← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] DPRK Takes 76% of 2026 Crypto Hack Losses

Zephyra|May 10, 2026|BPF
EXECUTIVE SUMMARY

North Korean state-backed hackers extracted USD 577 million from decentralized finance protocols in the first four months of 2026, accounting for 76% of all crypto hack losses during the period, according to blockchain intelligence firm TRM Labs. The theft occurred across just two operations — th...

"North Korean proxies sitting across a table from protocol employees over a period of months. That is, to my knowledge, unprecedented in North Korea's crypto hacking campaign. This is no longer just a remote keyboard operation." — Ari Redbord, Global Head of Policy, TRM Labs

Executive Summary

North Korean state-backed hackers extracted USD 577 million from decentralized finance protocols in the first four months of 2026, accounting for 76% of all crypto hack losses during the period, according to blockchain intelligence firm TRM Labs. The theft occurred across just two operations — the Drift Protocol exploit on April 1 (USD 285 million) and the KelpDAO bridge breach on April 18 (USD 292 million) — representing 3% of total hack incidents but three-quarters of total losses by value.

April 2026 now stands as the single worst month for cryptocurrency hacks on record: USD 651 million stolen across 30 separate exploits, exceeding the total annual hack figure for 2022. The two DPRK-attributed attacks alone composed 89% of that monthly total. Cumulative North Korean crypto theft since 2017 now exceeds USD 6 billion, according to TRM Labs data.

The cascading damage extended far beyond the directly exploited protocols. The KelpDAO attack triggered USD 13 billion in DeFi TVL withdrawals within 48 hours, forced Aave to freeze markets holding USD 1.2 billion in rsETH, and exposed the structural fragility of cross-chain bridge infrastructure that underpins much of decentralized finance.

Table of Contents

  1. Two Attacks, 76% of Losses
  2. Drift Protocol: The Long Con
  3. KelpDAO: The Single-Verifier Flaw
  4. Systemic Contagion: The USD 13 Billion Withdrawal Wave
  5. Laundering Playbooks Diverge
  6. North Korea's Escalating Share
  7. The Insurance Gap
  8. Industry Response and Structural Remedies
  9. Key Takeaways
  10. Conclusion

Two Attacks, 76% of Losses

Through the first four months of 2026, total cryptocurrency hack losses reached approximately USD 771.8 million across all incidents, according to aggregated data from TRM Labs and Chainalysis. North Korea's two operations — Drift Protocol and KelpDAO — accounted for USD 577 million of that total.

The concentration is notable. DPRK-linked actors executed 3% of all hack incidents but captured 76% of total stolen value. The remaining 28 exploits in April alone — including Rhea Finance (USD 18.4 million), Grinex (USD 15 million), and Wasabi Protocol (USD 4.55 million) — collectively totaled less than one-eighth of the two North Korean operations combined.

Both attacks targeted infrastructure layers rather than smart contract logic. Drift was compromised through social engineering of multisig signers. KelpDAO fell through a single-verifier bridge configuration. Neither required finding a bug in Solidity or Rust code.

Drift Protocol: The Long Con

The Drift Protocol breach on April 1, 2026, drained USD 285 million — over 50% of the protocol's total value locked — from Solana's largest decentralized perpetual futures exchange in approximately 12 minutes.

The attack began months earlier. According to Drift's own post-mortem and analysis by Chainalysis, North Korean operatives onboarded as vault participants on the protocol, deposited over USD 1 million in capital, and engaged in extended strategy and product discussions with Drift contributors. TRM Labs characterized the campaign as involving in-person meetings between DPRK proxies and protocol employees — a departure from the remote-only operations historically associated with Lazarus Group.

The technical execution proceeded in phases:

Phase 1 — Fake collateral creation (March 12): The attacker created CarbonVote Token (CVT), controlling approximately 80% of supply, and manufactured artificial trading activity between self-controlled wallets to establish a price of roughly USD 1.

Phase 2 — Durable nonce exploitation (March 23-30): Using Solana's durable nonce feature, which allows transactions to be signed now but executed later, the attacker induced Security Council multisig members to pre-sign what appeared to be routine transactions through a process Chainalysis described as "blind signing."

Phase 3 — Timelock removal (March 26-27): Drift migrated its Security Council to a 2-of-5 signature threshold and removed its timelock entirely. Timelocks typically enforce a 24-to-72-hour delay on administrative actions; without one, the attacker gained zero-delay execution authority.

Phase 4 — Drain (April 1): The pre-signed durable nonce transactions were activated. The attacker listed CVT as valid collateral, raised withdrawal limits, and deposited CVT against which Drift's risk engine issued real assets. The full drain completed in 12 minutes.

