nuloq
← Posts

North Korea Took Two-Thirds of 2026's Crypto Hack Losses So Far

· Issue

The world's most effective state-backed hacking operation is still North Korea's — and this year's numbers prove it.

In short
  • According to blockchain analytics firm TRM Labs, North Korea-linked hackers stole $643 million in the first half of 2026 — 55–66% of the roughly $1.1 billion stolen in crypto hacks worldwide.
  • Nearly 90% of that — $577 million — came from just two DeFi attacks in April: $285 million from Drift and $292 million from KelpDAO.
  • The dollar total is down from H1 2025's roughly $1.7 billion, but experts say that's not a sign of a shrinking threat — it reflects a shift toward private-key theft and AI-assisted attacks that are more precise, not less dangerous.

What happened

A report from San Francisco-based blockchain analytics firm TRM Labs found that North Korea-linked hackers took $643 million of the roughly $1.1 billion stolen in crypto hacks worldwide during the first half of 2026 — a 55–66% share, depending on how the figure is framed; narrowed to just the first four months of the year, the share climbs to 76%.

  • On April 1, hackers drained $285 million from Drift, a Solana-based decentralized futures exchange.
  • Later that month, $292 million more was stolen from KelpDAO, an Ethereum-based lending protocol.
  • Those two attacks alone account for roughly 90% of North Korea's $643 million haul — a handful of large, precise strikes rather than many small ones.
  • Across all crypto hacks, $789 million — 74% of total losses — came from stolen private keys rather than code exploits, with attackers increasingly targeting key management and employees through social engineering.

The attacks are attributed to Lazarus, the hacking group linked to North Korea's Reconnaissance General Bureau, and its sub-unit TraderTraitor. North Korea has publicly denied TRM Labs' attribution.

Why this money matters — the background

TRM Labs and the U.S. Treasury have both assessed that a substantial share of North Korea's stolen crypto funds its nuclear and missile programs. With international sanctions blocking normal channels for hard currency, crypto theft has effectively become a workaround. Last year, the Treasury's Office of Foreign Assets Control sanctioned individuals and entities tied to North Korea's cyber-laundering network, saying they had laundered more than $3 billion through hacking and overseas IT-worker schemes.

The trajectory tells its own story. TRM Labs puts North Korea's cumulative haul since 2016 at $6.75 billion. Through the third quarter of 2023, its share of global crypto-hack losses was 29.7% ($340.4 million); by 2025 it had grown to roughly 60% of a $2.06 billion global total — driven in large part by the roughly $1.5 billion theft from the Bybit exchange in February 2025, still the largest single crypto hack on record.

Korea has direct experience with this. Upbit, the country's largest exchange, lost 58 billion won worth of Ethereum to Lazarus in 2019, then was hit again on November 27, 2025, when 24 types of crypto assets worth 44.5 billion won — including Solana — were moved to 165 external addresses. Authorities and security researchers pointed to Lazarus both times.

By the numbers

Looking only at the H1 2026 total, the dollar figure is actually down from a year earlier.

North Korea-linked crypto-hack losses, H1 comparison
H1 2025
$1.70B
H1 2026
$643M
Source: TRM Labs, via UPI (2026.07.03)

Much of that decline reflects the absence of a single outsized event like 2025's $1.5 billion Bybit heist, rather than fewer attacks overall. North Korea's share of the global total, meanwhile, remains dominant.

North Korea's share of global crypto-hack losses
2023 (thru Q3)
29.7%
2025
60%
H1 2026
55–66%
Source: TRM Labs reports, via Etoday and VOA Korea
The conclusion changes depending on which number you look at. The dollar amount is down, but North Korea's share of global crypto-hack losses is up — a sign the group has shifted from casting a wide net to concentrating on fewer, more carefully reconnoitered, higher-value targets.

The debate — is the threat shrinking or sharpening?

TRM Labs and other security researchers caution against reading the dollar decline as a sign of a weakening threat. Several signals point the other way: 74% of total losses came from private-key theft and social engineering rather than code flaws, and researchers have found evidence that AI tools were used in the reconnaissance behind attacks like Drift and KelpDAO. The read is that operations have moved from indiscriminate probing toward precision strikes on fewer targets.

Others credit the decline to better defenses: exchanges have shifted more holdings into cold storage and adopted multi-signature controls, making direct breaches harder — pushing attackers toward less-hardened DeFi protocols instead. North Korea's denial of TRM Labs' attribution keeps a separate debate alive too, over how confidently the international response can be built on these threat assessments.

What to watch next

Three things are worth tracking. First, where the targets move next — from centralized exchanges to DeFi and onward to whatever segment is least hardened. Second, how much AI tooling actually shows up in reconnaissance and social engineering, since that could force a rethink of detection and defense strategy. Third, whether new sanctions and international coordination meaningfully cut into the amount actually stolen and laundered.

For Korea, the fact that Upbit has now been targeted twice is itself a warning. Users of domestic exchanges and DeFi services should favor platforms with strong multi-factor authentication and high cold-storage ratios, and pay attention to unusual-withdrawal alerts on large transactions. For government and industry, defending against private-key theft and insider-targeted social engineering looks like the next front line.

This is nuloq's own analysis based on the TRM Labs report and the public reporting listed under Sources, produced with the help of AI tools. It's for information only, not investment advice, and the underlying figures can shift depending on which research firm and cutoff date is used. We correct the piece if errors turn up.

Related posts