploit on April 1 (USD 285 million) and the KelpDAO bridge breach on April 18 (USD 292 million) — representing 3% of total hack incidents but three-quarters of total losses by value.
April 2026 now stands as the single worst month for cryptocurrency hacks on record: USD 651 million stolen across 30 separate exploits, exceeding the total annual hack figure for 2022. The two DPRK-attributed attacks alone composed 89% of that monthly total. Cumulative North Korean crypto theft since 2017 now exceeds USD 6 billion, according to TRM Labs data.
The cascading damage extended far beyond the directly exploited protocols. The KelpDAO attack triggered USD 13 billion in DeFi TVL withdrawals within 48 hours, forced Aave to freeze markets holding USD 1.2 billion in rsETH, and exposed the structural fragility of cross-chain bridge infrastructure that underpins much of decentralized finance.
Through the first four months of 2026, total cryptocurrency hack losses reached approximately USD 771.8 million across all incidents, according to aggregated data from TRM Labs and Chainalysis. North Korea's two operations — Drift Protocol and KelpDAO — accounted for USD 577 million of that total.
The concentration is notable. DPRK-linked actors executed 3% of all hack incidents but captured 76% of total stolen value. The remaining 28 exploits in April alone — including Rhea Finance (USD 18.4 million), Grinex (USD 15 million), and Wasabi Protocol (USD 4.55 million) — collectively totaled less than one-eighth of the two North Korean operations combined.
Both attacks targeted infrastructure layers rather than smart contract logic. Drift was compromised through social engineering of multisig signers. KelpDAO fell through a single-verifier bridge configuration. Neither required finding a bug in Solidity or Rust code.
The Drift Protocol breach on April 1, 2026, drained USD 285 million — over 50% of the protocol's total value locked — from Solana's largest decentralized perpetual futures exchange in approximately 12 minutes.
The attack began months earlier. According to Drift's own post-mortem and analysis by Chainalysis, North Korean operatives onboarded as vault participants on the protocol, deposited over USD 1 million in capital, and engaged in extended strategy and product discussions with Drift contributors. TRM Labs characterized the campaign as involving in-person meetings between DPRK proxies and protocol employees — a departure from the remote-only operations historically associated with Lazarus Group.
The technical execution proceeded in phases:
Phase 1 — Fake collateral creation (March 12): The attacker created CarbonVote Token (CVT), controlling approximately 80% of supply, and manufactured artificial trading activity between self-controlled wallets to establish a price of roughly USD 1.
Phase 2 — Durable nonce exploitation (March 23-30): Using Solana's durable nonce feature, which allows transactions to be signed now but executed later, the attacker induced Security Council multisig members to pre-sign what appeared to be routine transactions through a process Chainalysis described as "blind signing."
Phase 3 — Timelock removal (March 26-27): Drift migrated its Security Council to a 2-of-5 signature threshold and removed its timelock entirely. Timelocks typically enforce a 24-to-72-hour delay on administrative actions; without one, the attacker gained zero-delay execution authority.
Phase 4 — Drain (April 1): The pre-signed durable nonce transactions were activated. The attacker listed CVT as valid collateral, raised withdrawal limits, and deposited CVT against which Drift's risk engine issued real assets. The full drain completed in 12 minutes.
The DRIFT token fell 37-42% in the immediate aftermath. Contagion spread to more than 20 downstream protocols, including Prime Numbers Fi, Carrot Protocol, Pyra Protocol, and Piggybank.
Seventeen days after Drift, on April 18, attackers drained approximately 116,500 rsETH — valued at USD 292 million and representing roughly 18% of the token's circulating supply — from KelpDAO's LayerZero-powered bridge.
The exploit targeted the bridge's verification architecture. According to Chainalysis's post-incident analysis, the attacker compromised internal RPC nodes that fed data to KelpDAO's cross-chain messaging system. Poisoned nodes reported blocks showing rsETH being burned on the source chain when no such burn had occurred. The LayerZero Labs DVN (Decentralized Verifier Network), reading only from those compromised nodes, confirmed the fraudulent cross-chain message as valid.
The core vulnerability: KelpDAO's bridge was configured to accept attestation from a single verifier. LayerZero's OApp configuration model allows application developers to choose how many DVNs must sign off on an incoming message. KelpDAO had set that threshold at one.
KelpDAO's security team detected the attack in progress and successfully paused contracts to block a second transfer of approximately USD 95 million. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH (approximately USD 75 million) of the attacker's downstream funds.
The KelpDAO breach produced cascading effects that far exceeded the USD 292 million in directly stolen assets.
Because the bridge held reserves backing rsETH across more than 20 networks, the exploit immediately raised questions about rsETH backing on every layer-2 chain where the token was deployed. Protocols holding rsETH as collateral — including Aave, SparkLend, and Fluid — froze affected markets.
Aave, with USD 1.2 billion in rsETH deployed across its markets, activated its Guardian module to freeze exposure. Within 48 hours, USD 8.45 billion in deposits exited Aave alone, according to CoinDesk reporting. Total DeFi TVL declined by USD 13.21 billion in the two days following the attack.
