TrollEye Security

Cyber News

North Korea Quietly Walked Off With 76% of 2026’s Stolen Crypto Using Only Two Attacks

New TRM Labs data shows North Korea-aligned hackers now control roughly 76% of all cryptocurrency stolen worldwide this year, achieved not through more attacks but through fewer, smarter, AI-assisted operations.

TRM Labs Data Shows the DPRK Now Dominates Crypto Theft Through Fewer, Smarter, AI-Assisted Operations

While most 2026 cybercrime crews are still grinding away at phishing kits and commodity ransomware, North Korea has been playing a different game. New analysis from TRM Labs, surfaced this week by Dark Reading, shows DPRK-aligned groups now sit on roughly 76% of all cryptocurrency stolen worldwide so far this year.

This didn’t come from a surge in attack volume, novel malware, or a flood of new TTPs, just two heists, executed weeks apart, that drained around $577 million from decentralized finance in minutes. Taken together, those two operations mark a shift the rest of the threat landscape hasn’t caught up to yet: the DPRK has industrialized DeFi theft into a precision, nation-state-grade economic weapon, and the architectures and teams defending crypto are not yet built to absorb it.

And the two attacks are worth examining in detail, because they represent the two halves of the modern DPRK playbook: one a human exploit built over months, the other an architectural exploit executed in seconds.

The Drift Protocol Heist

The Drift breach is the human half of that playbook, a masterclass in long-game social engineering. TRM says the campaign included months of targeted manipulation and, in what may be unprecedented for North Korean operations, in-person meetings between DPRK proxies and Drift employees.

Attackers exploited a Solana feature called a durable nonce, which extends a pre-signed transaction’s validity from 90 seconds to indefinite. By tricking Drift’s Security Council multisig signers into pre-authorizing transactions in late March, they effectively pre-loaded the heist.

When Drift migrated to a new 2-of-5 Security Council with zero timelock on March 27th, the last meaningful safeguard was gone. On April 1st, the pre-signed transactions fired. 31 withdrawals draining USDC, JLP, and other assets in roughly 12 minutes. The stolen ETH then went dormant, consistent with a North Korean group known for slow, multi-phase laundering measured in months or years, a thread we will return to when we look at how defenders should respond.

The KelpDAO Bridge Exploit

If Drift was a social-engineering masterclass, KelpDAO was its architectural counterpart. KelpDAO was a textbook infrastructure attack. On April 18th, the TraderTraitor crew compromised two of KelpDAO’s internal RPC nodes and DDoSed the external ones, forcing the rsETH LayerZero bridge to fail over to the poisoned data sources. Those nodes falsely reported that rsETH had been burned on the source chain, and the bridge’s single verifier rubber-stamped the fraudulent message, draining roughly 116,500 rsETH, about $292 million, in one shot.

The defining flaw was architectural: LayerZero supports multiple independent verifiers (DVNs), but KelpDAO’s deployment used only one. After the theft, the Arbitrum Security Council froze about $75 million still on Arbitrum, triggering a frantic laundering scramble. Roughly $175 million in ETH has since been swapped to Bitcoin, mostly through THORChain, with the privacy tool Umbra used to muddy wallet trails. TRM notes the laundering pipeline is being run almost entirely by Chinese intermediaries.

An Accelerating Trend, Not an Anomaly

Two attacks of that scale would be remarkable on their own. What turns them into a thesis is that they sit on top of a multi-year trend line. This isn’t a one-year fluke. North Korea’s share of total crypto theft has climbed steadily, under 10% in 2020 and 2021, 22% in 2022, 37% in 2023, 39% in 2024, and 64% in 2025. The 2026 figure of 76% is the highest sustained share on record, and the cumulative DPRK total since 2017 now exceeds $6 billion.

Last year’s spike was driven largely by the historic $1.46 billion Bybit breach in February 2025, still the largest single crypto hack in history. Drift and KelpDAO together already rival any comparable window of DPRK activity.

AI Is Quietly Sharpening the Knife

AI isn’t the headline in these attacks, but it’s part of the broader trend. TRM Labs notes that analysts are beginning to see AI used in reconnaissance and social engineering workflows, while Dark Reading reports that it may be helping attackers scale and refine their operations. AI isn’t what drove these specific heists, but it’s increasingly acting as a force multiplier, making already precise, high-impact attacks more efficient and harder to detect.

Fewer Hacks, Bigger Hauls, and a Shrinking Margin for Error

North Korea’s 2026 numbers make one thing clear: the DPRK is no longer an opportunistic crypto thief but a disciplined, AI-empowered economic adversary, and the targets are no longer just wallets; they’re governance contracts, bridge verifiers, and the humans who hold the keys.

Defending against that means architecting for nation-state pressure from day one: multi-verifier bridges, timelocked multisigs, durable nonce hygiene, and aggressive cross-chain laundering monitoring on the technical side, paired with hardened identity checks, out-of-band approvals, and insider-threat programs that assume AI-augmented operators are already cultivating your contributors.

Until crypto’s security maturity catches up to the value it now safeguards, Pyongyang will keep treating DeFi as the cheapest, fastest, and most reliable funding mechanism on Earth.

Sources: DarkReading | TRM

 

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated