Twelve Minutes in April

On April 1, 2026, a series of transactions began executing against Drift Protocol, a perpetuals exchange built on Solana. Thirty-one withdrawals ran in sequence. The entire drain finished in roughly twelve minutes, and $285 million was gone.

However, the twelve minutes were the least interesting part. Instead, the real work had happened over the preceding months. In conference rooms and coffee shops, people posing as business contacts met Drift employees face to face. By 2026, in other words, North Korea crypto theft had evolved into something that no longer resembled hacking at all.

Seventeen days later, a second operation drained $292 million from KelpDAO. Together, those two attacks accounted for 76 percent of every dollar stolen from crypto platforms worldwide in 2026 through April. They represented just 3 percent of recorded incidents.

That ratio — a handful of operations, a commanding share of global losses — is the signature of the most consequential actor in digital finance that almost nobody outside the security industry can name.


The Growth Curve Nobody Charted

Most readers encounter North Korea crypto theft as a series of disconnected headlines. A number, a victim, a shrug. Viewed as a time series, though, the picture changes entirely.

North Korea’s share of global crypto hack losses sat below 10 percent in 2020 and 2021. Then it climbed to 22 percent in 2022, 37 percent in 2023, and 39 percent in 2024. Subsequently, the figure reached 64 percent in 2025. Through April 2026, it hit 76 percent — the highest sustained share ever recorded.

Meanwhile, the absolute numbers tell a parallel story. In 2025 alone, DPRK crypto hacking pulled in $2.02 billion, a 51 percent jump over the previous year. Cumulative attributed theft since 2016 now exceeds $6.75 billion.

For context, that cumulative figure exceeds the annual GDP of roughly forty countries. Moreover, it dwarfs what North Korea earns from every legal export combined.

Here is the detail that reframes everything, though. Notably, the attack cadence has not increased. North Korean hackers run fewer operations than most criminal groups, not more. In other words, they are not attacking more often — they are attacking more precisely.


Why Crypto, and Why Now

To understand the shift, consider the alternative. A conventionally sanctioned state has limited options for acquiring hard currency. Coal smuggling requires ships, ports, and cooperative buyers. Meanwhile, arms sales require intermediaries and physical logistics. Counterfeiting, similarly, requires distribution networks. Critically, every one of those channels has a chokepoint that a foreign government can squeeze.

Cryptocurrency has no such chokepoint. As a result, it became the ideal instrument for a state that is comprehensively cut off from the conventional financial system.

Furthermore, the returns are extraordinary relative to headcount. A team of a few dozen operators can generate revenue that would otherwise require an entire export industry. UN panels and multiple governments have documented that a meaningful portion of these proceeds flows toward weapons development, which is why the topic sits at the intersection of finance and national security rather than in either category alone.

For anyone building on Korean blockchain platforms or investing in the sector, this context matters directly. In practice, the won stablecoin race, the exchange consolidation, and the institutional entries all unfold inside one threat environment. That environment is shaped by a well-resourced adversary operating a few hundred kilometers north.


The Org Chart Behind North Korea Crypto Theft

Outside coverage tends to use “Lazarus Group” as shorthand for anything North Korean and digital. In practice, the structure resembles a set of departments rather than a single gang.

Lazarus Group is the oldest and best known name, tied to the 2014 Sony breach and the 2017 WannaCry campaign. Meanwhile, TraderTraitor covers teams specializing in exchange and bridge operations. Jasper Sleet is Microsoft’s name for the units running employment infiltration. Notably, analysts at TRM Labs assessed the Drift attackers as a group distinct from TraderTraitor entirely. The specific subgroup remains under investigation.

Consequently, the practical takeaway is not that one group is responsible. Instead, multiple specialized teams operate in parallel, share laundering infrastructure, and pursue different target classes with different tradecraft.


The New Weapon Is a Job Application

Perhaps the most underappreciated development in DPRK crypto hacking has nothing to do with code. Instead, it involves resumes.

Since 2020, thousands of North Korean workers have obtained legitimate remote employment worldwide using stolen or fabricated identities. Between 2020 and 2022 alone, US authorities identified more than 300 American companies that had unknowingly hired them. Several were Fortune 500 firms. Remarkably, these workers pass interviews, receive salaries, and perform real engineering work.

