Crypto
North Korea Stole 76% of All Crypto Hack Value Worldwide in 2026 Using Just Two Attacks
North Korean state-linked hackers accounted for a staggering 76% of all cryptocurrency stolen worldwide through the first four months of 2026, according to blockchain analytics firm TRM Labs, with two attacks alone netting the regime a combined $577 million even as international sanctions continue to formally cut it off from the global financial system. The two operations, carried out weeks apart in April, showcased increasingly sophisticated tactics that blockchain security researchers say represent a marked evolution from North Korea’s earlier, cruder hacking playbook. In the first attack, on April 1, hackers targeted Drift Protocol, a decentralized finance platform built on the Solana blockchain, stealing $285 million through a scheme that unfolded over months. The attackers spent weeks on social engineering — building trust with people who held authorization credentials — before spending roughly three weeks staging the theft directly on the blockchain itself. They ultimately exploited a feature of Solana’s transaction system known as a “durable nonce” to get the platform’s security council signers to pre-authorize transactions without fully realizing what they were approving, then executed 31 separate withdrawals in a rapid-fire window of approximately 12 minutes once the theft began in earnest. A separate North Korean group struck again just over two weeks later, on April 18, this time targeting KelpDAO through a cross-chain bridge built on the LayerZero protocol. That attack netted $292 million by compromising the remote procedure call nodes that platforms use to communicate with the blockchain, exploiting what researchers described as a single-verifier design flaw that allowed the attackers to push through fraudulent transactions without the additional layers of verification more robust systems require. In the aftermath, the Arbitrum Security Council managed to freeze roughly $75 million of the stolen funds before the hackers could move them further, but the bulk of the money was successfully laundered through THORChain, a decentralized cross-chain exchange that has become a favored laundering route for stolen crypto precisely because it allows funds to be swapped between different blockchains with minimal friction and limited centralized oversight. Combined, the two attacks totaled $577 million and, despite representing just 3% of the total number of crypto-theft incidents tracked globally in 2026, accounted for the overwhelming majority of the dollar value stolen across the entire industry during that period — a reflection of how selectively and effectively North Korean hacking units have come to target the largest, most lucrative platforms rather than pursuing high-volume, low-value theft. The scale of the haul lines up with a broader pattern researchers have documented in North Korea’s cyber operations over the past several years, in which state-linked hacking groups — most prominently the Lazarus Group, a unit widely believed to operate under North Korea’s Reconnaissance General Bureau intelligence agency — have increasingly targeted decentralized finance platforms, crypto exchanges and blockchain bridges as a primary funding mechanism for the isolated regime. Separate reporting from Bloomberg has put North Korean leader Kim Jong Un’s cumulative windfall from crypto theft and related illicit financial activity at roughly $22 billion, a sum that analysts say has become an increasingly important funding stream for a government that remains subject to some of the most extensive international sanctions of any country in the world, largely over its nuclear weapons and ballistic missile programs. The persistence and scale of the thefts have raised uncomfortable questions for the broader cryptocurrency industry about whether current security practices at even well-established platforms are adequate against a persistent, well-resourced state actor. Unlike criminal hacking groups motivated purely by short-term profit, North Korea’s units operate with the backing, patience and operational security resources of a nation-state, allowing them to invest months in reconnaissance and social engineering before executing a theft — an asymmetry that has repeatedly proven difficult for even sophisticated crypto platforms to defend against, since it targets human trust and institutional processes as much as it does purely technical vulnerabilities in code. U.S. and allied officials have long argued that North Korea’s crypto theft operations directly subsidize its weapons programs, helping the regime work around the formal international financial sanctions imposed by the United Nations Security Council and individual countries including the United States. That argument has taken on renewed urgency as North Korea has continued to expand its ballistic missile testing and, according to U.S. intelligence assessments, deepen military cooperation with Russia amid the ongoing war in Ukraine — cooperation that has reportedly included North Korean troops deployed to support Russian forces in exchange for military technology transfers, adding another dimension to concerns that sanctions-evading revenue streams like crypto theft are helping fund activity with consequences well beyond North Korea’s own borders. Industry groups and blockchain security firms have called for stronger cross-platform information sharing and more robust verification standards for the kinds of bridge and cross-chain infrastructure that both the Drift Protocol and KelpDAO attacks exploited, arguing that the current fragmented approach to security across thousands of independent DeFi platforms leaves systemic vulnerabilities that a sufficiently patient and well-funded attacker — state-sponsored or otherwise — will continue to find and exploit. Whether the industry moves quickly enough to close those gaps before North Korea’s hacking units identify the next one remains, based on the pattern of the past several years, very much an open question. U.S. Treasury officials have continued to add sanctions designations against individuals and front companies linked to North Korean cyber operations throughout the year, part of a broader effort to disrupt the laundering networks that convert stolen crypto into usable funds for the regime. But enforcement officials and blockchain analysts alike acknowledge that sanctions targeting individual wallets or front companies have had limited success in actually stopping the underlying theft, since decentralized platforms like THORChain are specifically designed to resist the kind of centralized control that would let a government freeze or block transactions the way it can with a traditional bank. Some lawmakers in Washington have pushed for legislation that would impose stricter know-your-customer requirements on cross-chain bridges and DeFi protocols, arguing that the industry’s continued resistance to centralized…