The DRIFT token fell 37-42% in the immediate aftermath. Contagion spread to more than 20 downstream protocols, including Prime Numbers Fi, Carrot Protocol, Pyra Protocol, and Piggybank.

KelpDAO: The Single-Verifier Flaw

Seventeen days after Drift, on April 18, attackers drained approximately 116,500 rsETH — valued at USD 292 million and representing roughly 18% of the token's circulating supply — from KelpDAO's LayerZero-powered bridge.

The exploit targeted the bridge's verification architecture. According to Chainalysis's post-incident analysis, the attacker compromised internal RPC nodes that fed data to KelpDAO's cross-chain messaging system. Poisoned nodes reported blocks showing rsETH being burned on the source chain when no such burn had occurred. The LayerZero Labs DVN (Decentralized Verifier Network), reading only from those compromised nodes, confirmed the fraudulent cross-chain message as valid.

The core vulnerability: KelpDAO's bridge was configured to accept attestation from a single verifier. LayerZero's OApp configuration model allows application developers to choose how many DVNs must sign off on an incoming message. KelpDAO had set that threshold at one.

KelpDAO's security team detected the attack in progress and successfully paused contracts to block a second transfer of approximately USD 95 million. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH (approximately USD 75 million) of the attacker's downstream funds.

Systemic Contagion: The USD 13 Billion Withdrawal Wave

The KelpDAO breach produced cascading effects that far exceeded the USD 292 million in directly stolen assets.

Because the bridge held reserves backing rsETH across more than 20 networks, the exploit immediately raised questions about rsETH backing on every layer-2 chain where the token was deployed. Protocols holding rsETH as collateral — including Aave, SparkLend, and Fluid — froze affected markets.

Aave, with USD 1.2 billion in rsETH deployed across its markets, activated its Guardian module to freeze exposure. Within 48 hours, USD 8.45 billion in deposits exited Aave alone, according to CoinDesk reporting. Total DeFi TVL declined by USD 13.21 billion in the two days following the attack.

Much of the decline reflected leveraged positions unwinding rather than direct capital destruction. DeFi leverage strategies cause assets to be counted multiple times in TVL calculations, amplifying both growth during accumulation and declines during deleveraging. The actual capital loss was the USD 292 million stolen plus roughly USD 177 million in bad debt created on Aave from rsETH collateral that lost its backing.

Capital rotation was immediate. Spark TVL jumped from USD 1.8 billion to USD 2.9 billion over the weekend as users migrated from Aave. Aave founder Stani Kulechov, Lido Finance, and EtherFi coordinated a recovery effort to cover the shortfall and prevent bad debt from spreading.

Laundering Playbooks Diverge

TRM Labs documented diverging post-theft laundering strategies between the two attacks:

Drift proceeds: After an initial cross-chain transfer to Ethereum, the stolen funds have remained largely dormant since theft day. The inactivity may indicate the attackers are waiting for enforcement attention to subside before attempting liquidation.

KelpDAO proceeds: The attacker pivoted to Bitcoin conversion via THORChain after the Arbitrum freeze blocked approximately USD 75 million. An estimated USD 175 million was converted to Bitcoin through THORChain, following a pattern TRM Labs described as a "textbook TraderTraitor liquidation process."

THORChain has now processed the vast majority of proceeds from both the 2025 Bybit breach (USD 1.4 billion) and the KelpDAO attack. The cross-chain DEX has become a critical node in North Korea's laundering infrastructure.

North Korea's Escalating Share

DPRK's proportion of total cryptocurrency hack losses has risen every year for six consecutive years, according to TRM Labs data:

| Year | DPRK Share of Hack Losses | |------|---------------------------| | 2020-2021 | Under 10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 YTD | 76% |

The pattern does not reflect an increase in the total number of DPRK operations. It reflects a shift toward fewer, higher-value targets. TRM Labs noted that North Korea executed only 3% of 2026's total incidents but captured 76% of total value — the inverse of a spray-and-pray approach.

TRM Labs analysts have also noted indications that North Korean operators may be incorporating AI tools into reconnaissance and social engineering workflows. The Drift attack, which required months of targeted relationship-building and manipulation of complex governance mechanisms, represents a level of operational sophistication beyond the private key compromises that historically characterized DPRK crypto theft.

The Insurance Gap

The scale of 2026's losses has intensified scrutiny of DeFi's insurance deficit. According to industry data compiled by CoinInsider, less than 2% of DeFi assets carry insurance coverage.

The DeFi insurance market reached USD 1.8 billion in 2025 and is projected to grow to USD 12.4 billion by 2034. The broader crypto insurance market stood at USD 9.49 billion in 2025, with projections of USD 192.7 billion by 2033.

