North Korea-linked hacking units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to TRM Labs and Chainalysis data compiled through April 2026. The Democratic People's Republic of Korea (DPRK) accounted for 76% of all crypto hack losses in 2026 through just two opera...
"This is not a standard financial crime actor that responds to conventional AML controls. It is a state program with dedicated technical resources, a long operational horizon, and a track record of successful adaptation to enforcement actions." — TRM Labs, DPRK Crypto Threat Assessment, April 2026
North Korea-linked hacking units have stolen an estimated $6.75 billion in cryptocurrency since 2017, according to TRM Labs and Chainalysis data compiled through April 2026. The Democratic People's Republic of Korea (DPRK) accounted for 76% of all crypto hack losses in 2026 through just two operations — the $285 million Drift Protocol exploit on April 1 and the $292 million KelpDAO bridge drain on April 18 — netting $577 million in 18 days.
The operational profile has shifted. Code-level smart contract vulnerabilities, the dominant attack vector through 2023, have been supplanted by multi-month social engineering campaigns targeting human infrastructure: developers, executives, and protocol contributors. The Drift hack required six months of in-person relationship-building before 12 minutes of on-chain execution. The KelpDAO breach began with social engineering of a single LayerZero Labs developer to harvest session keys. Neither attack exploited a bug in audited smart contract code.
The laundering infrastructure has also consolidated. THORChain processed the majority of proceeds from both the $1.5 billion Bybit hack in February 2025 and the $292 million KelpDAO exploit in April 2026, converting stolen ETH to BTC without intervention. The protocol's operators have declined to freeze or reject transfers, citing decentralization.
DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase over 2024, according to Chainalysis. The $1.5 billion Bybit exchange hack in February 2025 alone exceeded total DPRK crypto theft for any prior calendar year. Cumulative attributed theft since 2017 now stands at $6.75 billion, per TRM Labs.
Through April 2026, DPRK groups accounted for $577 million of the $760 million total crypto hack losses — a 76% share derived from exactly two operations, according to TRM Labs' April 2026 assessment. For context, total crypto hack losses for all of 2025 reached $3.4 billion across all actors globally, per Chainalysis.
Major attributed DPRK crypto thefts:
| Date | Target | Amount | Vector | |------|--------|--------|--------| | Mar 2022 | Ronin Network | $625M | Compromised validator keys | | Jun 2022 | Harmony Horizon | $100M | Compromised multi-sig keys | | Jun 2023 | Atomic Wallet | $100M | Supply chain compromise | | May 2024 | DMM Bitcoin | $308M | Infrastructure compromise | | Feb 2025 | Bybit | $1.5B | Multi-sig social engineering | | Apr 2026 | Drift Protocol | $285M | 6-month social engineering | | Apr 2026 | KelpDAO | $292M | Developer session key theft |
The UN Panel of Experts has assessed that proceeds from crypto theft fund a material proportion of North Korea's ballistic missile and nuclear weapons development programs.
The Drift Protocol exploit on April 1, 2026, was attributed with medium confidence to UNC4736, a DPRK unit also tracked as AppleJeus, Citrine Sleet, and Golden Chollima, according to TRM Labs.
Timeline:
The total loss was $285 million. The preparation took six months. According to The Hacker News, no smart contract bug was exploited — the attack relied entirely on social trust and infrastructure manipulation.
On April 18, 2026, attackers drained approximately 116,500 rsETH ($292 million) from KelpDAO's LayerZero bridge, according to CoinDesk and Chainalysis reporting.
The breach began on March 6, 2026, when an attacker socially engineered a LayerZero Labs developer to obtain session keys, then pivoted into LayerZero's RPC cloud environment and poisoned internal RPC nodes. The attacker compromised internal nodes and DDoS'd external nodes to feed false data to a 1-of-1 DVN (Decentralized Verifier Network) setup, tricking the Ethereum contract into releasing funds based on a phantom token burn on the source chain.
According to OpenZeppelin's post-incident analysis, zero bugs were found in audited smart contract code. The exploit targeted off-chain infrastructure — a fact that prompted a public dispute between KelpDAO and LayerZero Labs over which party's configuration created the vulnerability. LayerZero Labs acknowledged it "made a mistake" in an incident report published May 9, 2026.
KelpDAO successfully paused contracts to block a second $95 million theft. The Arbitrum Security Council coordinated with law enforcement to freeze over 30,000 ETH of the attacker's downstream funds. Approximately $175 million in ETH was routed through THORChain before freezes could take effect.
The pattern across 2025–2026 DPRK operations marks a structural shift in attack methodology. According to Chainalysis and CertiK:
Pre-2024 dominant vectors: Smart contract exploits, bridge logic flaws, re-entrancy attacks, flash loan manipulation.
2025–2026 dominant vectors: Multi-month social engineering campaigns, developer credential harvesting, infrastructure compromise, insider placement.
CertiK flagged the "Mach-O Man" campaign in April 2026 — a macOS-focused malware operation targeting crypto and fintech executives through fake Zoom and Teams meeting invitations. The ClickFix technique instructs victims to paste a terminal command to "fix" an apparent connection issue, granting attackers access to corporate systems. The malware searches for files associated with MetaMask, Ledger Live, and Trezor Suite, and erases itself before detection, according to CertiK researcher Natalie Newson.
The operational implication: traditional smart contract audits and bug bounty programs do not address the primary attack surface that DPRK units are now targeting. The attack surface is human.
THORChain has emerged as the primary conduit for DPRK fund laundering across the two largest crypto heists in consecutive years. According to TRM Labs:
THORChain's developers and validators have maintained that the protocol is decentralized and cannot reject transactions or centrally disable the platform. Critics, including blockchain analysis firm Blockchain Unmasked, have argued that this "neutrality" defense fails on its own terms, given that the protocol's validators could theoretically coordinate to reject transactions from sanctioned addresses.
DPRK hackers follow a documented 45-day laundering cycle, according to Chainalysis, moving funds in tranches under $500,000 through Chinese-language money movement services, cross-chain bridges, and mixing protocols. Final cash-out often occurs through OTC networks and casino infrastructure in Myanmar, Thailand, Laos, and Cambodia, where weak regulations and high-volume cash conversion channels persist, per UN Security Council expert panel reports.
A parallel revenue stream operates through IT worker placement. North Korean operatives secure developer positions at cryptocurrency companies using fabricated identities and, increasingly, AI-generated deepfakes for video interviews, according to a March 2026 CSIS analysis.
On March 12, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated six individuals and two entities for roles in DPRK IT worker fraud schemes that generated nearly $800 million in 2024, according to Chainalysis reporting on the sanctions action. The program has evolved from operatives applying for remote jobs to orchestrating fake hiring processes — posing as recruiters for Web3 and AI companies to harvest credentials, source code, and VPN access.
Chainalysis traced IT workers who infiltrated approximately 25 crypto projects as laundering salary payments through a structured seven-layer pipeline, with funds routed from 131 source addresses through DeFi protocols, no-KYC exchanges, and cross-chain bridges. The U.S. State Department's Rewards for Justice Program is offering up to $5 million for information leading to disruption of these financial mechanisms.
Response measures have scaled alongside the threat:
According to CSIS, third countries — particularly in Southeast Asia — function as "hidden enablers" in North Korea's cyber playbook, providing the physical infrastructure for converting crypto to fiat.
Recovery rates remain low. Of the $577 million stolen in April 2026's two attacks, only the 30,000+ ETH frozen by Arbitrum has been partially recovered. The majority of funds have been laundered through THORChain and downstream mixing infrastructure.
DPRK crypto operations now represent a structural feature of the cryptocurrency threat landscape, not an episodic risk. The operational shift from code exploits to social engineering, the consolidation of laundering through THORChain, and the parallel IT worker infiltration program indicate a professionalized apparatus that adapts to defensive measures.
The economic value implications are direct: every protocol participant — from validators to bridge operators to hiring managers — now sits within the attack surface. The industry's security model, built primarily around smart contract audits and bug bounties, was designed for a different threat. The current one targets humans, not code.
Protocols that cannot verify counterparty identity at the infrastructure level, and cross-chain bridges that cannot or will not implement transaction screening, function as state-subsidized laundering infrastructure — whether they intend to or not.