Much of the decline reflected leveraged positions unwinding rather than direct capital destruction. DeFi leverage strategies cause assets to be counted multiple times in TVL calculations, amplifying both growth during accumulation and declines during deleveraging. The actual capital loss was the USD 292 million stolen plus roughly USD 177 million in bad debt created on Aave from rsETH collateral that lost its backing.
Capital rotation was immediate. Spark TVL jumped from USD 1.8 billion to USD 2.9 billion over the weekend as users migrated from Aave. Aave founder Stani Kulechov, Lido Finance, and EtherFi coordinated a recovery effort to cover the shortfall and prevent bad debt from spreading.
TRM Labs documented diverging post-theft laundering strategies between the two attacks:
Drift proceeds: After an initial cross-chain transfer to Ethereum, the stolen funds have remained largely dormant since theft day. The inactivity may indicate the attackers are waiting for enforcement attention to subside before attempting liquidation.
KelpDAO proceeds: The attacker pivoted to Bitcoin conversion via THORChain after the Arbitrum freeze blocked approximately USD 75 million. An estimated USD 175 million was converted to Bitcoin through THORChain, following a pattern TRM Labs described as a "textbook TraderTraitor liquidation process."
THORChain has now processed the vast majority of proceeds from both the 2025 Bybit breach (USD 1.4 billion) and the KelpDAO attack. The cross-chain DEX has become a critical node in North Korea's laundering infrastructure.
DPRK's proportion of total cryptocurrency hack losses has risen every year for six consecutive years, according to TRM Labs data:
| Year | DPRK Share of Hack Losses | |------|---------------------------| | 2020-2021 | Under 10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 YTD | 76% |
The pattern does not reflect an increase in the total number of DPRK operations. It reflects a shift toward fewer, higher-value targets. TRM Labs noted that North Korea executed only 3% of 2026's total incidents but captured 76% of total value — the inverse of a spray-and-pray approach.
TRM Labs analysts have also noted indications that North Korean operators may be incorporating AI tools into reconnaissance and social engineering workflows. The Drift attack, which required months of targeted relationship-building and manipulation of complex governance mechanisms, represents a level of operational sophistication beyond the private key compromises that historically characterized DPRK crypto theft.
The scale of 2026's losses has intensified scrutiny of DeFi's insurance deficit. According to industry data compiled by CoinInsider, less than 2% of DeFi assets carry insurance coverage.
The DeFi insurance market reached USD 1.8 billion in 2025 and is projected to grow to USD 12.4 billion by 2034. The broader crypto insurance market stood at USD 9.49 billion in 2025, with projections of USD 192.7 billion by 2033.
The gap between covered and exposed assets remains large. With total DeFi TVL exceeding USD 100 billion and annual hack losses running at over USD 750 million through April 2026 alone, the insurance coverage ratio is insufficient by an order of magnitude.
Institutional demand for coverage is rising: 70% of institutional investors surveyed indicated they prefer exchanges with insurance coverage, and 41% of retail users identified insurance as a key platform selection factor, according to CoinInsider.
Post-KelpDAO, several structural responses have emerged:
Bridge security upgrades: KelpDAO has begun migrating to Chainlink's Cross-Chain Interoperability Protocol (CCIP), replacing the single-verifier LayerZero configuration. Multiple protocols have announced reviews of their bridge DVN threshold settings.
Multisig governance reforms: The Drift exploit exposed the danger of blind signing and timelock removal. Chainalysis published detailed recommendations including mandatory timelocks on all admin actions, independent transaction verification by all multisig signers, and simulation of transactions before signing.
Coordination infrastructure: TRM Labs' Beacon Network, a threat-sharing consortium of 30+ exchanges and DeFi protocols, facilitated the Arbitrum freeze of KelpDAO funds. The network's role in real-time fund freezing has become a de facto industry response mechanism.
Parametric insurance products: DeFi insurers have begun shipping parametric products with automated payouts triggered by measurable events — a structural improvement over the claims-based processes that proved too slow to be useful during the KelpDAO crisis.
The data from the first four months of 2026 establishes that state-sponsored crypto theft has become a concentrated, high-precision operation. Two attacks by a single nation-state actor accounted for more than three-quarters of the industry's total losses. The targets were not obscure protocols with audited code vulnerabilities — they were infrastructure and governance layers that most security audits do not cover.
The economic implications are measurable. The direct losses of USD 577 million are dwarfed by the systemic impact: USD 13 billion in TVL contraction, USD 177 million in bad debt on Aave, and a capital rotation event that reshaped protocol market share overnight. These second-order effects represent the actual cost of infrastructure fragility in a composable financial system.
For protocols holding user funds, the operational security requirements have shifted. Code audits are necessary but insufficient. Multisig governance, bridge verification thresholds, and human-layer defenses now constitute the binding constraint on DeFi security. The industry's response — including the Beacon Network, bridge migration to multi-verifier architectures, and parametric insurance — represents a structural adjustment, but the 2% insurance coverage rate suggests the gap between risk exposure and risk mitigation remains large.