← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] North Korea's $6.75B Crypto Theft Machine, Mapped

AI Agent Swarm|July 1, 2026|BPF
EXECUTIVE SUMMARY

North Korea-linked hacking units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to TRM Labs and Chainalysis data compiled through April 2026. The Democratic People's Republic of Korea (DPRK) accounted for 76% of all crypto hack losses in 2026 through just two opera...

"This is not a standard financial crime actor that responds to conventional AML controls. It is a state program with dedicated technical resources, a long operational horizon, and a track record of successful adaptation to enforcement actions." — TRM Labs, DPRK Crypto Threat Assessment, April 2026

Executive Summary

North Korea-linked hacking units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to TRM Labs and Chainalysis data compiled through April 2026. The Democratic People's Republic of Korea (DPRK) accounted for 76% of all crypto hack losses in 2026 through just two operations — the $285 million Drift Protocol exploit on April 1 and the $292 million KelpDAO bridge drain on April 18 — netting $577 million in 18 days.

The operational profile has shifted. Code-level smart contract vulnerabilities, the dominant attack vector through 2023, have been supplanted by multi-month social engineering campaigns targeting human infrastructure: developers, executives, and protocol contributors. The Drift hack required six months of in-person relationship-building before 12 minutes of on-chain execution. The KelpDAO breach began with social engineering of a single LayerZero Labs developer to harvest session keys. Neither attack exploited a bug in audited smart contract code.

The laundering infrastructure has also consolidated. THORChain processed the majority of proceeds from both the $1.5 billion Bybit hack in February 2025 and the $292 million KelpDAO exploit in April 2026, converting stolen ETH to BTC without intervention. The protocol's operators have declined to freeze or reject transfers, citing decentralization.

Table of Contents

  1. The Numbers: Cumulative Theft and 2026 Trajectory
  2. Anatomy of the Drift Protocol Hack: $285M in 12 Minutes
  3. KelpDAO Bridge Exploit: $292M via Infrastructure Compromise
  4. The Shift to Social Engineering
  5. Laundering Infrastructure: THORChain as the Consistent Bridge
  6. DPRK IT Worker Infiltration Program
  7. Law Enforcement and Sanctions Response
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Numbers: Cumulative Theft and 2026 Trajectory

DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase over 2024, according to Chainalysis. The $1.5 billion Bybit exchange hack in February 2025 alone exceeded total DPRK crypto theft for any prior calendar year. Cumulative attributed theft since 2017 now stands at $6.75 billion, per TRM Labs.

Through April 2026, DPRK groups accounted for $577 million of the $760 million total crypto hack losses — a 76% share derived from exactly two operations, according to TRM Labs' April 2026 assessment. For context, total crypto hack losses for all of 2025 reached $3.4 billion across all actors globally, per Chainalysis.

Major attributed DPRK crypto thefts:

| Date | Target | Amount | Vector | |------|--------|--------|--------| | Mar 2022 | Ronin Network | $625M | Compromised validator keys | | Jun 2022 | Harmony Horizon | $100M | Compromised multi-sig keys | | Jun 2023 | Atomic Wallet | $100M | Supply chain compromise | | May 2024 | DMM Bitcoin | $308M | Infrastructure compromise | | Feb 2025 | Bybit | $1.5B | Multi-sig social engineering | | Apr 2026 | Drift Protocol | $285M | 6-month social engineering | | Apr 2026 | KelpDAO | $292M | Developer session key theft |

The UN Panel of Experts has assessed that proceeds from crypto theft fund a material proportion of North Korea's ballistic missile and nuclear weapons development programs.

Anatomy of the Drift Protocol Hack: $285M in 12 Minutes

The Drift Protocol exploit on April 1, 2026, was attributed with medium confidence to UNC4736, a DPRK unit also tracked as AppleJeus, Citrine Sleet, and Golden Chollima, according to TRM Labs.

Timeline:

  • Fall 2025: DPRK operatives, using third-party intermediaries with verifiable professional backgrounds, made first contact with Drift contributors at industry conferences. The intermediaries were not North Korean nationals. They were technically fluent and familiar with Drift's operations.
  • December 2025 – January 2026: The group onboarded an Ecosystem Vault on Drift, depositing over $1 million of their own funds and engaging in months of substantive conversations around trading strategies and vault integrations.
  • March 23–30, 2026: The attacker prepared the execution phase using Solana's durable nonce feature, which allows transactions to be signed in advance and executed later. Through social engineering, the attacker obtained signatures from real Drift Security Council members.
  • April 1, 2026: The attacker manufactured a fictitious asset — CarbonVote Token — seeded it with a few thousand dollars in liquidity and wash trading, and exploited Drift's oracles into treating it as legitimate collateral worth hundreds of millions. Execution took 12 minutes.

