Skip to main content

The Modern Memo

Edit Template
Oct 5, 2026
North Korea Stole 76% of All Crypto Hack Value Worldwide in 2026 Using Just Two Attacks

North Korea Stole 76% of All Crypto Hack Value Worldwide in 2026 Using Just Two Attacks

North Korean state-linked hackers accounted for a staggering 76% of all cryptocurrency stolen worldwide through the first four months of 2026, according to blockchain analytics firm TRM Labs, with two attacks alone netting the regime a combined $577 million even as international sanctions continue to formally cut it off from the global financial system. The two operations, carried out weeks apart in April, showcased increasingly sophisticated tactics that blockchain security researchers say represent a marked evolution from North Korea’s earlier, cruder hacking playbook. In the first attack, on April 1, hackers targeted Drift Protocol, a decentralized finance platform built on the Solana blockchain, stealing $285 million through a scheme that unfolded over months. The attackers spent weeks on social engineering — building trust with people who held authorization credentials — before spending roughly three weeks staging the theft directly on the blockchain itself. They ultimately exploited a feature of Solana’s transaction system known as a “durable nonce” to get the platform’s security council signers to pre-authorize transactions without fully realizing what they were approving, then executed 31 separate withdrawals in a rapid-fire window of approximately 12 minutes once the theft began in earnest. A separate North Korean group struck again just over two weeks later, on April 18, this time targeting KelpDAO through a cross-chain bridge built on the LayerZero protocol. That attack netted $292 million by compromising the remote procedure call nodes that platforms use to communicate with the blockchain, exploiting what researchers described as a single-verifier design flaw that allowed the attackers to push through fraudulent transactions without the additional layers of verification more robust systems require. In the aftermath, the Arbitrum Security Council managed to freeze roughly $75 million of the stolen funds before the hackers could move them further, but the bulk of the money was successfully laundered through THORChain, a decentralized cross-chain exchange that has become a favored laundering route for stolen crypto precisely because it allows funds to be swapped between different blockchains with minimal friction and limited centralized oversight. Combined, the two attacks totaled $577 million and, despite representing just 3% of the total number of crypto-theft incidents tracked globally in 2026, accounted for the overwhelming majority of the dollar value stolen across the entire industry during that period — a reflection of how selectively and effectively North Korean hacking units have come to target the largest, most lucrative platforms rather than pursuing high-volume, low-value theft. The scale of the haul lines up with a broader pattern researchers have documented in North Korea’s cyber operations over the past several years, in which state-linked hacking groups — most prominently the Lazarus Group, a unit widely believed to operate under North Korea’s Reconnaissance General Bureau intelligence agency — have increasingly targeted decentralized finance platforms, crypto exchanges and blockchain bridges as a primary funding mechanism for the isolated regime. Separate reporting from Bloomberg has put North Korean leader Kim Jong Un’s cumulative windfall from crypto theft and related illicit financial activity at roughly $22 billion, a sum that analysts say has become an increasingly important funding stream for a government that remains subject to some of the most extensive international sanctions of any country in the world, largely over its nuclear weapons and ballistic missile programs. The persistence and scale of the thefts have raised uncomfortable questions for the broader cryptocurrency industry about whether current security practices at even well-established platforms are adequate against a persistent, well-resourced state actor. Unlike criminal hacking groups motivated purely by short-term profit, North Korea’s units operate with the backing, patience and operational security resources of a nation-state, allowing them to invest months in reconnaissance and social engineering before executing a theft — an asymmetry that has repeatedly proven difficult for even sophisticated crypto platforms to defend against, since it targets human trust and institutional processes as much as it does purely technical vulnerabilities in code. U.S. and allied officials have long argued that North Korea’s crypto theft operations directly subsidize its weapons programs, helping the regime work around the formal international financial sanctions imposed by the United Nations Security Council and individual countries including the United States. That argument has taken on renewed urgency as North Korea has continued to expand its ballistic missile testing and, according to U.S. intelligence assessments, deepen military cooperation with Russia amid the ongoing war in Ukraine — cooperation that has reportedly included North Korean troops deployed to support Russian forces in exchange for military technology transfers, adding another dimension to concerns that sanctions-evading revenue streams like crypto theft are helping fund activity with consequences well beyond North Korea’s own borders. Industry groups and blockchain security firms have called for stronger cross-platform information sharing and more robust verification standards for the kinds of bridge and cross-chain infrastructure that both the Drift Protocol and KelpDAO attacks exploited, arguing that the current fragmented approach to security across thousands of independent DeFi platforms leaves systemic vulnerabilities that a sufficiently patient and well-funded attacker — state-sponsored or otherwise — will continue to find and exploit. Whether the industry moves quickly enough to close those gaps before North Korea’s hacking units identify the next one remains, based on the pattern of the past several years, very much an open question. U.S. Treasury officials have continued to add sanctions designations against individuals and front companies linked to North Korean cyber operations throughout the year, part of a broader effort to disrupt the laundering networks that convert stolen crypto into usable funds for the regime. But enforcement officials and blockchain analysts alike acknowledge that sanctions targeting individual wallets or front companies have had limited success in actually stopping the underlying theft, since decentralized platforms like THORChain are specifically designed to resist the kind of centralized control that would let a government freeze or block transactions the way it can with a traditional bank. Some lawmakers in Washington have pushed for legislation that would impose stricter know-your-customer requirements on cross-chain bridges and DeFi protocols, arguing that the industry’s continued resistance to centralized…

