← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] DPRK Actors Take $613M in Three Crypto Heists

Zephyra|June 18, 2026|BPF
EXECUTIVE SUMMARY

DPRK-linked threat actors have stolen an estimated $613 million in cryptocurrency through the first half of 2026, according to data compiled from TRM Labs, Chainalysis, and Quantstamp. Two operations — the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on...

"North Korean hackers accounted for 76% of all crypto hack value in 2026 — with just two attacks." — Ari Redbord, Global Head of Policy, TRM Labs

Executive Summary

DPRK-linked threat actors have stolen an estimated $613 million in cryptocurrency through the first half of 2026, according to data compiled from TRM Labs, Chainalysis, and Quantstamp. Two operations — the $285 million Drift Protocol drain on April 1 and the $292 million KelpDAO bridge exploit on April 18 — account for 76% of all crypto hack losses through April, per TRM Labs. A third incident, the $36 million Humanity Protocol breach on June 8, has since been attributed to suspected North Korean actors by Quantstamp.

The figures extend a five-year acceleration: North Korea's share of global crypto theft has climbed from 22% in 2022 to 37% in 2023, 39% in 2024, 64% in 2025, and 76% through April 2026. Cumulative DPRK-linked crypto theft since 2017 now exceeds $6 billion, according to TRM Labs. The U.S. Treasury sanctioned six individuals and two companies in March 2026 for laundering approximately $800 million on Pyongyang's behalf — a measure that has not visibly slowed the pace of attacks.

Table of Contents

  1. 2026 Attack Timeline
  2. Drift Protocol: Six Months of Social Engineering
  3. KelpDAO: Infrastructure Attack on a Single Verifier
  4. Humanity Protocol: One Laptop, One Phishing Email
  5. Laundering Infrastructure: The THORChain Pipeline
  6. Enforcement Response and Its Limits
  7. Systemic Risk to DeFi Infrastructure
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

2026 Attack Timeline

Total crypto hack losses in 2026 through June exceed $840 million across more than 60 incidents, according to aggregated data from PeckShield and Altfins. North Korean actors are responsible for $613 million of that total — roughly 73% — across just three confirmed or suspected incidents.

| Date | Target | Amount | Attack Vector | Attribution | |------|--------|--------|---------------|-------------| | April 1 | Drift Protocol (Solana) | $285M | Social engineering of multisig signers | DPRK / UNC4736 (confirmed) | | April 18 | KelpDAO (LayerZero bridge) | $292M | RPC node compromise + single verifier exploit | DPRK / Lazarus Group (confirmed) | | June 8 | Humanity Protocol (ETH/BNB) | $36M | Phishing + multisig key theft from single laptop | DPRK (suspected, per Quantstamp) |

April 2026 alone saw $629.69 million drained from crypto protocols — the single worst month in the history of crypto hacking, driven almost entirely by the two DPRK operations. These two attacks represented only 3% of total hack incidents through April, but 76% of the value stolen.

Drift Protocol: Six Months of Social Engineering

The Drift Protocol breach is the most operationally sophisticated crypto heist attributed to a state actor. According to TRM Labs' post-incident analysis, the attack began in the fall of 2025 when operatives from DPRK unit UNC4736 approached Drift team members at a major crypto conference, posing as a quantitative trading firm.

The operatives met Drift staff face-to-face at conferences across multiple countries over a six-month period. They built professional relationships, exchanged communications, and gradually established trust. The social engineering campaign was not conducted remotely — it was a sustained, in-person infiltration.

The technical execution, when it came on April 1, took approximately 12 minutes. According to Chainalysis and The Hacker News, attackers socially engineered multisig signers into pre-signing hidden authorizations and exploited a zero-timelock Security Council migration to eliminate the protocol's last line of defense. No smart contract vulnerability was exploited. The $285 million was drained through governance manipulation — the system functioned exactly as designed, but its human operators had been compromised.

Drift Protocol is the largest exploit in Solana's history after the $326 million Wormhole bridge hack in 2022.

KelpDAO: Infrastructure Attack on a Single Verifier

Seventeen days later, on April 18, the Lazarus Group executed a fundamentally different attack against KelpDAO's rsETH bridge, built on LayerZero infrastructure. According to LayerZero's post-mortem published via The Defiant, the attack targeted off-chain infrastructure rather than smart contracts or human operators.

