📈 Get daily crypto insights that make you smarter about your money

North Korea’s $577 Million Crypto Heist Campaign: How Two Attacks Devastated April 2026

The first four months of 2026 delivered a stark reminder that cryptocurrency security remains an evolving battlefield. North Korean hacking groups stole approximately $577 million across just two operations — accounting for 76% of all crypto hack losses through April. The Drift Protocol breach on April 1 drained $285 million, while the KelpDAO exploit on April 18 extracted $292 million. Together, these incidents propelled April 2026 into the record books as the worst month for crypto exploits since the Bybit breach in February 2025, with total losses surpassing $606 million across 12 incidents. Bitcoin traded near $76,300 as the scale of these attacks rippled through market sentiment.

The Exploit Mechanics

The Drift Protocol attack on Solana exemplified a new tier of operational sophistication. North Korean operators spent six months establishing trust with the Drift team, including what TRM Labs described as unprecedented in-person meetings between proxies and Drift employees. On-chain staging began March 11 with a modest 10 ETH withdrawal from Tornado Cash. The attackers then exploited Solana’s durable nonce feature — a mechanism designed for offline hardware signing that extends transaction validity indefinitely — to induce Security Council multisig signers into pre-authorizing transactions between March 23 and March 30. When Drift migrated its Security Council to a new 2/5 threshold configuration with zero timelock on March 27, the attackers seized the window. They manufactured a fictitious CarbonVote Token, seeded it with minimal liquidity, inflated it through wash trading, and Drift’s oracles treated it as legitimate collateral. The entire vault drain executed in approximately 12 minutes on April 1.

The KelpDAO attack followed a different but equally devastating playbook. Hackers identified a single-verifier design flaw in a LayerZero bridge and exploited it to drain 116,500 rsETH — 18% of the token’s circulating supply — in a single transaction. The $292 million haul triggered cascading consequences: Aave absorbed $177 million in bad debt from rsETH collateral that could not be liquidated, creating measurable credit risk for one of DeFi’s largest lending platforms. After $75 million was frozen on Arbitrum, the attackers pivoted to laundering proceeds through THORChain, converting stolen ETH to Bitcoin in a process TRM Labs identified as a textbook TraderTraitor liquidation strategy.

Affected Systems

The blast radius extended well beyond the two primary targets. KelpDAO’s rsETH collapse sent shockwaves through the restaking ecosystem, with USDe outflows surging $1.6 billion as investors fled to stablecoins. DeFi United ultimately finalized a $300 million KelpDAO rescue package with on-chain compensation beginning for rsETH holders. Aave’s $177 million bad debt exposure forced the protocol to activate emergency procedures. Smaller April incidents compounded the damage: Silo Finance lost $392,000 to a misconfigured oracle, Dango suffered $410,000 from a bridge aggregator bug, a BNB Chain flash loan attack extracted $1.6 million, CoW Swap lost $1.2 million to domain hijacking, and Grinex Exchange saw $13.74 million drained across 54 wallets. TRM Labs noted that THORChain processed the vast majority of proceeds from both the 2025 Bybit breach and the KelpDAO hack, converting hundreds of millions in stolen ETH to Bitcoin with no operator willing to freeze transfers.

The Mitigation Strategy

TRM’s Beacon Network — comprising over 30 member exchanges and DeFi protocols — enables immediate cross-platform alerts when North Korea-linked funds reach participating institutions before withdrawals clear. The French Interior Ministry publicly acknowledged 41 physical crypto-related attacks at Paris Blockchain Week 2026, a rate of approximately one assault every 2.5 days, leading to the indictment of 88 suspects on April 25. CertiK’s wrench attack data shows 34 verified incidents globally in the first four months of 2026, a 41% increase over the same period in 2025, with 82% concentrated in Europe. The industry is responding with layered defenses: multi-signature governance with mandatory timelocks, independent oracle validation for collateral tokens, and bridge architecture audits that eliminate single-verifier dependencies.

Lessons Learned

Two patterns define the 2026 threat landscape. First, North Korea’s share of total crypto hack losses has grown from under 10% in 2020 to 76% in early 2026 — not because they attack more frequently, but because they target more precisely. TRM analysts speculate that North Korean operators are incorporating AI tools into reconnaissance and social engineering workflows, consistent with the increasing precision seen in the Drift attack. Second, cross-chain bridges remain the weakest link in the DeFi ecosystem. The KelpDAO exploit demonstrates that a single verifier flaw in bridge architecture can cascade into nine-figure losses across multiple protocols.

User Action Required

For individual holders, the lessons are immediate. Verify that any protocol you interact with uses multi-signature governance with enforced timelocks. Avoid protocols with single-verifier bridge designs. Enable address whitelisting on withdrawals. Use hardware wallets for any significant holdings — the $606 million lost in April alone underscores that software-based storage remains vulnerable to increasingly sophisticated attack chains. Monitor TRM Labs alerts and CertiK’s Skynet platform for real-time vulnerability disclosures. The threat is not theoretical; it is operational, well-funded, and growing more sophisticated each quarter.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “North Korea’s $577 Million Crypto Heist Campaign: How Two Attacks Devastated April 2026”

  1. six months building trust including in person meetings is state level tradecraft. this isnt some script kitty in a basement, its a funded intelligence operation

  2. 10 ETH initial withdrawal from Tornado on March 11 was their test run. classic recon before the actual hit. anyone monitoring tornado cash outflows could have flagged this

  3. chain_sentry_

    durable nonce exploit on solana was clever tbh. most audit firms dont even check for nonce related attack vectors on that chain

  4. six months of in person meetings to build trust before the strike. Lazarus plays a completely different game than your average DeFi exploiter

  5. Alex Blockchain

    This is another wake-up call for the industry. The sophisticated nature of these state-sponsored attacks shows that even the most secure protocols can have social engineering vulnerabilities. We need better cross-chain security standards and more transparent auditing processes to prevent these massive drains in the future.

