nuloq
← Posts
Issue

· Updated 2026-09-11

North Korea's two-thirds of H1 crypto hacking losses — reading two counts without mixing them

Contact & corrections

Correction (2026-09-11): ① The counts from two research firms (TRM Labs and Blockaid) had again been mixed together in the list in the body, and we fixed that (the $789 million and 74% for private-key theft are Blockaid's figures, not TRM's). ② We removed the sentence that lumped April's two incidents together as the work of Lazarus and its sub-unit TraderTraitor. TRM assessed the Drift attacker as a different North Korean group from TraderTraitor, and said which group it was is still under investigation. ③ We corrected the part that explained the gap between TRM's 76% (April 30 material) and 66% (July 1 material) by time period alone. The July material restated the same April point as 71%. ④ We removed the $6.75 billion cumulative figure and the "roughly $2 billion in 2025" estimate, which we could not find in the material we cite, and added the U.S. Treasury statement to the sources. ⑤ We removed the explanation that "exchanges hardened their security, so attacks moved to DeFi," because it runs the opposite way from the TRM material we cite. We also removed the advice to pick a service by its cold-wallet ratio, since there is no public data to compare. ⑥ Added on 2026-09-11: we put both of TRM's 2025 figures in the body side by side. The December 2025 material gave the year only as a floor of more than $1.5 billion, while the July 2026 material said about $1.7 billion in the first half of 2025 alone. The two are not in conflict, but they must not be read as one continuous series. ⑦ We cut TRM's recommendations back to the three in the original (hardware-backed signing, key management, and multi-party approval for large transfers). The "custody arrangements" item in the earlier version is not in the original. ⑧ We restored the 2025 loss wording to match the original: more than $2.7 billion was stolen, and North Korea's share was well over half. The original publication date (2026-08-02) is unchanged.

You often see the line "North Korea took two-thirds of this half-year's hacking losses." But which research firm produced that figure, and what did they divide it by? Here we set the numbers from two firms that count differently side by side, without mixing them.

In short
  • By TRM Labs' count, hacking losses in the first half of 2026 came to 207 incidents and $972 million in all. Of that, it treated about $643 million (about 66%) as activity linked to North Korea.
  • Count the same period through another firm (Blockaid) and you get 212 incidents and about $1.1 billion, with $609 million (55%) linked to North Korea. The two counts divide by different bases, so the numbers cannot be mixed.
  • About 90% of North Korea's share ($577 million) came from two incidents in April (Drift, $285 million; KelpDAO, $292 million). The amount is down from the first half of 2025 (about $1.7 billion, TRM's July 2026 material). TRM puts the gap down to there being fewer large thefts across the rest of the ecosystem than in 2025.

What happened

  • On April 1, about $285 million in crypto assets was drained from Drift, a decentralized futures exchange built on Solana.
  • On April 18, another $292 million was stolen from KelpDAO, a protocol built on Ethereum.
  • The two together come to $577 million. That is about 90% of the $643 million TRM Labs estimated as North Korea's share. It means the money is concentrated in a few large attacks, not spread over many small hacks.
  • TRM Labs said infrastructure and operations breaches accounted for about 76% of all stolen value. By incident count they were only about 15%. An infrastructure and operations breach goes after the ways people and systems get access — private keys (the keys that open a wallet, like a password) or accounts — rather than a hole in the code. In other words, there are fewer of them, but each one does far more damage.

The two incidents cannot be tied to one and the same group. In its April 30 material, TRM Labs assessed both as linked to North Korea. But it judged the Drift attacker to be a different North Korean group from TraderTraitor, and wrote that which group it is remains under investigation. For KelpDAO, it explained that the way the money was laundered after the theft looked like TraderTraitor's usual method. Lazarus is the name the U.S. Treasury used in September 2019, when it designated the group for sanctions and described it as tied to North Korea's Reconnaissance General Bureau. But we could not find, for this article, any material that pins April 2026's two incidents on Lazarus specifically. North Korea has publicly denied analyses of this kind. This article did not verify who did it. It reports that research firms made those assessments. That is not the same as a finding settled by a court.

Same period, two different counts — the error you get by mixing them

There is one error that shows up most often in Korean coverage of this subject: attaching Blockaid's percentage to TRM Labs' total. The two firms counted different incidents and different amounts, so the base they divide by is different too.