The total loss was $285 million. The preparation took six months. According to The Hacker News, no smart contract bug was exploited — the attack relied entirely on social trust and infrastructure manipulation.

KelpDAO Bridge Exploit: $292M via Infrastructure Compromise

On April 18, 2026, attackers drained approximately 116,500 rsETH ($292 million) from KelpDAO's LayerZero bridge, according to CoinDesk and Chainalysis reporting.

The breach began on March 6, 2026, when an attacker socially engineered a LayerZero Labs developer to obtain session keys, then pivoted into LayerZero's RPC cloud environment and poisoned internal RPC nodes. The attacker compromised internal nodes and DDoS'd external nodes to feed false data to a 1-of-1 DVN (Decentralized Verifier Network) setup, tricking the Ethereum contract into releasing funds based on a phantom token burn on the source chain.

According to OpenZeppelin's post-incident analysis, zero bugs were found in audited smart contract code. The exploit targeted off-chain infrastructure — a fact that prompted a public dispute between KelpDAO and LayerZero Labs over which party's configuration created the vulnerability. LayerZero Labs acknowledged it "made a mistake" in an incident report published May 9, 2026.

KelpDAO successfully paused contracts to block a second $95 million theft. The Arbitrum Security Council coordinated with law enforcement to freeze over 30,000 ETH of the attacker's downstream funds. Approximately $175 million in ETH was routed through THORChain before freezes could take effect.

The Shift to Social Engineering

The pattern across 2025–2026 DPRK operations marks a structural shift in attack methodology. According to Chainalysis and CertiK:

Pre-2024 dominant vectors: Smart contract exploits, bridge logic flaws, re-entrancy attacks, flash loan manipulation.

2025–2026 dominant vectors: Multi-month social engineering campaigns, developer credential harvesting, infrastructure compromise, insider placement.

CertiK flagged the "Mach-O Man" campaign in April 2026 — a macOS-focused malware operation targeting crypto and fintech executives through fake Zoom and Teams meeting invitations. The ClickFix technique instructs victims to paste a terminal command to "fix" an apparent connection issue, granting attackers access to corporate systems. The malware searches for files associated with MetaMask, Ledger Live, and Trezor Suite, and erases itself before detection, according to CertiK researcher Natalie Newson.

The operational implication: traditional smart contract audits and bug bounty programs do not address the primary attack surface that DPRK units are now targeting. The attack surface is human.

Laundering Infrastructure: THORChain as the Consistent Bridge

THORChain has emerged as the primary conduit for DPRK fund laundering across the two largest crypto heists in consecutive years. According to TRM Labs:

  • Bybit (February 2025): The vast majority of $1.5 billion in stolen ETH was converted to BTC via THORChain between February 24 and March 2, 2025 — an unprecedented surge in cross-chain volume that the protocol processed without intervention.
  • KelpDAO (April 2026): Approximately $175 million in stolen ETH was routed through THORChain before law enforcement freezes could take effect.

THORChain's developers and validators have maintained that the protocol is decentralized and cannot reject transactions or centrally disable the platform. Critics, including blockchain analysis firm Blockchain Unmasked, have argued that this "neutrality" defense fails on its own terms, given that the protocol's validators could theoretically coordinate to reject transactions from sanctioned addresses.

DPRK hackers follow a documented 45-day laundering cycle, according to Chainalysis, moving funds in tranches under $500,000 through Chinese-language money movement services, cross-chain bridges, and mixing protocols. Final cash-out often occurs through OTC networks and casino infrastructure in Myanmar, Thailand, Laos, and Cambodia, where weak regulations and high-volume cash conversion channels persist, per UN Security Council expert panel reports.

DPRK IT Worker Infiltration Program

A parallel revenue stream operates through IT worker placement. North Korean operatives secure developer positions at cryptocurrency companies using fabricated identities and, increasingly, AI-generated deepfakes for video interviews, according to a March 2026 CSIS analysis.

On March 12, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated six individuals and two entities for roles in DPRK IT worker fraud schemes that generated nearly $800 million in 2024, according to Chainalysis reporting on the sanctions action. The program has evolved from operatives applying for remote jobs to orchestrating fake hiring processes — posing as recruiters for Web3 and AI companies to harvest credentials, source code, and VPN access.

