April 2026 Was the Worst Month for Crypto Hacks on Record. North Korea Ran Most of It.
Two state-linked attacks on Solana and Ethereum protocols drained more than $577 million in April, pushing monthly losses to a historic high and sending shockwaves through DeFi markets globally.
Crypto protocols lost between $629 million and $650 million to hacks and exploits in April 2026. Whether that makes it the single worst month on record depends on methodology: DeFiLlama, which tracks on-chain losses, calls April 2026 the worst month in crypto history; CertiK, whose $650.9 million figure incorporates a broader accounting that includes scams and fraud alongside direct exploits, describes April as the worst month since March 2022, implying its own methodology placed that earlier month higher. Both firms agree on the month's extraordinary scale, and the volume of individual incidents is not in dispute: more than 20 separate hacks were recorded in April, also a monthly record by incident count.
The damage was not spread thinly across those events. Two attacks, one on April 1 and one on April 18, accounted for roughly 95 percent of the month's total losses. Both have been attributed to two separate North Korean-linked hacker clusters by blockchain intelligence firm TRM Labs. April's record also stands in sharp relief against the rest of 2026: January logged $370.3 million in losses, February fell to $26.52 million, March came in between $52 million and $59.5 million, and April then shattered all prior monthly benchmarks.
How the attacks worked
The first strike hit Drift Protocol, a perpetuals exchange built on Solana, for $285 million on April 1. TRM Labs documented that the attack was not improvised. Attackers spent three weeks in March conducting on-chain preparation and invested months in social engineering, including in-person meetings with protocol staff. Central to the scheme was the fabrication of a fictitious CarbonVote Token (CVT), which the attackers used as synthetic collateral through wash trading to manipulate the protocol's valuation mechanisms. This infrastructure-layer deception, distinct from a conventional code exploit, would prove to be a defining feature of the month's most damaging attacks. On the day of the exploit, 31 withdrawal transactions were executed in approximately 12 minutes. The attackers used Solana's durable nonce feature, a technical mechanism that extends how long a signed transaction remains valid, to give themselves a wider execution window. Stolen funds were converted to USDC via Jupiter, the Solana DEX aggregator, moved to Ethereum, swapped to ETH, and spread across fresh wallets. As of April 30, those funds have not moved.
The second and larger attack struck KelpDAO on April 18. KelpDAO operates a restaking token called rsETH, which lets users earn additional yield on their staked Ethereum. The incident ranks as the third largest DeFi hack in history, behind only Poly Network in August 2021 ($611 million) and the Binance BNB Bridge in October 2022 ($570 million). Attackers manipulated the protocol's LayerZero cross-chain bridge, a system that passes messages between different blockchains, by compromising two internal RPC nodes and simultaneously flooding external nodes with junk traffic to force a failover to the corrupted infrastructure. A structural design flaw made the attack possible: the bridge operated a single-verifier DVN (Decentralized Verifier Network) architecture with no redundancy to detect forged cross-chain messages. Once the compromised RPC nodes controlled the verification pathway, the bridge had no fallback mechanism to catch fraudulent instructions.
The bridge then accepted forged messages and minted 116,500 unbacked rsETH tokens, worth approximately $292 million, equal to roughly 18 percent of the token's entire circulating supply. An emergency pause came 46 minutes after the initial drain. The attacker subsequently attempted two additional drains at 18:26 and 18:28 UTC, each targeting approximately $100 million. Both attempts reverted, indicating that the emergency response, though delayed, did curtail further losses.
Fallout across DeFi
The KelpDAO hack triggered immediate contagion. Aave, one of the largest decentralized lending platforms in the sector, froze its rsETH markets across two product versions. Estimates placed Aave's potential bad debt exposure at up to $230 million, context that explains the severity of the market reaction that followed. Its governance token fell roughly 10 percent. SparkLend, Fluid, Upshift, and Lido Finance all enacted emergency pauses on products with rsETH exposure. Ethena suspended its LayerZero-based token bridges for six hours. A Bloomberg report published April 20 cited $9 billion in withdrawals from a single major DeFi lender in the immediate aftermath; Bloomberg reporting also attributed $13 billion in total DeFi outflows to the episode across the following week, though readers should note that the precise sourcing and scope of the broader $13 billion figure warrant confirmation against the underlying articles.
The Arbitrum Security Council exercised emergency powers on April 20 to freeze 30,766 ETH, worth approximately $75 million, linked to the KelpDAO exploiter. That recovery represents roughly 25.7 percent of the $292 million stolen in the KelpDAO attack. A broader coalition known as the Beacon Network, comprising Coinbase, Binance, Kraken, OKX, Crypto.com, and participating DeFi protocols, coordinated to freeze additional portions of the stolen proceeds in one of the most extensive multi-platform industry responses to a single exploit on record.
TRM Labs identified approximately $175 million in further proceeds converted from ETH to bitcoin through THORChain, a cross-chain swap protocol whose operators declined to block or reverse the transfers. The remaining funds were further obscured using Umbra, an Ethereum-based privacy tool. TRM Labs linked the laundering operation to Chinese intermediaries associated with Wu Huihui, a broker indicted in 2023 for handling proceeds from North Korea's Lazarus Group.
TRM Labs noted in its April report: "Two attacks account for 76 percent of all 2026 hack value to date. The group is not attacking more frequently[,] it is targeting more precisely."
What this means for users in South Asia and Africa
KelpDAO's rsETH token was distributed across more than 20 networks including Base, Arbitrum, Linea, Blast, Scroll, and Mantle. For retail users, particularly in India where Ethereum liquid staking products have attracted significant participation, the depegging of rsETH created direct losses for holders who did not exit before trading was suspended. The Drift attack's social engineering methodology, which relied on months of in-person contact with protocol staff, also mirrors patterns that have caused severe losses across South Asia before: the Treasure NFT scheme caused an estimated $800 million in losses across India and Pakistan through similarly protracted trust-building tactics. Cross-chain DeFi users who held collateral positions on any of the affected networks faced locked or undervalued assets with no immediate recourse.
In Africa, where stablecoins and cross-chain bridges underpin a growing share of remittance and trade finance flows, especially across corridors linking Africa to the Middle East and Asia, the KelpDAO incident is a direct threat to settlement infrastructure. THORChain's refusal to act on flagged transfers is also a live compliance problem for regulators in Nigeria, South Africa, and Kenya, all of which are advancing Anti-Money Laundering rules under Travel Rule frameworks in 2026. That regulatory urgency has a concrete domestic precedent: Nigeria's CBEX fraud case, which resulted in over $250 million in victim losses, demonstrated how quickly failures in crypto infrastructure translate into direct harm for African retail users in markets where adoption has outpaced oversight.
What comes next
The Drift Protocol funds sitting untouched on Ethereum are the most significant unresolved variable. North Korean hacking groups have a documented practice of holding stolen assets for 12 to 24 months before beginning structured, phased conversions. The $285 million sitting dormant since April 1 has not disappeared; it is waiting.
Security researchers at The Block reported what they characterized as a new exploit involving dormant Ethereum addresses late on April 30, with reporting indicating the incident may add to the month's total loss figure. Whether that characterization is fully confirmed and the precise additional scope remain under active review; readers should treat the final April total as subject to upward revision.
North Korea's cumulative crypto theft since 2017 now exceeds $6 billion, per TRM Labs, and April 2026 alone added $577 million to that total with two targeted strikes.