Crypto hacking in H1 2026 — counts compared by firm
TRM Labs (2026.07.01)66%
Total losses
$972M
North Korea-linked
$643M
Incidents
207
Blockaid (cited by VOA, 2026.07.30)55%
Total losses
~$1.1B
North Korea-linked
$609M
Incidents
212
Both counts cover January to June 2026. Bar lengths are drawn with each firm's total losses set to 100%. So do not compare a bar on the left with a bar on the right. The incident-count bars are for display and are not drawn to scale. The $789 million (74%) for private-key theft is a figure from Blockaid's count, so it cannot be attached to TRM's total.

Working the base backwards from the percentage

There is a check you can run yourself. In the Blockaid numbers VOA reported, private-key theft is $789 million, and its share is 74%. Divide $789 million by 0.74 and you get about $1.07 billion. That matches the "about $1.1 billion" in the same article once you allow for rounding. Divide the same $789 million by TRM's $972 million instead and you get about 81%, which does not match 74%. When a percentage and a total do not fit each other, the two came from different counts.

For the same reason, even inside TRM's own material you have to check which month it came from. The 76% we saw earlier was the share by type of breach. The 76% we are talking about now is North Korea's share, so it is a different number. TRM's April 30 material, titled "North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks," divided by a base running from January 1 to April 30, 2026. Yet the July 1 half-year material looked back at the same April point and restated it as 71% through April. So the gap between 76% (end of April) and 66% (end of June) is not explained by the time period alone. Part of it may be that TRM revised its own internal count. We could not find, for this article, any explanation of why 76% became 71%. It means that even figures from the same firm cannot simply be strung together when they come from different releases.

Why this money matters

On May 6, 2022 the U.S. Treasury announced sanctions on a crypto mixer — a service that scrambles the flow of money to make it hard to trace. In that announcement it wrote that, under the pressure of strong U.S. and U.N. sanctions, North Korea has relied on illicit activities to fund its unlawful weapons of mass destruction (WMD) and ballistic missile programs. Those activities include cyber-enabled theft targeting virtual currency exchanges and financial institutions. Research firms read it the same way: with sanctions blocking normal ways to earn hard currency, hacking works as a detour for funds.

The trend in scale goes like this. In material dated December 18, 2025, TRM Labs said that more than $2.7 billion was stolen in hacks worldwide that year, and that North Korea took well over half of it. That is a count up to the day the material was published. It is not a figure finalized after the year ended. The same material pointed to more than $1.5 billion in 2025 alone as linked to North Korea. The $643 million in the first half of 2026 is smaller than that. But it covers six months, so it cannot be set beside a full-year figure. The $6.75 billion cumulative figure and the "roughly $2 billion in 2025" estimate from the earlier version were removed, because we could not find them on the TRM page we cite.

One thing needs pointing out here. TRM's half-year report for 2026 said about $1.7 billion for the first half of 2025 alone. The December 2025 material, though, gave that whole year only as more than $1.5 billion. "More than" is a floor, so we cannot say the two figures contradict each other. What we can say is that looking only at the December material makes it easy to read the year as smaller than it was. So the two values must not be strung together as an annual trend. The rule we used above for 76% and 66% applies here just the same.

For reference, the often-quoted "29.7% in 2023 ($340.4 million)" is a running total through the third quarter of 2023. Put it on the same line as full-year figures and draw a trend, and it will look smaller than it really is.

Korea is no exception. Upbit, the country's largest exchange, lost 342,000 ETH in 2019 (worth about 58 billion won at the time). On November 27, 2025, it was hit again by an attack that moved about 44.5 billion won worth of crypto assets out to the outside. An official at the Ministry of Science and ICT said: "Being hacked on the same date and in the same way as six years ago makes it highly likely that the same North Korean group was behind it." That is an assessment by the government and the security industry. It is not a finding settled by a court.

By the numbers — the amount fell, but

Crypto theft linked to North Korea — first halves compared (TRM Labs count)
H1 2025
~$1.70B
H1 2026
$643M
Both values are TRM Labs counts. The first-half 2025 value, however, is a number TRM wrote looking back in its July 2026 material. The same firm's "more than $1.5 billion for all of 2025," published in December 2025, states only a floor, so the two cannot be strung together as an annual trend. Bar lengths are drawn with the first half of 2025 set to 100%. Source: TRM Labs (2026.07.01).

