April 2026 recorded the highest monthly crypto exploit total in the industry's history: $629 million stolen across 29 separate incidents, according to data compiled by CryptoTimes and IndexBox. Two attacks — both attributed to North Korea's Lazarus Group — accounted for 95% of the dollar value lo...
"What we are watching is not a North Korean campaign that is broader — it is one that is sharper. North Korea is moving faster and more precisely than ever." — Ari Redbord, Global Head of Policy and Government Affairs, TRM Labs
April 2026 recorded the highest monthly crypto exploit total in the industry's history: $629 million stolen across 29 separate incidents, according to data compiled by CryptoTimes and IndexBox. Two attacks — both attributed to North Korea's Lazarus Group — accounted for 95% of the dollar value lost. The Drift Protocol breach on April 1 drained $285 million from the Solana-based perpetual futures exchange; the KelpDAO bridge exploit on April 18 extracted $292 million in rsETH across 20 chains via a compromised LayerZero verification layer.
The fallout was immediate and structural. DeFi total value locked fell $13.2 billion in 48 hours, from $99.5 billion to $86.3 billion, according to CoinDesk. Aave alone shed $6.6 billion in deposits. Nine protocols froze rsETH markets. The month pushed 2026 year-to-date hack losses past $760 million, with TRM Labs reporting that North Korean actors now account for 76% of all crypto theft value this year — the highest sustained share on record.
Both exploits targeted off-chain infrastructure rather than smart contract logic. Neither involved a code vulnerability in the traditional sense. Both exploited human and operational layers surrounding audited contracts — a pattern that suggests the industry's security model remains structurally misaligned with its actual threat surface.
| Metric | Value | Source | |--------|-------|--------| | Total stolen (April) | $629M | CryptoTimes | | Number of incidents | 29 | Crowdfund Insider | | Largest single exploit | $292M (KelpDAO) | CoinDesk | | Second-largest exploit | $285M (Drift) | Bloomberg | | North Korea share of 2026 losses | 76% | TRM Labs | | Cumulative NK theft since 2017 | $6B+ | The Block / TRM Labs | | DeFi TVL drop (48 hours post-KelpDAO) | $13.2B | CoinDesk | | Aave deposit outflows | $6.6B | Unchained Crypto | | Protocols that froze rsETH markets | 9 | CoinDesk | | 2026 YTD hack losses | ~$760M | IndexBox |
April averaged nearly one attack per day. DeFi protocols accounted for $614 million of the total — 97.6% of the month's losses. Centralized exchange breaches were negligible by comparison.
On April 1, attackers drained $285 million from Drift Protocol, the largest decentralized perpetual futures exchange on Solana. The breach represented over 50% of Drift's total value locked and stands as the second-largest exploit in Solana's history, behind the $326 million Wormhole bridge hack in 2022.
According to Chainalysis and TRM Labs, the operation began in fall 2025. Lazarus operatives posed as a quantitative trading firm, building trust with Drift contributors over months — including in-person meetings. TRM Labs' Ari Redbord described this as "unprecedented in North Korea's crypto hacking campaign," adding: "This is no longer just a remote keyboard operation."
The technical execution exploited Solana's "durable nonces" system — a feature allowing transactions to be pre-signed for later execution. Attackers tricked Security Council members into blindly pre-signing dormant transactions that, when triggered, transferred admin control to attacker-controlled wallets.
Once in control, the attackers deployed a fabricated token — CarbonVote Token (CVT) — created on March 12 with 750 million tokens. They seeded a Raydium liquidity pool, wash-traded CVT to anchor its price at approximately $1, and deployed a controlled price oracle to feed that artificial price to Drift. With admin access, they modified Drift's parameters to accept CVT as collateral with infinite borrowing limits. The $285 million in user assets — USDC, SOL, JLP, WBTC, and others — was drained in approximately 12 minutes, with most funds bridged to Ethereum within hours.
Attribution was assigned with medium confidence to UNC4736, a North Korean state-sponsored group also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces. A class action lawsuit was filed on April 15 by Gibbs Mura, a law firm, on behalf of affected depositors.
On April 18, 116,500 rsETH — approximately 18% of the token's circulating supply — was extracted from KelpDAO's LayerZero bridge. Chainalysis confirmed Lazarus Group attribution within three days, matching mixer usage patterns and fund-dispersal methodology to the group's known operational fingerprint.
The root cause was a 1-of-1 verifier configuration. When receiving cross-chain messages via LayerZero, a single node was responsible for validating transactions before releasing funds. Attackers compromised two RPC nodes that served as data sources for this verifier, then launched a simultaneous DDoS attack against external fallback nodes. The verifier, forced onto poisoned data sources, approved a fraudulent instruction releasing the full 116,500 rsETH to an attacker-controlled address.
This was not a smart contract vulnerability. The audited code performed as designed. The failure occurred entirely in the off-chain infrastructure supporting the bridge's verification layer.