    1. manufacturing a fake CarbonVote Token, seeding it with liquidity, wash trading it until oracles accepted it as collateral… the Drift attack reads like a heist movie script. 12 minutes to drain the vault

      1. governance_exploit_

        Tunde B. manufacturing a fake CarbonVote Token to manipulate oracles is next level. 12 minutes for $285M because nobody verified what the oracle was reading

        1. governance_nerd_88

          manufacturing a fake CarbonVote Token to trick oracles into accepting it as collateral is next level. 12 minutes for 285M because nobody verified the governance source

          1. governance_nerd_88 manufacturing a fake CarbonVote Token and seeding liquidity until oracles accepted it is next level social engineering. 12 minutes to drain 285M because nobody checked the governance source

      2. Tunde B. the fake CarbonVote Token is the craziest part. manufactured an entire governance asset, wash traded it, pumped it through oracles. 12 minutes to drain $285M

  6. NoFungible_Dan

    $577 million in just one month? That’s insane. This is exactly why mainstream adoption is struggling; people are terrified of losing their life savings to some North Korean hacker group. Until we solve the security gap and provide better insurance for DeFi users, this space will remain the Wild West.

    1. blockade_runner

      the KelpDAO single-verifier flaw in a LayerZero bridge is wild. one point of failure for 116k rsETH. how does that pass any audit

      1. chain_sleuth_

        blockade_runner single verifier on a LayerZero bridge holding 116k rsETH is insane. thats not a hack thats an open door

        1. single verifier on a LayerZero bridge holding 116k rsETH. the audit literally just needed to ask is one signature enough to move 116k ETH. apparently nobody asked

          1. Tomasz N a single verifier moving 116k rsETH should have been caught in any competent audit. the question literally writes itself

          2. cross_chain_fail_

            single verifier on a LayerZero bridge moving 116k rsETH. the audit literally needed to ask one question: is one signature enough. apparently nobody did

  7. Sarah Eth-Heart

    It’s devastating to see so much value lost, but I’m actually impressed by how the community responded to these hacks. The way the white-hats and developers work together to track the movement of stolen funds on-chain is incredible. We’re getting better at this, even if the bad actors are too.

  8. Man, those Lazarus Group guys don’t quit, do they? April was a rough month for the markets with these headlines constantly popping up. Just a reminder to get your stuff off the exchanges and into cold storage ASAP. Not your keys, not your crypto! Stay safe out there everyone.

    1. cold storage protects your keys but it doesnt protect protocols you have funds locked in. the attack surface is way bigger than most people realize

  9. six months of in-person meetings with drift team to build trust. lazarus is playing the long game now, this isnt some quick drain

    1. flashbanga six months of in-person meetings to build trust before the exploit. state sponsored ops have infinite patience and unlimited resources

  10. six months building trust with the Drift team including in person meetings. the patience and operational discipline here is genuinely terrifying

    1. using Solana durable nonce to stage the attack is clever. a feature designed for offline hardware wallets repurposed as an exploit mechanism

  11. 76% of all crypto hack losses from a single state actor. traditional finance doesnt deal with nation state adversaries like this

  12. drift_postmortem_

    manufacturing a fake CarbonVote Token and wash trading it until oracles accepted it as collateral took weeks of prep. 12 minutes to drain 285M after that. the asymmetry is terrifying

    1. chainlink_anywhere_

      drift_postmortem_ the fake token to oracle pipeline is the scariest innovation. they exploited the gap between governance and price discovery. no protocol has fixed this yet

  13. single verifier on a LayerZero bridge for 116k rsETH. whoever designed that threshold should be named publicly. that decision alone cost 292M

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,487.00+0.2%ETH$1,896.84+1.2%SOL$73.47-1.1%BNB$592.50-1.7%XRP$1.05-2.6%ADA$0.1908-0.9%DOGE$0.0696-0.9%DOT$0.8407-2.0%AVAX$6.63-1.1%LINK$8.11-0.9%UNI$4.10+5.4%ATOM$1.34-3.0%LTC$44.99-0.3%ARB$0.0797-2.1%NEAR$1.70-1.8%FIL$0.7094-1.2%SUI$0.6849-1.4%BTC$64,487.00+0.2%ETH$1,896.84+1.2%SOL$73.47-1.1%BNB$592.50-1.7%XRP$1.05-2.6%ADA$0.1908-0.9%DOGE$0.0696-0.9%DOT$0.8407-2.0%AVAX$6.63-1.1%LINK$8.11-0.9%UNI$4.10+5.4%ATOM$1.34-3.0%LTC$44.99-0.3%ARB$0.0797-2.1%NEAR$1.70-1.8%FIL$0.7094-1.2%SUI$0.6849-1.4%
Scroll to Top