The amount did not fall because there were fewer attacks. There were 207 incidents in the first half of 2026. TRM puts the gap down to there being fewer large thefts across the rest of the ecosystem than in 2025. It then stated plainly that a drop in stolen funds should not be mistaken for a safer environment. In other words, a smaller total does not mean a smaller threat. It is a figure that swings on whether a big incident happened or not.

The debate — has the threat shrunk, or grown sharper?

The security industry stresses that a smaller amount should not be read as a smaller threat. The grounds are the structure we saw above. Infrastructure and operations breaches were only 15% by incident count, yet they produced 76% of the money. That means going after key management and people does far more damage than hunting for holes in code.

On the other side, some read the smaller amount as a result of sanctions and better security. But the explanation the earlier version leaned on — that "exchanges hardened their security, so attacks moved to DeFi (financial services that run on programs, with no middleman company)" — runs the opposite way from the TRM material we cite, so we removed it. In its December 2025 material, TRM assessed that North Korea's targets had shifted from bridges (services that act as a bridge between different blockchains) toward centralized services, which are weaker against tricking people. It gave as the reason that a centralized service can produce far bigger losses than a single bridge. In the end, the material now public cannot tell us the main reason the amount fell. It also has to be read alongside the fact that North Korea denies these analyses outright.

What comes next — what to watch

Three things are worth watching. First, whether TRM's observation from December 2025 — that targets moved from bridges to centralized services — keeps holding. Second, whether the share taken by infrastructure and operations breaches stays high. If it does, defense has to shift its focus from code review toward key management and toward countering tricks aimed at insiders. Third, whether another very large single incident turns up in the second-half count.

An individual user cannot pick "which service is safer" from these statistics alone. There is no public data that lets you compare exchanges by their cold-wallet ratio (wallets kept off the internet). What TRM recommended in its half-year report is three things: hardware-backed signing, strong key management, and approval by several people when large amounts are moved. The point is to put weight on the controls that actually protect the money, rather than on code review. These are not items an individual can choose; they are items a service has to have in place. This article does not recommend any investment decision on a particular service or asset.

What this article could not verify

  • Blockaid's original report — the 55% and 74% figures were confirmed through VOA's reporting. We could not open the report Blockaid itself published. Whether the total is "about $1.1 billion" or in the $1.07 billion range also needs checking against the original.
  • Why TRM revised the April share — we could not find any explanation of why the 76% in the April 30 material became 71% in the July 1 material (a revised count, or a different base).
  • A settled full-year figure for 2025 — TRM stated only a floor of "more than $1.5 billion." The roughly $2 billion estimate from other firms was removed from the body, because in this correction we could not confirm it in material published by the firm itself.
  • Details of Upbit's 2025 incident — the number of asset types taken and the number of outside addresses they were moved to were removed from the body, because in this review we could not confirm them in material published by the institution itself.
  • Cumulative laundering linked to OFAC sanctions — removed from the body, because we could not check the original sanctions notice.

This article was put together by nuloq with the help of AI tools, based on the material listed under "Sources" above. For the correction of September 11, 2026, the documents we opened and read ourselves were TRM Labs' half-year report of July 1, 2026, its material of April 30, 2026, its long-term trend material of December 18, 2025, and the U.S. Treasury statement of May 6, 2022. We could not open Blockaid's original report, so every figure connected to it is written as the value VOA's reporting carried. In the further correction of September 11, 2026, we reopened TRM's July 1 half-year report and its December 18 material and confirmed in the originals the about $1.7 billion for the first half of 2025, the "more than $2.7 billion" and "well over half" wording, and the three recommended items. Analyses of who did it are judgments by research firms, not findings settled by a court. Counted figures change with the firm and with the date of the count. The purpose is to inform, not to serve as a basis for investment decisions, and we will fix anything found to be wrong.

#North Korea#cryptocurrency#hacking#cybersecurity#Lazarus Group

Related posts

Issue

Welfare ₩148.8tn, National Debt ₩1,519.8tn — What Is the 48.3% Ratio Divided By?

We separate the two ways of counting the welfare ministry's budget, and correct the denominator of the national debt ratio to nominal GDP. We hold back judgment on why the ratio falls until the official GDP assumption can be checked, and we found no confirmed evidence that the future response fund caused the ₩106 trillion rise in debt.

#budget#welfare#national debt#fiscal policy#aging population