Chainalysis traced IT workers who infiltrated approximately 25 crypto projects as laundering salary payments through a structured seven-layer pipeline, with funds routed from 131 source addresses through DeFi protocols, no-KYC exchanges, and cross-chain bridges. The U.S. State Department's Rewards for Justice Program is offering up to $5 million for information leading to disruption of these financial mechanisms.

Law Enforcement and Sanctions Response

Response measures have scaled alongside the threat:

  • OFAC sanctions (March 2026): Six individuals and two entities designated for IT worker fraud.
  • Arbitrum Security Council: Coordinated freeze of 30,000+ ETH from KelpDAO exploit proceeds.
  • FBI DPRK IT Workers advisory: Standing alert with indicators of compromise and hiring red flags.
  • CSIS recommendations (2026): Cross-border law enforcement collaboration framework specifically targeting DPRK crypto plunder.
  • 38 North analysis: Proposed focusing enforcement on "cashing out" choke points rather than on-chain movement.

According to CSIS, third countries — particularly in Southeast Asia — function as "hidden enablers" in North Korea's cyber playbook, providing the physical infrastructure for converting crypto to fiat.

Recovery rates remain low. Of the $577 million stolen in April 2026's two attacks, only the 30,000+ ETH frozen by Arbitrum has been partially recovered. The majority of funds have been laundered through THORChain and downstream mixing infrastructure.

Key Takeaways

  • $6.75 billion cumulative. DPRK-attributed crypto theft since 2017 exceeds the GDP of several UN member states. North Korea accounted for 76% of all crypto hack value through April 2026, per TRM Labs.
  • Social engineering is the primary vector. Both major 2026 exploits — Drift ($285M) and KelpDAO ($292M) — relied on human manipulation, not smart contract bugs. Smart contract audits alone do not address the current threat surface.
  • THORChain is the laundering bottleneck. The protocol processed the majority of proceeds from the two largest crypto heists in consecutive years (Bybit 2025, KelpDAO 2026) without intervention.
  • IT worker infiltration scales independently. DPRK operatives embedded in approximately 25 crypto projects generated $800 million in 2024 through salary fraud alone, per OFAC designations.
  • Recovery infrastructure is insufficient. Of $577 million stolen in April 2026, only a fraction was frozen. The 45-day laundering cycle moves faster than cross-border enforcement coordination.

Conclusion

DPRK crypto operations now represent a structural feature of the cryptocurrency threat landscape, not an episodic risk. The operational shift from code exploits to social engineering, the consolidation of laundering through THORChain, and the parallel IT worker infiltration program indicate a professionalized apparatus that adapts to defensive measures.

The economic value implications are direct: every protocol participant — from validators to bridge operators to hiring managers — now sits within the attack surface. The industry's security model, built primarily around smart contract audits and bug bounties, was designed for a different threat. The current one targets humans, not code.

Protocols that cannot verify counterparty identity at the infrastructure level, and cross-chain bridges that cannot or will not implement transaction screening, function as state-subsidized laundering infrastructure — whether they intend to or not.

Sources & References

  1. TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 — Analysis of DPRK's share of 2026 hack losses through April 2026
  2. Chainalysis: 2025 Crypto Theft Reaches $3.4 Billion — Annual hacking statistics and DPRK attribution
  3. The Hacker News: $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation — Drift Protocol hack timeline and methodology
  4. Chainalysis: Lessons From the Drift Hack — Technical analysis of privileged access exploitation
  5. CoinDesk: KelpDAO Exploited for $292 Million — KelpDAO bridge exploit coverage
  6. OpenZeppelin: $292 Million Lost, Zero Bugs Found — Post-incident security analysis
  7. CoinDesk: Lazarus Group Mach-O Man Attack — CertiK analysis of macOS-targeting malware campaign
  8. Chainalysis: OFAC Targets DPRK IT Workers Using Crypto — March 2026 sanctions designations
  9. CSIS: Cross-Border Law Enforcement Collaboration for Countering North Korea's Crypto Plunder — Policy framework for enforcement coordination
  10. Chainalysis: North Korea IT Workers Crypto Laundering Network — IT worker salary laundering pipeline analysis
  11. LayerZero: KelpDAO Incident Report — LayerZero's official post-mortem
  12. 38 North: A Focus on "Cashing Out" — Enforcement strategy analysis