The mechanics are systematic. Operators build profiles with AI-generated headshots and fabricated employment histories. During video interviews, some deploy real-time deepfakes. Once hired, they request that company laptops ship to intermediary addresses in the target country. These are the so-called laptop farms, where local facilitators keep the machines running and reachable from abroad. More recently, operators have registered shell companies with working websites and bank accounts to lend plausibility to fake histories.

Two revenue streams follow. First, the salaries themselves flow back to the regime, which violates sanctions regardless of anything else. Second, and far more consequentially, an employed engineer holds credentials. Accordingly, Chainalysis found that embedded IT workers had become one of the DPRK’s principal attack vectors. They contributed to a record 76 percent share of all service compromises.

In short, the fastest route into a crypto company’s infrastructure is no longer the firewall. It is the hiring pipeline.


Anatomy of a Modern Operation

The two 2026 attacks illustrate how far the tradecraft has moved beyond stolen passwords.

Drift Protocol exploited a Solana feature called a durable nonce. Ordinarily, Solana transactions expire in about ninety seconds if not confirmed. However, durable nonces extend that window indefinitely, a design intended for offline hardware signing. Between March 23 and March 30, the attacker created durable nonce accounts. Then he induced members of Drift’s Security Council multisig to pre-authorize transactions that looked routine at signing. Meanwhile, on March 27, Drift migrated its Security Council to a configuration with zero timelock, removing a safeguard. In parallel, the attacker manufactured a fictitious token and seeded it with liquidity. After wash trading inflated its price, Drift’s oracles treated it as legitimate collateral. Consequently, when the pre-signed transactions broadcast on April 1, every condition was already in place.

KelpDAO took a different route. The attackers compromised two internal RPC nodes and modified the software to report false blockchain data. Then they launched a denial-of-service attack against the external, uncompromised nodes. As a result, the bridge’s verifier failed over to the poisoned ones. Those nodes reported that tokens had burned on the source chain when no burn had occurred. Because KelpDAO’s bridge used a single verifier rather than several independent ones, one corrupted source sufficed to approve a fraudulent $292 million transfer.

Notably, neither attack was a brute-force intrusion. Both were patient exploitations of design decisions that looked reasonable in isolation.


Following the Money

Stealing is the easy half. Converting nine figures of traceable blockchain assets into usable currency is far harder. Indeed, that stage is where North Korea crypto theft reveals its industrial character.

The KelpDAO laundering ran according to a familiar playbook. Curiously, the attackers left roughly 30,766 ETH on Arbitrum, a layer-2 network far more centralized than Ethereum itself. The Arbitrum Security Council then used emergency powers to freeze approximately $75 million. That intervention triggered an immediate scramble. Subsequently, roughly $175 million in ETH became Bitcoin, primarily through THORChain — a cross-chain protocol with no KYC requirement whose operators decline to freeze transfers. Meanwhile, Umbra, an Ethereum privacy tool, obscured wallet linkages along the way.

THORChain also processed the bulk of the 2025 Bybit proceeds, making it the consistent exit ramp across North Korea’s largest operations. Assets enter as ETH; they emerge as BTC.

By contrast, the Drift proceeds took the opposite approach. Converted to USDC, bridged to Ethereum, swapped into ETH, and then spread across fresh wallets — where they have sat motionless ever since. Accordingly, analysts expect a liquidation stretched over months or years.

One further detail deserves attention. Notably, the final laundering phase runs almost entirely through Chinese intermediaries rather than North Koreans. TRM traced part of the KelpDAO pre-funding to a Bitcoin wallet controlled by Wu Huihui. That Chinese broker was indicted in 2023 for laundering earlier Lazarus Group proceeds. In short, this is a subcontracted supply chain with specialized vendors at each stage.


The Seoul Front

Korean readers tend to notice something international coverage often skips. Specifically, the same exchange has been hit twice.

Upbit, Korea’s largest crypto exchange, lost 342,000 ETH in a 2019 breach attributed to North Korean hackers. Then, in November 2025, it lost roughly $30 to $36 million in Solana-network assets from a hot wallet. South Korean officials linked the second incident to Lazarus Group based on the intrusion method and the laundering pattern. Furthermore, investigators noted the attackers appeared to impersonate administrators rather than breach servers directly. That is the same shape as 2019.

Meanwhile, the timing carried an additional signal. The breach landed one day after Naver announced its acquisition of Dunamu, Upbit’s operator, through a share swap. Security officials suggested the choice was deliberate. Whether or not that reading holds, the episode struck the most consequential deal in Korean crypto. Since then, that transaction has moved toward a Nasdaq listing, drawing in Hana Bank and Samsung affiliates as stakeholders.