Read More
North Korea Fires Barrage of Missiles Toward the Sea, Rebuffing Trump's Bid to Restart Diplomacy

North Korea Fires Barrage of Missiles Toward the Sea, Rebuffing Trump’s Bid to Restart Diplomacy

North Korea launched a barrage of ballistic missiles into the sea off its eastern coast Thursday, a pointed rejection of a recent U.S. gesture aimed at reviving stalled diplomacy — the latest sign that Pyongyang intends to hold out for bigger concessions before returning to the negotiating table with the Trump administration. What Happened South Korea’s Joint Chiefs of Staff said North Korea launched about 10 short-range ballistic missiles from the country’s capital region around 5 p.m. local time Thursday, with the missiles traveling roughly 185 miles toward North Korea’s eastern waters. The launch came just a day after North Korean officials publicly dismissed a U.S. decision to scale back the size and duration of joint military drills with South Korea — a move Washington had made in an apparent bid to create space for renewed talks. Pyongyang’s Blunt Rejection Kim Yo Jong, the influential sister of North Korean leader Kim Jong Un, made clear Wednesday that the scaled-back drills weren’t enough to change North Korea’s calculus. “The provocative, aggressive nature of the drills won’t change even though their duration and size were reduced,” she said in a statement, adding a warning to Washington against reading too much into the gesture: “If the U.S. calculates that it can propagate its recent measure as the one of so-called good faith, they will not get the desired answer.” Kim Yo Jong also directly disputed a claim from President Trump that her brother had responded positively to his outreach for a conversation, denying that any such response had been given. Reading Between the Lines Despite the firm rejection, Kim Yo Jong notably avoided the kind of fiery, personally directed rhetoric North Korea has often employed in past standoffs. She specifically noted that personal relations between her brother and Trump remain “still excellent” — a detail analysts say suggests Pyongyang isn’t slamming the door on diplomacy altogether, but rather signaling that it wants Trump to offer more substantial concessions before agreeing to resume formal talks. In other words, Thursday’s missile launch appears designed as calibrated pressure rather than a definitive rejection of engagement. Asked by reporters Wednesday whether he expects to meet with Kim Jong Un before the end of the year, Trump responded simply: “Yeah, I will be” — suggesting the administration remains optimistic about eventually restarting the kind of high-profile, direct diplomacy that characterized Trump’s approach to North Korea during his first term. Part of a Longer Pattern Thursday’s launch fits a well-established pattern in the on-again, off-again relationship between Washington, Seoul, and Pyongyang. North Korea has repeatedly used missile tests over the years as a signal of displeasure with joint U.S.-South Korea military exercises, which it has long characterized as rehearsals for an invasion. Backdrop tensions have simmered for months, with North Korea previously dismissing earlier South Korean peace overtures as a “clumsy, deceptive farce” and warning of “terrible consequences” over prior rounds of joint drills. The Strategic Calculation For Pyongyang, using missile tests to register displeasure while stopping short of a full rhetorical escalation serves a specific purpose: it keeps pressure on Washington and Seoul without foreclosing the possibility of resumed talks, preserving North Korea’s leverage heading into any eventual negotiation. Supporters of the administration’s approach argue that offering to scale back joint drills was a reasonable, low-cost gesture worth attempting, and that North Korea’s calibrated response — firm rejection paired with warm personal comments about the Trump-Kim relationship — actually signals the door to eventual talks remains open, just not yet on terms Pyongyang is prepared to accept. Skeptics note that this is a familiar cycle: the U.S. offers a concession, North Korea rejects it as insufficient while conducting a weapons test to underscore the point, and the two sides remain at a standstill until one party is willing to move further. From that view, genuine breakthroughs with North Korea have historically required much larger, more concrete concessions than a modest reduction in drill size and duration. What Happens Next With Trump signaling continued optimism about an eventual meeting with Kim Jong Un and North Korea leaving the door open, if only narrowly, further diplomatic maneuvering seems likely in the coming months. In the meantime, South Korea’s military continues to closely monitor North Korean military activity, and additional missile tests or other displays of military capability remain a real possibility as both sides continue to feel out the other’s position ahead of any potential return to the negotiating table. This story is developing.

Read More