The attackers compromised two RPC nodes that fed data to KelpDAO's sole DVN (Decentralized Verifier Network) instance. They deployed malware that fed false transaction data exclusively to LayerZero's verifier while maintaining honest responses to all monitoring systems — a man-in-the-middle attack on oracle infrastructure. Simultaneously, they launched a DDoS attack against legitimate RPC endpoints, forcing the verifier to rely entirely on the poisoned nodes.

Once the verifier signed off on a fabricated transaction, the bridge released $292 million in unbacked rsETH. The malware then self-destructed and deleted all traces.

LayerZero Labs noted that KelpDAO was using a 1-of-1 DVN setup — a single point of failure that LayerZero had "repeatedly warned against." The incident was contained to KelpDAO; no other LayerZero-connected application was affected. LayerZero subsequently announced it would stop approving messages for any application still running a single-verifier configuration.

Arbitrum's Security Council froze approximately $75 million of stolen funds on its chain. The remaining $217 million was moved through THORChain within days.

Humanity Protocol: One Laptop, One Phishing Email

The June 8 breach of Humanity Protocol — the palm-scanning identity project sometimes described as "Chinese Worldcoin" — demonstrated a simpler but equally effective attack pattern. According to Quantstamp's investigation and CoinDesk's reporting, a single phishing email disguised as a token lockup schedule update from South Korean exchange Bithumb delivered malware to an employee's laptop.

The malware was signed with a South Korean Hancom digital certificate, a tactic Quantstamp described as "characteristic of DPRK intrusions." It installed spyware granting full remote access to the device, which contained private keys for multiple multisig wallets. Three of six Ethereum keys and three of five BNB Chain keys were stored on the same laptop — a catastrophic operational security failure.

The attackers used the compromised keys to upgrade bridge contracts to a malicious implementation, draining 141 million H tokens on Ethereum. The H token collapsed approximately 85-90% within hours. Humanity Protocol initiated a token swap on June 17.

Total estimated losses: $32-36 million. The attack required one email and access to one device.

Laundering Infrastructure: The THORChain Pipeline

DPRK-linked actors follow a well-documented laundering pattern, according to Chainalysis and TRM Labs. The pipeline has evolved since 2022:

2022-2023: Tornado Cash served as the primary mixing tool. After the U.S. Treasury sanctioned Tornado Cash in August 2022, operators briefly shifted to Sinbad.io.

2024-2025: THORChain emerged as the primary cross-chain laundering venue. In the $1.5 billion Bybit hack of February 2025, the vast majority of stolen ETH was converted to BTC via THORChain within a six-day window. THORChain processed these swaps without restriction; the protocol has no compliance layer or ability to freeze transactions by design.

2026: The KelpDAO attackers converted approximately $175 million in stolen ETH to Bitcoin through THORChain after Arbitrum froze $75 million. The pattern is consistent: convert stolen tokens to ETH, bridge to THORChain, swap to BTC, distribute across wallets, hold for months or years, then execute structured cashouts through OTC desks and high-risk exchanges.

North Korean actors held $2.02 billion in stolen crypto through 2025, per TRM Labs — a 51% year-over-year increase. Cumulative holdings are growing faster than enforcement can freeze them. Fund recovery rates across all crypto hacks dropped from 21.2% in Q1 2024 to 0.4% in Q1 2025, according to Immunefi data.

Enforcement Response and Its Limits

The U.S. government has responded with sanctions and attribution, but the deterrent effect remains unclear.

March 2026: The U.S. Treasury's OFAC sanctioned six individuals and two companies for laundering approximately $800 million in cryptocurrency for North Korea. The network operated across Vietnam, Laos, and Spain. The designation included 21 crypto wallet addresses across Ethereum, Tron, and Bitcoin.

November 2025: OFAC listed 53 crypto addresses belonging to sanctioned North Korean bank Cheil Credit Bank.

March 2025: The U.S. lifted sanctions on Tornado Cash following a court ruling, removing one enforcement tool from the toolkit.

The core challenge is structural. DPRK hackers do not operate within jurisdictions that cooperate with U.S. law enforcement. Decentralized protocols like THORChain cannot freeze assets by design. Stablecoin issuers (Tether, Circle) can freeze USDT and USDC on specific addresses, but attackers convert to native assets (ETH, BTC) within hours of a breach. The T3 Financial Crimes Unit — a joint initiative of Tron, Tether, TRM Labs, and Binance — has frozen $250 million globally, but this represents a fraction of total stolen volume.

Code vulnerabilities accounted for 66% of all crypto hack incidents in 2026. But the three largest DPRK attacks did not exploit code bugs. They exploited people, infrastructure configurations, and operational security failures.