The broader Korean market makes an attractive target for structural reasons. Korea has more than 16 million crypto users and per-capita adoption among the world’s highest. In addition, 27 licensed VASPs operate under Financial Services Commission rules. Cumulative losses from Korean exchange hacks between 2017 and 2025 exceed $196 million. Meanwhile, the country is racing to launch won-denominated stablecoins, whose real-world use cases already span remittance and retail. That effort introduces an entirely new category of infrastructure to defend.


What the Defenders Have Managed

The response has been real, though uneven.

On the sanctions side, the US Treasury designated eight North Korean individuals and two entities in late 2025 for laundering stolen digital assets. Those targets included a state-run IT front company and financial representatives in China and Russia. Subsequently, South Korea’s Deputy Foreign Minister indicated that Seoul was weighing adjustments to its own sanctions framework. Notably, this marked one of the first times Korean policy explicitly tied cybercrime to new penalties.

Internationally, the Multilateral Sanctions Monitoring Team now tracks sanctions violations tied to crypto laundering. Eleven nations participate, including the US, Japan, and South Korea. Furthermore, a 2025 UN working group report formally acknowledged member-state concern that cryptocurrency theft may affect international peace and security.

Domestically, the Financial Supervisory Service has moved toward proactive digital risk supervision, including punitive fines and CEO-level accountability for security failures. On the technical side, the Arbitrum freeze showed that fast intervention can preserve real value — $75 million, in that case. Additionally, industry threat-sharing networks now propagate attributed addresses across major exchanges within minutes rather than days.

Nevertheless, CSIS analysts assess that the impact of sanctions and exchange regulation has been constrained. North Korean hackers adapted by shifting toward opaque channels. These include informal brokers, mixers, and intermediaries operating through China and Russia. In effect, the chokepoints keep moving.


A Practical Checklist for Founders and Investors

For anyone operating in or entering the Korean blockchain market, the following measures address the vectors that actually produce losses.

On hiring. First, require live, unfiltered video for every remote candidate interview, since deepfakes degrade under unscripted conditions. Second, verify employment history independently rather than trusting supplied references. Third, flag last-minute changes to equipment delivery addresses — the single most reliable laptop-farm indicator. Additionally, watch for consistent meeting avoidance, call-center background noise, and unexplained VPN use. If you suspect an active hire, do not confront them. Instead, escalate to security and legal counsel first, because past cases show operators will exfiltrate data when they sense exposure.

On protocol design. Never deploy a cross-chain bridge with a single verifier. Similarly, preserve timelocks on multisig configuration changes rather than removing them for convenience. Treat oracle collateral listings as a security surface, not a product decision. Above all, assume that any pre-signing mechanism with an extended validity window will eventually be targeted.

On treasury and compliance. Screen deposits against attributed address clusters using multi-hop analysis, since first-hop screening misses funds routed through intermediary wallets. Furthermore, apply enhanced due diligence to inflows with cross-chain protocols upstream. Finally, re-screen retroactively, because attribution frequently lands weeks after an incident.

On diligence. Foreign founders relocating under the digital nomad visa or building a Korean entity should treat these controls as day-one infrastructure. For investors, a portfolio company’s hiring controls now belong in technical diligence alongside its code audit. Ultimately, the two questions are no longer separable.


Where This Goes

Three trends look durable. First, the concentration continues — fewer operations, larger takes, higher share of global losses. Second, AI is entering the workflow. Specifically, analysts have begun observing signs that operators use AI tooling for reconnaissance and social engineering. That shift is consistent with the increasing precision of campaigns like Drift. Third, DeFi protocols and cross-chain bridges will remain the preferred target class. After all, they combine large pooled value with lighter controls and thinner oversight than centralized exchanges.

For Korea specifically, the exposure grows as the market institutionalizes. A Nasdaq-listed exchange operator, bank-backed stablecoins, and tokenized securities all represent new surface area. Consequently, security stops being a compliance line item. Instead, it becomes a competitive variable.

The $6 billion figure will be out of date by the time most people read it. That is, in the end, the point. North Korea crypto theft is not a series of crimes. Rather, it is an operation compounding for a decade in public, while most of the industry it targets treated each incident as an isolated accident.

Twelve minutes in April was the visible part. The months before it were the actual work.