← DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)1 decision on this page
Audit log
Every state-changing event for DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-31 12:22:48ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
NUcp8Av6qnyS…h1YFc8tFsha256 → base58
verifying row…canonical bytes (30083 B) ▸
{"actor":"system:backfill","investigation_id":"c1e79c32-018b-450b-855c-d8d387fea579","kind":"publish","page_slug":"dprk-crypto-theft-h1-2026-trm-labs-blockaid-report","published_at":"2026-07-31T12:22:48.102Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report)","sections":[{"content":"According to a TRM Labs report published in July 2026, North Korean state-sponsored hackers stole approximately $643 million across H1 2026, accounting for roughly two-thirds of all cryptocurrency stolen globally during that period. A separately published Blockaid H1 2026 report, released July 29, 2026, tracked a record 212 verified on-chain exploits and $1.1 billion in total losses, and attributed roughly $609 million — approximately 55 percent of H1 losses — to North Korea-linked groups including Lazarus and TraderTraitor. The divergence in attribution totals between the two reports reflects differing scope: the Blockaid figure includes the June 2026 Humanity Protocol exploit ($36 million), while TRM Labs' primary accounting focused on the two major April incidents. Cumulative DPRK-attributed cryptocurrency theft since 2017 has now surpassed $6 billion, according to TRM Labs.","heading":"Overview and Scale","severity":"critical","sources":[{"credibility":2,"name":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid | CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":1,"name":"North Korea behind two-thirds of crypto theft in H1 2026, report says | UPI","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/07/03/North-Korea-crypto-theft-two-thirds-H1-TRM-Labs/4361783069480/"},{"credibility":2,"name":"North Korea Stole $643 Million in Crypto in First Half, Two-Thirds of Global Losses | Seoul Economic Daily","type":"news_article","url":"https://en.sedaily.com/politics/2026/07/03/north-korea-stole-643-million-in-crypto-in-first-half-two"},{"credibility":2,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says | The Block","type":"news_article","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"}]},{"content":"On April 1, 2026, attackers drained approximately $285 million from Drift Protocol, Solana's largest decentralized derivatives exchange, in a coordinated operation that executed approximately 31 withdrawals within a 12-minute window. TRM Labs and Elliptic attributed the attack with medium confidence to UNC4736, a North Korean state-sponsored group also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. The attack was the culmination of a six-month social engineering campaign that began in fall 2025. DPRK-linked proxies attended crypto conferences in person, built rapport with Drift contributors via Telegram, deposited over $1 million of their own funds to appear as legitimate partners, and debugged vault integrations alongside protocol employees. Two Drift contributors were compromised: one after cloning a malicious code repository, and a second after being persuaded to install a weaponized wallet application through Apple's TestFlight. The attackers manipulated a fabricated asset — referred to as CarbonVote Token (CVT) — to gain governance access, and induced multisig signers to pre-authorize transactions weeks before execution, then pushed a zero-timelock governance migration that removed the protocol's review window. Following the theft, funds were converted to ETH via Jupiter and bridged to Ethereum, where they reportedly remained dormant as of the TRM Labs report publication date.","heading":"Drift Protocol Exploit — April 1, 2026 ($285 Million)","severity":"critical","sources":[{"credibility":2,"name":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation | The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html"},{"credibility":1,"name":"The long con: How North Korean spies spent months in-person to drain $285 million from Drift | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/30/north-korean-hackers-are-moving-faster-they-account-for-76-of-crypto-exploits-this-year-trmlabs"},{"credibility":2,"name":"Drift Protocol Hack Explained: Six-Month Social Engineering Led to $285M Solana DeFi Exploit | BitPinas","type":"news_article","url":"https://bitpinas.com/cryptocurrency/drift-protocol-exploit/"},{"credibility":2,"name":"Drift Protocol Hack: $285M Stolen in 12 Min [2026] | Shattered.io","type":"research","url":"https://shattered.io/drift-protocol-hack-285m/"},{"credibility":2,"name":"Drift Protocol Exploit: Why Social Trust Is the Newest Cybersecurity Gap | Crowell and Moring LLP","type":"other","url":"https://www.crowell.com/en/insights/client-alerts/drift-protocol-exploit-why-social-trust-is-the-newest-cybersecurity-gap"}]},{"content":"On April 18, 2026, attackers drained approximately $292 million (116,500 rsETH) from KelpDAO's rsETH bridge built on LayerZero. Cybersecurity firms including Chainalysis and security researchers attributed the attack to the Lazarus Group's TraderTraitor subunit. This was not a smart-contract exploit but an infrastructure attack: hackers compromised internal RPC nodes and executed a DDoS attack against external nodes, forcing the bridge's single decentralized validator node (a 1-of-1 DVN setup) to rely on poisoned data sources. This caused the Ethereum smart contract to release funds based on a phantom token burn on the source chain. KelpDAO paused contracts quickly enough to prevent an additional alleged $95 million drain. Arbitrum's governance subsequently froze approximately $75 million in stolen funds that remained on the Arbitrum network. The remaining approximately $175 million in ETH was moved to new wallets within roughly 36 hours and swapped primarily to Bitcoin via THORChain, a decentralized cross-chain protocol with no KYC requirements. THORChain's volume surged approximately 18 times its typical daily level during the laundering window. The conversion of ETH to Bitcoin through THORChain materially reduced traceability and eliminated the possibility of further protocol-level freezes.","heading":"KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)","severity":"critical","sources":[{"credibility":2,"name":"Inside the KelpDAO Bridge Exploit | Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"$290 Million Kelp DAO Crypto Heist Blamed on North Korea | SecurityWeek","type":"news_article","url":"https://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/"},{"credibility":2,"name":"KelpDAO confirms $290M hack linked to North Korea's Lazarus Group | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/kelpdao-confirms-290m-hack-linked-to-north-koreas-lazarus-group/"},{"credibility":2,"name":"Kelp DAO Exploiter Moves $175 Million in Stolen ETH Into New Wallets, Routing Funds Through THORChain | Unchained","type":"news_article","url":"https://unchainedcrypto.com/kelp-dao-exploiter-moves-175-million-in-stolen-eth-into-new-wallets-routing-funds-through-thorchain/"},{"credibility":1,"name":"North Korean hackers tied to $290M crypto heist, firm says | UPI","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"}]},{"content":"On June 8, 2026, Humanity Protocol suffered an alleged $36 million exploit affecting its H token contracts on Ethereum and BNB Chain. Forensic analysis by security firm Quantstamp identified malware tooling consistent with DPRK-affiliated hacking groups. The initial access vector was a phishing email disguised as communications from South Korean exchange Bithumb, purportedly containing a token lockup schedule update. The malware installed spyware that granted attackers full remote access to an employee's laptop, exposing multisig keys used to manage the bridge contracts. The H token price fell over 80 percent intraday following disclosure on June 9. Blockaid's H1 2026 report lists the Humanity Protocol exploit among the incidents attributed to North Korea-linked groups; however, attribution confidence for this incident is assessed as lower than for the April attacks given it rests primarily on tooling similarity rather than direct operational linkage.","heading":"Humanity Protocol Exploit — June 8, 2026 ($36 Million)","severity":"high","sources":[{"credibility":2,"name":"Humanity Protocol Hack Tooling Linked to North Korean Hackers: Quantstamp | CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/humanity-protocol-hack-linked-north-korean-actors-quantstamp"},{"credibility":2,"name":"Humanity Protocol's $36M hack linked to suspected North Korean hackers, Quantstamp reports | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/humanity-protocol-36m-hack-north-korean-hackers/"},{"credibility":2,"name":"Humanity Protocol Hack Tied to North Korean