North Korea's Lazarus Group and affiliated units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to Chainalysis data. The pace is accelerating. DPRK-linked actors took $2.02 billion in 2025 — a 51% increase over 2024 — and added at least $600 million more through th...
"Bybit has demonstrated a likelihood of success on the merits." — U.S. District Court for the District of Columbia, ruling in Bybit v. DPRK & Lazarus Group, August 2026
North Korea's Lazarus Group and affiliated units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to Chainalysis data. The pace is accelerating. DPRK-linked actors took $2.02 billion in 2025 — a 51% increase over 2024 — and added at least $600 million more through the first seven months of 2026, accounting for 76% of all crypto hack value in the period. The two largest DeFi exploits of 2026 — Drift Protocol ($285 million, April 1) and KelpDAO ($292 million, April 18) — were both attributed to Lazarus by blockchain intelligence firms.
The operation is not a collection of opportunistic thefts. It is a state-run funding mechanism. According to UN Panel of Experts estimates cited in security council reports, malicious cyber activity generates approximately 40-50% of North Korea's foreign currency income and is used directly to fund its weapons of mass destruction programs. Eleven allied nations issued a coordinated warning on July 31, 2026, that DPRK operatives are now using real-time AI deepfake video to infiltrate Western companies through fraudulent hiring.
This report examines the scale, methods, and economic implications of what has become the largest sustained state-sponsored theft operation in cryptocurrency history.
The Chainalysis 2026 Crypto Crime Report provides the clearest accounting of DPRK theft operations to date. In 2025, North Korean actors executed approximately 80 incidents totaling $2.02 billion in stolen cryptocurrency. The single largest event — the Bybit exchange breach in February 2025 — netted $1.5 billion in Ethereum, making it the largest cryptocurrency theft in history.
Through the first four months of 2026, DPRK-linked groups accounted for 76% of all cryptocurrency hack value, according to Chainalysis. The first half of 2026 saw 207 hack incidents across the broader crypto industry totaling approximately $972 million in losses, per Immunefi data. North Korean actors were responsible for the majority of the dollar value.
The cumulative total since 2017 now stands at approximately $6.75 billion. For context, the Chainalysis 2026 report estimates total illicit cryptocurrency activity at approximately $154 billion, encompassing fraud, theft, ransomware, and darknet marketplace operations.
April 2026 set a record as the single worst month in crypto theft history, with $629.69 million drained across the industry, of which $614.17 million came from DeFi protocols. The two largest incidents — Drift Protocol and KelpDAO — were both attributed to Lazarus.
The most consequential shift in DPRK cyber operations during 2025-2026 has been the move away from smart contract exploitation toward human-layer attacks. Both of the year's largest exploits succeeded not because of code vulnerabilities, but because attackers compromised people and processes.
Social Engineering at Scale. In April 2026, CertiK disclosed a campaign dubbed "Mach-O Man" in which Lazarus operatives send fake Zoom, Microsoft Teams, or Google Meet invitations via Telegram. The link directs victims to a convincing but fraudulent website that instructs them to paste a command into their Mac terminal to resolve an apparent connection issue. The command installs a modular malware kit built from native Mach-O binaries tailored for Apple environments, which profiles the host, establishes persistence, and exfiltrates credentials through a Telegram-based command-and-control channel. The malware erases itself before most victims realize they have been compromised, according to CertiK researchers.
Insider Placement. DPRK operatives now embed IT workers inside crypto companies using stolen identities and fabricated credentials, gaining privileged access before executing high-impact thefts. CrowdStrike tracks this cluster as FAMOUS CHOLLIMA. The Treasury Department estimates these schemes generated approximately $800 million for Pyongyang in 2024 alone.
Infrastructure Compromise. Rather than exploiting code bugs, attackers in both the Drift and KelpDAO incidents compromised operational infrastructure — governance signers in Drift's case, and RPC node infrastructure in KelpDAO's.
The Drift Protocol exploit on Solana represents a textbook case of patient, human-driven infiltration. According to post-incident analysis by The Hacker News and Chainalysis, the attack was the culmination of a six-month social engineering operation that began in fall 2025.
Lazarus operatives built relationships with Drift team members over months, eventually manipulating Security Council members into pre-signing transactions using Solana's "durable nonces" feature. The pre-signed transactions unknowingly handed over administrative control of the protocol.
Once in control, attackers whitelisted a worthless, artificially priced token (CVT) as collateral. They deposited 500 million CVT and used it to withdraw $285 million in USDC, SOL, and ETH. The entire drain took approximately 12 minutes. TRM Labs attributed the theft to Lazarus Group.
The KelpDAO exploit targeted the protocol's LayerZero-powered cross-chain bridge. According to Halborn's post-mortem analysis, the root cause was a single-verifier (1-of-1) configuration for receiving cross-chain messages. Despite multi-verifier setups having been previously recommended across the industry, KelpDAO ran a single Data Verification Network (DVN) node.
Attackers compromised internal RPC nodes and DDoS'd external nodes, feeding false data to the bridge. A phantom token burn convinced the Ethereum contract to release 116,500 rsETH — approximately $292 million, representing roughly 18% of the token's circulating supply.
