VERSE PRESS

Crypto News, Global First.

North Korea's Lazarus Group Now Accounts for 76% of All 2026 Crypto Theft, TRM Labs Finds

Cumulative DPRK haul since 2017 has crossed $6 billion after two April exploits drained $577 million in under three weeks.

|

North Korea's state-sponsored hacking collective, known as Lazarus Group, is responsible for 76% of all cryptocurrency stolen globally so far in 2026, according to a report released April 30 by blockchain intelligence firm TRM Labs. The findings arrive after two back-to-back attacks in April targeting Solana-based perpetuals and spot trading platform Drift Protocol ($285 million) and cross-chain restaking protocol KelpDAO ($292 million), which combined for $577 million in losses out of a total $606 million stolen across 12 incidents that month, making April the worst month for crypto security since February 2025. The group's total theft since 2017 has now surpassed $6 billion.

Two Attacks, 18 Days Apart

The Drift Protocol exploit on April 1 stands as the second-largest hack in Solana's history. Attackers ran a sustained social engineering campaign from March 11 through March 30 against the individuals holding signing keys for Drift's governance multisig, a security structure requiring multiple approvals before funds can move.

They manipulated those key holders into pre-signing hidden authorization transactions, then manufactured a fake token called CarbonVote Token (CVT) and used wash trading to create artificial price signals that gave it fraudulent legitimacy as collateral.

On March 27, as part of a planned migration, Drift reduced its governance security threshold to two of five signers and removed its timelock, a delay mechanism that gives teams time to catch suspicious transactions before they execute. Attackers incorporated that change into their coordinated attack timeline, using it to eliminate the intervention window entirely.

With no safeguards remaining, attackers listed the fake token as valid collateral, inflated withdrawal limits, and drained real USDC, SOL, and JLP tokens across 31 sequential transactions in roughly 12 minutes. More than half of the protocol's total value locked was gone.


Seventeen days later, KelpDAO's cross-chain bridge lost approximately 116,500 rsETH (a restaked Ether token) worth around $292 million, a figure representing 18% of the token's total circulating supply. The attack compromised two RPC nodes, the servers that relay blockchain data, then used a denial-of-service attack to force a failover to a node under attacker control. That gave the attackers enough influence to trick the bridge's verifier into approving a fraudulent cross-chain message, effectively authorizing the transfer of funds that did not belong to them. LayerZero, the messaging protocol underlying the bridge, publicly blamed KelpDAO's own infrastructure decisions despite prior warnings, stating it had previously cautioned KelpDAO against using a single-verifier configuration.

The combined market shock from both attacks erased an estimated $13 billion from DeFi total value locked across two days, according to Bitget News.


A Pattern, Not a Surprise

Researchers at 38North and other policy analysts have increasingly framed North Korea's crypto operations as a shadow national treasury: a parallel financing system designed to generate hard currency beyond the reach of international sanctions. The two April attacks fit squarely within that strategic logic.

North Korea has been systematically escalating its crypto theft operations since at least 2017, moving from exchange hacks to DeFi protocol exploits to, now, attacks on the human operators who hold signing authority. The 2022 Ronin Bridge hack generated $620 million. The February 2025 Bybit breach, still the largest single crypto hack on record, netted $1.5 billion in Ethereum, with more than $160 million laundered within 48 hours and over $400 million laundered within five days. According to Chainalysis, the group stole $2.02 billion in 2025 alone, a 51% increase over the prior year.

Nick Carlsen, a North Korea specialist at TRM Labs and a former FBI subject matter expert, has characterized the laundering approach as a "flood the zone" strategy. In his words, the group focuses on "overwhelming compliance teams, blockchain analysts, and law enforcement agencies with rapid, high-frequency transactions across multiple platforms, thereby complicating tracking efforts." The group has increasingly moved away from cryptocurrency mixers following enforcement actions and now relies on cross-chain bridges, direct ETH-to-BTC conversions, and high-volume over-the-counter brokers, particularly in China, to convert stolen funds into usable cash.

Dave Schwed, COO at SVRN, framed the structural motivation plainly: "North Korea doesn't have the luxury of patience. They're under comprehensive international sanctions and they need hard currency to fund weapons programs. Crypto theft gives them immediate access to liquid value, globally, without needing a counterparty willing to do business with them."


The Threat Is Not Distant for Regional Users

For users outside North America and Western Europe, this is not an abstract geopolitical story. In July 2024, Lazarus Group stole $235 million from WazirX, then India's largest crypto exchange, wiping out 45% of its total holdings. That attribution was formally confirmed in January 2025 through a joint statement issued by the United States, South Korea, and Japan. Indian retail investors ultimately absorbed a 15% loss on assets held at the time of the breach. WazirX did not resume operations until October 2025. The attack exploited a structurally similar category of vulnerability to that seen in Drift: insufficient controls over multi-signature signing authority, in this case involving a compromise of the third-party custody provider Liminal Custody.

In Africa, where Chainalysis data shows crypto fraud rates surged 112% in a recent measurement period, the risk takes a different form. CSIS researchers have specifically flagged Africa as an expansion target for North Korea's IT worker infiltration scheme, a coordinated operation in which DPRK operatives pose as freelance developers to embed in Web3 teams, steal credentials, and siphon funds. Operatives have also posed as recruiters to harvest credentials from developers. Developer communities in Nigeria, Kenya, South Africa, and Ghana are considered low-awareness, high-growth targets for the scheme, which generated an estimated $800 million for North Korean weapons programs in 2024 alone, according to the U.S. Treasury's Office of Foreign Assets Control.

African retail users also face direct exposure through the DeFi protocols they increasingly rely on. Cross-chain bridges and liquidity pools, the exact attack surface exploited at Drift and KelpDAO, represent a documented and growing risk for the continent's expanding DeFi user base.


What Comes Next

According to CryptoBriefing, prediction markets tracking "another $100 million or more hack before December 31, 2026" were locked at 100% YES at the time of publication. CryptoBriefing analysis puts the current pace of major exploits at one every 2.9 days.

For developers and protocol teams, the practical recommendations from security researchers are specific: implement timelocks on all governance multisig structures, require multi-verifier configurations for cross-chain bridges, independently audit third-party custody arrangements, and verify the identities of remote contributors. As Alexander Urbelis, CISO at ENS Labs, put it: "Their targets are exchanges, wallet providers, DeFi protocols and the individual engineers and founders who have signing authority." The code can be audited. The people holding the keys are harder to protect.