Group, $36M Lost | Blockchain.News","type":"news_article","url":"https://blockchain.news/news/humanity-protocol-hack-north-korean-link"}]},{"content":"The attacks documented in H1 2026 are attributed to the Lazarus Group, a collective of state-sponsored North Korean hackers operating under the Reconnaissance General Bureau (RGB) of the DPRK government. The FBI tracks a Lazarus subunit as TraderTraitor, which the bureau first identified in 2022 and which has been responsible for multiple large-scale DeFi bridge exploits, including the February 2025 Bybit theft of $1.5 billion — the largest single cryptocurrency theft on record. Additional tracking aliases for related units include UNC4736, AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces. TRM Labs reported that North Korea's share of global crypto hack losses has grown consistently year-over-year: approximately 10 percent during 2020 to 2021, 22 percent in 2022, 37 percent in 2023, 39 percent in 2024, 64 percent in 2025, and 76 percent of YTD losses as of the time of the April 2026 report. The group's operations have shifted markedly toward longer-duration social engineering campaigns and infrastructure-layer attacks rather than direct smart-contract exploits.","heading":"Threat Actor Attribution — Lazarus Group and TraderTraitor","severity":"critical","sources":[{"credibility":2,"name":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know | Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"TraderTraitor: Deep Dive | Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"},{"credibility":2,"name":"North Korea accounts for 76% of 2026 crypto hack losses, with theft since 2017 topping $6 billion | The Block","type":"news_article","url":"https://www.theblock.co/post/399569/north-korea-accounts-for-76-of-2026-crypto-hack-losses-with-theft-since-2017-topping-6-billion-trm-labs"}]},{"content":"Post-theft fund movement in H1 2026 exhibited two distinct patterns. In the Drift Protocol theft, stolen funds were converted to ETH via the Jupiter aggregator on Solana and bridged to Ethereum, where they reportedly remained dormant as of early July 2026 — consistent with prior DPRK behavior of allowing investigative attention to subside before moving funds. In the KelpDAO theft, approximately $75 million was frozen by Arbitrum governance action shortly after the exploit, while the remaining approximately $175 million in ETH was moved to freshly created wallets and routed through THORChain, a decentralized cross-chain liquidity protocol that operates without KYC requirements, converting the ETH to Bitcoin. Once converted to Bitcoin via THORChain, the funds are not subject to any protocol-level freeze mechanism, and forensic traceability degrades with each subsequent hop. THORChain's operators publicly maintained that the protocol is neutral infrastructure. The broader laundering playbook — converting illiquid staked tokens to liquid assets, routing through decentralized exchanges and no-KYC swap services, and breaking transactions across intermediate wallets — is consistent with methods documented by Chainalysis and TRM Labs in prior DPRK campaigns.","heading":"Laundering Methods and Fund Movement","severity":"high","sources":[{"credibility":2,"name":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"KelpDAO hacker launders ETH via THORChain — Network says it is neutral | AMBCrypto","type":"news_article","url":"https://ambcrypto.com/kelpdao-hacker-launders-eth-via-thorchain-network-says-it-is-neutral/"},{"credibility":2,"name":"How THORChain Works: Why KelpDAO Hacker Used It to Swap $175M ETH into BTC | CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/insights/how-thorchain-works-why-kelpdao-hacker-used-it-to-swap-175m-eth-into-btc/"},{"credibility":2,"name":"North Korea Crypto Hackers: How Stolen Funds Were Laundered | CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/north-korea-crypto-laundering"}]},{"content":"On March 12, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned six individuals and two entities — Amnokgang Technology Development Company and Quangvietdnbg International Services Company Limited — for facilitating North Korean IT worker fraud schemes. OFAC assessed that these networks generated nearly $800 million in 2024 to fund DPRK weapons programs. The designations included 21 cryptocurrency addresses across multiple blockchains and targeted operators in Vietnam, Laos, and Spain. The DPRK