The gap between covered and exposed assets remains large. With total DeFi TVL exceeding USD 100 billion and annual hack losses running at over USD 750 million through April 2026 alone, the insurance coverage ratio is insufficient by an order of magnitude.

Institutional demand for coverage is rising: 70% of institutional investors surveyed indicated they prefer exchanges with insurance coverage, and 41% of retail users identified insurance as a key platform selection factor, according to CoinInsider.

Industry Response and Structural Remedies

Post-KelpDAO, several structural responses have emerged:

Bridge security upgrades: KelpDAO has begun migrating to Chainlink's Cross-Chain Interoperability Protocol (CCIP), replacing the single-verifier LayerZero configuration. Multiple protocols have announced reviews of their bridge DVN threshold settings.

Multisig governance reforms: The Drift exploit exposed the danger of blind signing and timelock removal. Chainalysis published detailed recommendations including mandatory timelocks on all admin actions, independent transaction verification by all multisig signers, and simulation of transactions before signing.

Coordination infrastructure: TRM Labs' Beacon Network, a threat-sharing consortium of 30+ exchanges and DeFi protocols, facilitated the Arbitrum freeze of KelpDAO funds. The network's role in real-time fund freezing has become a de facto industry response mechanism.

Parametric insurance products: DeFi insurers have begun shipping parametric products with automated payouts triggered by measurable events — a structural improvement over the claims-based processes that proved too slow to be useful during the KelpDAO crisis.

Key Takeaways

  • North Korea extracted USD 577 million from two DeFi protocols in April 2026, representing 76% of all crypto hack losses year-to-date, according to TRM Labs.
  • April 2026 was the worst single month for crypto hacks on record: USD 651 million across 30 exploits.
  • Both major attacks targeted infrastructure and human layers — not smart contract code. Drift fell to social engineering of multisig signers; KelpDAO fell to a single-verifier bridge configuration.
  • The KelpDAO breach triggered USD 13 billion in DeFi TVL withdrawals within 48 hours, exposing the systemic risk posed by widely-composited tokens losing their backing.
  • North Korea's share of crypto hack losses has risen from under 10% in 2020-2021 to 76% in 2026 YTD — a six-year trend of increasing concentration.
  • Less than 2% of DeFi assets carry insurance coverage, a gap that is becoming more visible as losses scale.
  • THORChain has become the primary laundering channel for DPRK-linked crypto proceeds.

Conclusion

The data from the first four months of 2026 establishes that state-sponsored crypto theft has become a concentrated, high-precision operation. Two attacks by a single nation-state actor accounted for more than three-quarters of the industry's total losses. The targets were not obscure protocols with audited code vulnerabilities — they were infrastructure and governance layers that most security audits do not cover.

The economic implications are measurable. The direct losses of USD 577 million are dwarfed by the systemic impact: USD 13 billion in TVL contraction, USD 177 million in bad debt on Aave, and a capital rotation event that reshaped protocol market share overnight. These second-order effects represent the actual cost of infrastructure fragility in a composable financial system.

For protocols holding user funds, the operational security requirements have shifted. Code audits are necessary but insufficient. Multisig governance, bridge verification thresholds, and human-layer defenses now constitute the binding constraint on DeFi security. The industry's response — including the Beacon Network, bridge migration to multi-verifier architectures, and parametric insurance — represents a structural adjustment, but the 2% insurance coverage rate suggests the gap between risk exposure and risk mitigation remains large.

Sources & References

  1. North Korea Stole 76% of All Crypto Hack Value in 2026 — TRM Labs research report, April 2026
  2. The Drift Protocol Hack: How Privileged Access Led to a $285 Million Loss — Chainalysis analysis
  3. Inside the KelpDAO Bridge Exploit — Chainalysis technical post-mortem
  4. The Long Con: How North Korean Spies Drained $285 Million from Drift — CoinDesk, April 30, 2026
  5. April 2026: The Worst Month for Crypto Hacks in History — Crypto Impact Hub
  6. DeFi TVL Drops More Than $13 Billion in Two Days Following KelpDAO Hack — CoinDesk, April 20, 2026
  7. Aave Rallies DeFi Partners to Contain Fallout from $292 Million KelpDAO Hack — CoinDesk, April 23, 2026
  8. Crypto's Insurance Crisis: Billions Exposed as Hacks Persist — CoinInsider, 2026
  9. North Korea Accounts for 76% of 2026 Crypto Hack Losses — The Block, April 2026
  10. Drift Protocol Exploited for $286 Million in Suspected DPRK-Linked Attack — Elliptic