DPRK-linked threat actors have stolen an estimated $613 million in cryptocurrency through the first half of 2026, according to data compiled from TRM Labs, Chainalysis, and Quantstamp. Two operations — the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on...
"North Korean hackers accounted for 76% of all crypto hack value in 2026 — with just two attacks." — Ari Redbord, Global Head of Policy, TRM Labs
DPRK-linked threat actors have stolen an estimated $613 million in cryptocurrency through the first half of 2026, according to data compiled from TRM Labs, Chainalysis, and Quantstamp. Two operations — the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on April 18 — account for 76% of all crypto hack losses through April, per TRM Labs. A third incident, the $36 million Humanity Protocol breach on June 8, has since been attributed to suspected North Korean actors by Quantstamp.
The figures extend a five-year acceleration: North Korea's share of global crypto theft has climbed from 22% in 2022 to 37% in 2023, 39% in 2024, 64% in 2025, and 76% through April 2026. Cumulative DPRK-linked crypto theft since 2017 now exceeds $6 billion, according to TRM Labs. The U.S. Treasury sanctioned six individuals and two companies in March 2026 for laundering approximately $800 million on Pyongyang's behalf — a measure that has not visibly slowed the pace of attacks.
Total crypto hack losses in 2026 through June exceed $840 million across more than 60 incidents, according to aggregated data from PeckShield and Altfins. North Korean actors are responsible for $613 million of that total — roughly 73% — across just three confirmed or suspected incidents.
| Date | Target | Amount | Attack Vector | Attribution | |------|--------|--------|---------------|-------------| | April 1 | Drift Protocol (Solana) | $285M | Social engineering of multisig signers | DPRK / UNC4736 (confirmed) | | April 18 | KelpDAO (LayerZero bridge) | $292M | RPC node compromise + single verifier exploit | DPRK / Lazarus Group (confirmed) | | June 8 | Humanity Protocol (ETH/BNB) | $36M | Phishing + multisig key theft from single laptop | DPRK (suspected, per Quantstamp) |
April 2026 alone saw $629.69 million drained from crypto protocols — the single worst month in the history of crypto hacking, driven almost entirely by the two DPRK operations. These two attacks represented only 3% of total hack incidents through April, but 76% of the value stolen.
The Drift Protocol breach is the most operationally sophisticated crypto heist attributed to a state actor. According to TRM Labs' post-incident analysis, the attack began in the fall of 2025 when operatives from DPRK unit UNC4736 approached Drift team members at a major crypto conference, posing as a quantitative trading firm.
The operatives met Drift staff face-to-face at conferences across multiple countries over a six-month period. They built professional relationships, exchanged communications, and gradually established trust. The social engineering campaign was not conducted remotely — it was a sustained, in-person infiltration.
The technical execution, when it came on April 1, took approximately 12 minutes. According to Chainalysis and The Hacker News, attackers socially engineered multisig signers into pre-signing hidden authorizations and exploited a zero-timelock Security Council migration to eliminate the protocol's last line of defense. No smart contract vulnerability was exploited. The $285 million was drained through governance manipulation — the system functioned exactly as designed, but its human operators had been compromised.
Drift Protocol is the largest exploit in Solana's history after the $326 million Wormhole bridge hack in 2022.
Seventeen days later, on April 18, the Lazarus Group executed a fundamentally different attack against KelpDAO's rsETH bridge, built on LayerZero infrastructure. According to LayerZero's post-mortem published via The Defiant, the attack targeted off-chain infrastructure rather than smart contracts or human operators.
The attackers compromised two RPC nodes that fed data to KelpDAO's sole DVN (Decentralized Verifier Network) instance. They deployed malware that fed false transaction data exclusively to LayerZero's verifier while maintaining honest responses to all monitoring systems — a man-in-the-middle attack on oracle infrastructure. Simultaneously, they launched a DDoS attack against legitimate RPC endpoints, forcing the verifier to rely entirely on the poisoned nodes.
Once the verifier signed off on a fabricated transaction, the bridge released $292 million in unbacked rsETH. The malware then self-destructed and deleted all traces.
LayerZero Labs noted that KelpDAO was using a 1-of-1 DVN setup — a single point of failure that LayerZero had "repeatedly warned against." The incident was contained to KelpDAO; no other LayerZero-connected application was affected. LayerZero subsequently announced it would stop approving messages for any application still running a single-verifier configuration.
Arbitrum's Security Council froze approximately $75 million of stolen funds on its chain. The remaining $217 million was moved through THORChain within days.
The June 8 breach of Humanity Protocol — the palm-scanning identity project sometimes described as "Chinese Worldcoin" — demonstrated a simpler but equally effective attack pattern. According to Quantstamp's investigation and CoinDesk's reporting, a single phishing email disguised as a token lockup schedule update from South Korean exchange Bithumb delivered malware to an employee's laptop.