Systemic Risk to DeFi Infrastructure

The 2026 data reveals a shift in North Korean attack methodology that carries implications for DeFi protocol design:

From code to people. The Drift hack required no smart contract exploit. It targeted human trust. Compromised accounts now account for more than 50% of all DeFi attack value, overtaking traditional code exploits for the first time.

From contracts to infrastructure. The KelpDAO attack targeted RPC nodes and verifier networks — off-chain infrastructure that most security audits do not cover. Smart contract audits, the industry's primary defense mechanism, would not have prevented this breach.

From sophisticated to simple. The Humanity Protocol hack required one phishing email and one laptop. The multisig design was rendered irrelevant because multiple keys were stored on a single device.

Bridges remain the highest-risk category. Fourteen bridge exploits in 2026 drained $340.7 million. Since 2022, bridges have produced more than $2.8 billion in cumulative losses — approximately 40% of all value ever hacked in Web3, per Spaziocrypto and 1inch analysis.

Key Takeaways

  • DPRK-linked actors have stolen an estimated $613 million in crypto in 2026 across three incidents, representing approximately 73% of all hack losses year-to-date.
  • Cumulative DPRK crypto theft since 2017 now exceeds $6 billion, per TRM Labs. North Korea's share of global crypto hack value has risen from 22% (2022) to 76% (2026 through April).
  • None of the three major 2026 DPRK attacks exploited smart contract bugs. All three targeted human operators, off-chain infrastructure, or operational security failures.
  • THORChain remains the primary laundering venue for state-sponsored hackers. The protocol processed over $175 million in stolen KelpDAO funds without restriction.
  • Fund recovery rates have collapsed: from 21.2% in Q1 2024 to 0.4% in Q1 2025, per Immunefi. Enforcement actions have not kept pace with attack volume.
  • April 2026 was the worst single month for crypto hacking in history, with $629.69 million in losses driven almost entirely by two DPRK operations.

Conclusion

North Korea's crypto theft apparatus has reached a scale where it constitutes a systemic risk to decentralized finance infrastructure. The $613 million stolen in the first half of 2026 reflects not just the sophistication of the attackers but the structural vulnerabilities of the systems they target: multisig wallets with centralized key storage, bridge protocols with single-verifier configurations, and governance systems with zero timelocks.

The economic value extracted by DPRK actors is not recycled into the crypto ecosystem. It exits permanently — converted to fiat, routed through OTC desks, and directed toward weapons programs. For protocols and their users, these losses are unrecoverable. The 0.4% fund recovery rate in Q1 2025 suggests that the industry's post-hack response capabilities are deteriorating, not improving.

The data indicates that smart contract audits, while necessary, are insufficient as a primary defense. The three largest crypto hacks of 2026 were social engineering, infrastructure compromise, and phishing attacks — categories that fall outside the scope of code review. Protocol security now requires operational security standards for key management, infrastructure redundancy requirements for bridges, and human-layer defenses that the industry has largely failed to develop.

Sources & References

  1. North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks — TRM Labs analysis of DPRK crypto theft statistics
  2. North Korean Hackers Attack Drift Protocol In $285 Million Heist — TRM Labs post-incident report on Drift Protocol
  3. LayerZero Post Mortem Shows Lazarus Group Stole $290M From KelpDAO — The Defiant's coverage of the LayerZero post-mortem
  4. Inside the KelpDAO Bridge Exploit — Chainalysis forensic analysis
  5. Humanity Protocol's $36M Hack Linked to Suspected North Korean Hackers — Quantstamp attribution report via Crypto Briefing
  6. Humanity's $36 Million Exploit Happened Because a 'Multisig' Lived on One Laptop — CoinDesk reporting on operational security failure
  7. U.S. Sanctions Network That Allegedly Laundered $800 Million in Crypto for North Korea — CoinDesk coverage of March 2026 OFAC sanctions
  8. OFAC Targets DPRK IT Workers Using Crypto — Chainalysis analysis of March 2026 sanctions
  9. DeFi Hacks 2026: $840M+ Lost — Altfins aggregate hack statistics
  10. $340M Lost: 14 Crypto Hacks 2026 Targeting Bridges — Bridge exploit aggregate data
  11. Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis lessons from the Drift Protocol hack
  12. Drift Loses $285 Million in Durable Nonce Social Engineering Attack — The Hacker News technical analysis
  13. Crypto Hack Losses Fell In May, Incidents Stay Near 2026 Highs — Bitcoin Foundation monthly incident data