The theft triggered a cascade. According to CoinDesk reporting, major lending platforms including Aave, SparkLend, and Fluid froze their rsETH markets, and approximately $10 billion in withdrawals occurred across multiple lending protocols. LayerZero attributed the exploit to Lazarus Group's TraderTraitor subunit.
On July 31, 2026, eleven allied nations — the United States, Japan, South Korea, France, Germany, Italy, the Netherlands, and four others — issued a joint advisory warning that DPRK IT workers are using real-time AI deepfake video to impersonate candidates during live job interviews. According to the advisory, operatives use a deepfake model running live during video calls, mapping a stolen or synthetic face onto the operative's actual video feed through a virtual camera driver that conferencing platforms treat as a normal webcam.
The scale of operations is significant. Estimates cited in the advisory suggest approximately 100,000 North Korean workers across 40 countries earn the regime up to $500 million annually through IT worker fraud. Eight individuals were sentenced to prison in 2026 for roles in these schemes, according to reporting by the Seoul Economic Daily.
On March 12, 2026, OFAC sanctioned six individuals and two entities facilitating DPRK IT worker fraud, including 21 cryptocurrency addresses across multiple blockchains. According to Chainalysis analysis of the sanctions action, the designated networks operated across Vietnam, Laos, and Spain. One facilitator, Nguyen Quang Viet, converted approximately $2.5 million into cryptocurrency for the regime between mid-2023 and mid-2025, per Treasury Department filings.
The integration of deepfake technology with established IT worker fraud networks represents a tactical evolution. The objective is twofold: direct revenue from IT salaries, and privileged access to company systems that can later be exploited for larger thefts.
Moving stolen cryptocurrency out of the blockchain ecosystem and into usable funds remains the operational bottleneck for DPRK actors. The methods have evolved as law enforcement has shut down key infrastructure.
Mixer Usage. Lazarus has historically relied on mixing services to obscure transaction trails. After law enforcement takedowns of Blender.io and Sinbad.io, the group returned to Tornado Cash despite U.S. sanctions on the protocol, according to Elliptic research. The decentralized, smart-contract-based architecture of Tornado Cash makes it difficult to shut down through traditional enforcement actions, unlike centralized mixer services.
Chain-Hopping. Stolen funds are routinely moved across dozens of blockchains and through hundreds of intermediate wallets. In the KelpDAO case, wrapped ether was stranded across 20 chains following the exploit, according to CoinDesk reporting. This multi-chain dispersal complicates tracing and recovery efforts.
DeFi Protocols. Attackers use decentralized exchanges and lending protocols as additional laundering layers, swapping stolen tokens for more liquid assets before moving them through mixers or peer-to-peer networks.
Despite the sophistication of these methods, blockchain tracing has improved. Chainalysis and TRM Labs have both demonstrated the ability to attribute stolen funds to DPRK wallets within days or weeks of major exploits.
The enforcement landscape shifted in August 2026 when Bybit filed a civil lawsuit in the U.S. District Court for the District of Columbia against North Korea, its Reconnaissance General Bureau (RGB), and the Lazarus Group. On August 7, 2026, the court granted a preliminary injunction freezing identified stolen assets, finding that "Bybit has demonstrated a likelihood of success on the merits."
The lawsuit represents the first time a cryptocurrency exchange has directly sued a nation-state over a hack. The legal strategy combines blockchain intelligence, international cooperation, and judicial remedies. The practical recovery prospects remain uncertain — North Korea does not recognize U.S. court jurisdiction, and much of the stolen Ethereum has already been laundered through mixers and chain-hopping.
Other enforcement actions in 2026 include:
The enforcement gap remains wide. According to the UN Panel of Experts, cyber operations generate 40-50% of North Korea's foreign currency income, making them too valuable for the regime to abandon. Sanctions and prosecutions have targeted individual facilitators and laundering infrastructure, but the core operational capability — housed within the Reconnaissance General Bureau — remains intact.
The 2026 attack pattern has forced a reassessment of DeFi security assumptions. As reported by Crypto Economy, audits catch smart contract bugs but rarely stop six-month social engineering campaigns or cloud-key compromises. Both Drift and KelpDAO passed code audits. Both were compromised through operational failures.
Industry responses include:
The fundamental problem, however, is structural. DeFi protocols are built for permissionless composability, and administrative key management — the layer most vulnerable to social engineering — sits outside the auditable smart contract stack.
North Korea's cryptocurrency theft operations have reached a scale that places them among the most significant state-sponsored financial crime programs in history. The $6.75 billion cumulative total exceeds the GDP of several UN member states. The operations fund weapons programs that the international community has spent decades attempting to constrain through sanctions.
The shift from smart contract exploitation to social engineering and insider placement reflects both the maturation of the threat and the limitations of current defenses. Code audits, while necessary, are insufficient against attackers willing to spend six months building relationships with protocol team members. Multi-signature governance, while an improvement over single-key administration, can be subverted through social manipulation of signers.
The economic value at risk extends beyond the direct theft amounts. The KelpDAO exploit triggered $10 billion in lending protocol withdrawals — a 34-to-1 multiplier on the stolen funds. Bridge TVL stood at $21.94 billion as of March 2026, representing a concentrated attack surface for state-level adversaries.
For protocol designers, the implication is that security is no longer primarily a code problem. It is an organizational security problem, and the adversary has the resources and patience of a nation-state.