The malware was signed with a South Korean Hancom digital certificate, a tactic Quantstamp described as "characteristic of DPRK intrusions." It installed spyware granting full remote access to the device, which contained private keys for multiple multisig wallets. Three of six Ethereum keys and three of five BNB Chain keys were stored on the same laptop — a catastrophic operational security failure.
The attackers used the compromised keys to upgrade bridge contracts to a malicious implementation, draining 141 million H tokens on Ethereum. The H token collapsed approximately 85-90% within hours. Humanity Protocol initiated a token swap on June 17.
Total estimated losses: $32-36 million. The attack required one email and access to one device.
DPRK-linked actors follow a well-documented laundering pattern, according to Chainalysis and TRM Labs. The pipeline has evolved since 2022:
2022-2023: Tornado Cash served as the primary mixing tool. After the U.S. Treasury sanctioned Tornado Cash in August 2022, operators briefly shifted to Sinbad.io.
2024-2025: THORChain emerged as the primary cross-chain laundering venue. In the $1.5 billion Bybit hack of February 2025, the vast majority of stolen ETH was converted to BTC via THORChain within a six-day window. THORChain processed these swaps without restriction; the protocol has no compliance layer or ability to freeze transactions by design.
2026: The KelpDAO attackers converted approximately $175 million in stolen ETH to Bitcoin through THORChain after Arbitrum froze $75 million. The pattern is consistent: convert stolen tokens to ETH, bridge to THORChain, swap to BTC, distribute across wallets, hold for months or years, then execute structured cashouts through OTC desks and high-risk exchanges.
North Korean actors held $2.02 billion in stolen crypto through 2025, per TRM Labs — a 51% year-over-year increase. Cumulative holdings are growing faster than enforcement can freeze them. Fund recovery rates across all crypto hacks dropped from 21.2% in Q1 2024 to 0.4% in Q1 2025, according to Immunefi data.
The U.S. government has responded with sanctions and attribution, but the deterrent effect remains unclear.
March 2026: The U.S. Treasury's OFAC sanctioned six individuals and two companies for laundering approximately $800 million in cryptocurrency for North Korea. The network operated across Vietnam, Laos, and Spain. The designation included 21 crypto wallet addresses across Ethereum, Tron, and Bitcoin.
November 2025: OFAC listed 53 crypto addresses belonging to sanctioned North Korean bank Cheil Credit Bank.
March 2025: The U.S. lifted sanctions on Tornado Cash following a court ruling, removing one enforcement tool from the toolkit.
The core challenge is structural. DPRK hackers do not operate within jurisdictions that cooperate with U.S. law enforcement. Decentralized protocols like THORChain cannot freeze assets by design. Stablecoin issuers (Tether, Circle) can freeze USDT and USDC on specific addresses, but attackers convert to native assets (ETH, BTC) within hours of a breach. The T3 Financial Crimes Unit — a joint initiative of Tron, Tether, TRM Labs, and Binance — has frozen $250 million globally, but this represents a fraction of total stolen volume.
Code vulnerabilities accounted for 66% of all crypto hack incidents in 2026. But the three largest DPRK attacks did not exploit code bugs. They exploited people, infrastructure configurations, and operational security failures.
The 2026 data reveals a shift in North Korean attack methodology that carries implications for DeFi protocol design:
From code to people. The Drift hack required no smart contract exploit. It targeted human trust. Compromised accounts now account for more than 50% of all DeFi attack value, overtaking traditional code exploits for the first time.
From contracts to infrastructure. The KelpDAO attack targeted RPC nodes and verifier networks — off-chain infrastructure that most security audits do not cover. Smart contract audits, the industry's primary defense mechanism, would not have prevented this breach.
From sophisticated to simple. The Humanity Protocol hack required one phishing email and one laptop. The multisig design was rendered irrelevant because multiple keys were stored on a single device.
Bridges remain the highest-risk category. Fourteen bridge exploits in 2026 drained $340.7 million. Since 2022, bridges have produced more than $2.8 billion in cumulative losses — approximately 40% of all value ever hacked in Web3, per Spaziocrypto and 1inch analysis.
North Korea's crypto theft apparatus has reached a scale where it constitutes a systemic risk to decentralized finance infrastructure. The $613 million stolen in the first half of 2026 reflects not just the sophistication of the attackers but the structural vulnerabilities of the systems they target: multisig wallets with centralized key storage, bridge protocols with single-verifier configurations, and governance systems with zero timelocks.
The economic value extracted by DPRK actors is not recycled into the crypto ecosystem. It exits permanently — converted to fiat, routed through OTC desks, and directed toward weapons programs. For protocols and their users, these losses are unrecoverable. The 0.4% fund recovery rate in Q1 2025 suggests that the industry's post-hack response capabilities are deteriorating, not improving.
The data indicates that smart contract audits, while necessary, are insufficient as a primary defense. The three largest crypto hacks of 2026 were social engineering, infrastructure compromise, and phishing attacks — categories that fall outside the scope of code review. Protocol security now requires operational security standards for key management, infrastructure redundancy requirements for bridges, and human-layer defenses that the industry has largely failed to develop.