0x4d5c969b4d5c…4d5c969e
North Korea Extracted $577M From Just Two Crypto Hacks in 2026: TRM Labs
Two North Korean attacks — Drift ($285M) and KelpDAO ($292M) — drove 76% of all crypto hack losses in 2026 through April, TRM Labs on-chain analysis shows.

Outputs
North Korean groups stole ~$577 million in 2026 through April — 76% of all hack losses — from just two attacks.
Drift Protocol lost $285 million on April 1 via pre-signed Solana durable-nonce transactions executed in ~12 minutes.
KelpDAO lost ~$292 million (116,500 rsETH) on April 18 via a compromised single-verifier LayerZero bridge.
The Arbitrum Security Council froze ~$75 million of KelpDAO proceeds; ~$175 million was laundered to Bitcoin via THORChain.
North Korea's cumulative attributed crypto theft since 2017 now exceeds $6 billion.
North Korean hacking groups stole approximately $577 million in crypto during 2026 through April, accounting for 76% of all hack losses recorded in the period — from just two attacks, according to on-chain analysis by blockchain intelligence firm TRM Labs.
The Drift Protocol breach on April 1 netted $285 million; the KelpDAO bridge exploit on April 18 drained roughly $292 million. Together, the two incidents represent 3% of 2026's incident count but 76% of stolen value, extending a pattern TRM attributes to North Korea's operational doctrine: a small number of precisely targeted, high-value operations rather than high-volume campaigns.
North Korea's cumulative attributed crypto theft now exceeds $6 billion since 2017, TRM estimates. Its share of total hack losses has climbed from under 10% in 2020–2021 to 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and now 76% through April 2026 — the highest sustained share on record.
How was Drift Protocol compromised?
TRM assesses the Drift attacker as a North Korean group distinct from the TraderTraitor cluster, with subgroup attribution still under investigation. On-chain staging began March 11 with a single 10 ETH withdrawal from Tornado Cash, but the social engineering campaign ran for months beforehand — including in-person meetings between North Korean proxies and Drift employees, which TRM analysts describe as possibly unprecedented in North Korea's crypto hacking campaign.
The technical core of the attack exploited Solana's durable nonce feature, which extends a transaction's validity from roughly 90 seconds to an indefinite window. Between March 23 and March 30, the attacker created durable nonce accounts and induced Drift's Security Council multisig signers to pre-authorize transactions. On March 27, Drift migrated its Security Council to a 2/5 threshold configuration with zero timelock — a change the attacker subsequently exploited. In parallel, the attacker manufactured CarbonVote Token (CVT), a fictitious asset inflated through wash trading, which Drift's oracles accepted as legitimate collateral.
On April 1, the pre-signed transactions executed: 31 withdrawals in approximately 12 minutes, draining real assets including USDC and JLP. Most proceeds were bridged to Ethereum within hours and have not moved since. TRM anticipates a months- or years-long liquidation process.
What happened in the KelpDAO exploit?
The April 18 attack targeted KelpDAO's rsETH LayerZero bridge on Ethereum. The attackers compromised two internal RPC nodes, replacing node software to report false blockchain data, then launched a DDoS attack against external nodes to force the bridge verifier to fail over to the poisoned ones. Those nodes falsely reported rsETH had been burned on the source chain. The bridge's single verifier — LayerZero Labs' DVN — confirmed the fraudulent message as legitimate, and the attacker drained approximately 116,500 rsETH.
TRM attributed the exploit to North Korea based on on-chain analysis of pre-funding and laundering flows. A portion of the initial funding traces back to 2018, to a Bitcoin wallet controlled by Wu Huihui, a Chinese broker indicted in 2023 for laundering Lazarus crypto thefts; other funds trace to the BTCTurk hack, another recent TraderTraitor operation.
Laundering proceeded under duress. The attackers left roughly 30,766 ETH on Arbitrum, and the Arbitrum Security Council froze it — about $75 million — using emergency powers. That triggered a scramble in which approximately $175 million in ETH was swapped to Bitcoin, mostly via THORChain, a no-KYC cross-chain protocol, with the Ethereum privacy tool Umbra used to obscure wallet linkages. Chinese intermediaries, not North Koreans directly, are handling the ongoing laundering phase, TRM says.
Why does THORChain keep appearing in these cases?
THORChain processed the vast majority of proceeds from both the 2025 Bybit breach ($1.46 billion, still the largest crypto hack in history) and the KelpDAO theft. No operator froze or rejected transfers in either case. The protocol's developers maintain it is decentralized and cannot censor transactions, though TRM notes recent statements on X by project members suggest this has not always been the case.
TRM's Beacon Network — whose 30-plus members include Coinbase, Binance, Kraken, OKX, Crypto.com and major DeFi protocols — auto-traces flagged addresses and pushes cross-platform alerts before withdrawals clear, converting a screening lag measured in days into minutes. TRM also speculates that North Korean operators are incorporating AI tools into reconnaissance and social-engineering workflows, consistent with the increasing precision of attacks like Drift.
TRM advises exchanges to re-screen April 2026 inflows within 30 days, since KelpDAO and Drift address attribution is still being finalized — leaving a defined window for retroactive detection of addresses labeled after the initial response.
via cdn.prod.website-files.com (Original)