A blame dispute followed immediately. LayerZero attributed the failure to KelpDAO's single-verifier setup. KelpDAO countered that LayerZero's default configuration uses the same architecture, and that approximately 40% of protocols on LayerZero operate with identical single-verifier exposure, according to CoinDesk reporting.
The KelpDAO exploit's impact extended far beyond the $292 million in directly stolen assets. The attacker deposited 89,567 rsETH into Aave as collateral and borrowed $190.86 million in wrapped Ether against it. Aave's pricing oracle continued to value rsETH at its pre-exploit rate, allowing the attacker to extract real value against unbacked collateral.
By the time Aave froze rsETH markets, $190 million in real Ether had been borrowed against tokens that no longer had backing. Aave's incident report estimated potential losses between $123 million (if damage is shared across all rsETH holders) and $230 million (if losses are confined to Layer 2 positions).
The cascade unfolded across nine protocols in 48 hours:
Total DeFi TVL fell from $99.5 billion to $86.3 billion. According to CoinDesk, much of the decline was leveraged positions unwinding rather than capital destruction, but the distinction offered limited comfort to depositors who could not access frozen funds.
TRM Labs' April 2026 report documented a structural shift in North Korean crypto operations. The data is unambiguous:
| Year | NK Share of Global Crypto Hack Losses | |------|---------------------------------------| | 2020-2021 | <10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 (through April) | 76% |
Cumulative North Korean-attributed crypto theft exceeds $6 billion since 2017, according to TRM Labs and The Block. The $1.46 billion Bybit breach in 2025 marked an inflection point. Since that event, the operational cadence has shifted toward fewer but higher-impact attacks targeting bridges, multisig governance systems, and cross-chain infrastructure.
The April 2026 attacks introduced a new dimension: sustained physical-proximity social engineering. The Drift operation involved North Korean proxies attending in-person meetings with protocol employees for months. TRM Labs identified this as the first confirmed instance of DPRK operatives conducting face-to-face espionage to facilitate a crypto theft.
The two April attacks alone — $285 million (Drift) and $292 million (KelpDAO) — totaled $577 million, representing 76% of all 2026 crypto hack losses through April.
Cross-chain bridges have produced the largest single-day losses in crypto history since 2022. Cumulative bridge-related theft exceeds $2.8 billion, representing approximately 40% of all value hacked in Web3, according to Phemex and Chainalysis data.
Major bridge exploits by year:
The failure modes have not changed. The 2022 Ronin bridge hack exploited compromised validator keys. The 2026 KelpDAO hack exploited compromised RPC nodes feeding a single verifier. The underlying vulnerability — insufficient redundancy in verification infrastructure — remains the same. Attackers are not discovering new vulnerability classes; they are executing established attack patterns at increasing scale because bridge TVL continues to grow.
CoinDesk analysis noted that bridge infrastructure has produced two of the three largest DeFi exploits in 2026, and called bridges "still one of the industry's weakest links."
When examined through the lens of economic value distribution, the April 2026 hack crisis reveals a cost layer that rarely appears in standard ecosystem analyses. The $629 million stolen in April represents approximately 4.6% of the blockchain sector's estimated $13.7 billion in annual on-chain revenue. A single month's theft equated to nearly a month's worth of the entire industry's legitimate fee income.
These losses are not borne uniformly. Individual depositors in Aave's rsETH markets face potential losses of $123-230 million — value extracted from their deposits by an attacker who exploited infrastructure they had no visibility into or control over. The economic flow from user deposits to state-sponsored theft represents a value transfer that is functionally invisible to users at the time of deposit.
The $13.2 billion TVL decline following the KelpDAO exploit also highlights the fragility of leverage-dependent composability. When one protocol's collateral token loses its backing, the cascading liquidation and withdrawal pressure reveals how tightly interconnected DeFi's value flows are — and how much of that value depends on assumptions about infrastructure security that the industry has not adequately stress-tested.
The data from April 2026 presents a straightforward conclusion: the crypto industry's security model is misaligned with its threat environment. Billions of dollars in smart contract audits have not prevented the two largest exploits of the year, because those exploits occurred outside the audited code layer entirely.
North Korea's Lazarus Group has demonstrated that social engineering and infrastructure compromise yield higher returns than code exploitation. The progressive increase in DPRK's share of global crypto theft — from under 10% in 2020 to 76% in 2026 — reflects a sustained, adaptive adversary operating against an industry that has not correspondingly adapted its defenses.
Bridge infrastructure continues to concentrate risk. The architectural pattern — large pools of locked value protected by minimal verification redundancy — creates attack surfaces that rational adversaries will continue to target. Until the industry invests in off-chain infrastructure security with the same rigor it applies to on-chain code auditing, the frequency and scale of these incidents is unlikely to decline.
The $629 million lost in April 2026 is not an anomaly. It is a data point on a trendline.