IT worker program operates by deploying North Korean nationals who secure remote employment at legitimate global companies using stolen identities and forged documents; the DPRK government then seizes the bulk of their wages, redirecting revenue toward prohibited weapons programs. The March 2026 OFAC action was described by analysts as targeting the infiltration pipeline that enables access for subsequent hacking operations. Prior OFAC sanctions related to Lazarus Group infrastructure include Tornado Cash addresses and the Sinbad mixer. A now-disbanded U.N. Panel of Experts estimated in a 2024 report that illicit cyber activity funded approximately 40 percent of the DPRK's weapons programs.","heading":"Regulatory and Sanctions Actions","severity":"critical","sources":[{"credibility":1,"name":"OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs | The Hacker News","type":"regulatory","url":"https://thehackernews.com/2026/03/ofac-sanctions-dprk-it-worker-network.html"},{"credibility":1,"name":"U.S. sanctions network that allegedly laundered $800 million in crypto for North Korea | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/03/13/u-s-sanctions-6-people-2-companies-that-laundered-usd800-million-in-crypto-for-north-korea"},{"credibility":2,"name":"OFAC Targets DPRK IT Workers Using Crypto | Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"credibility":2,"name":"OFAC Sanctions Crypto Network Tied to $800M North Korea IT Worker Scheme | Blockonomi","type":"news_article","url":"https://blockonomi.com/ofac-sanctions-crypto-network-tied-to-800m-north-korea-it-worker-scheme/"}]},{"content":"Multiple government agencies, intelligence bodies, and private analytics firms have assessed that cryptocurrency stolen by DPRK-linked groups flows directly into the regime's weapons-of-mass-destruction and ballistic missile programs. A formerly active U.N. Panel of Experts estimated in 2024 that illicit cyber activity accounted for approximately 40 percent of DPRK weapons funding. The OFAC designation of March 2026 explicitly cited WMD program financing as the use of IT worker proceeds. TRM Labs documented that North Korea's cumulative cryptocurrency theft since 2017 exceeds $6 billion, with $1.7 billion stolen in H1 2025 alone before declining to $643 million in H1 2026 — a decline TRM attributed to reduced number of successful operations rather than a reduced threat posture. Analysts have noted that even at reduced volumes, DPRK cryptocurrency theft remains a significant and ongoing source of hard-currency revenue for a heavily sanctioned state economy.","heading":"Proceeds and Weapons Program Funding","severity":"critical","sources":[{"credibility":2,"name":"North Korea reaffirms nuclear state position as its crypto theft machine funds the arsenal | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/north-korea-nuclear-crypto-theft-funding/"},{"credibility":2,"name":"From Digital Kleptocracy to Rogue Crypto-Superpower | 38 North","type":"research","url":"https://www.38north.org/2026/01/from-digital-kleptocracy-to-rogue-crypto-superpower/"},{"credibility":2,"name":"North Korea's cyber army funds nuclear arms with $2.8B in stolen crypto: MSMT | NK News","type":"news_article","url":"https://www.nknews.org/?p=962906"},{"credibility":1,"name":"Why North Korea hacks crypto instead of evading sanctions like Russia and Iran | CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/12/why-north-korea-keeps-stealing-billions-in-crypto-out-in-the-open"}]},{"content":"Blockaid's H1 2026 report recorded 212 verified on-chain exploits, the highest number for any six-month period on record, though total dollar losses of $1.1 billion were below the $2.3 billion recorded in H1 2025, a period that included the $1.5 billion Bybit theft. The four largest incidents — KelpDAO ($292 million), Drift Protocol ($285 million), Resolv, and CowSwap — accounted for approximately $707 million, or 64 percent of total H1 losses. Ethereum and Solana recorded the largest network-level losses at approximately $332 million and $326 million, respectively. Cross-chain bridges, EVM Layer-2 exploits, and compromised private keys were identified as the leading attack vectors. Blockaid also documented the emergence of AI agents as a new attack surface, with several incidents involving manipulation of on-chain AI agent infrastructure. TRM Labs noted a trend toward higher-speed execution: both the Drift and KelpDAO attacks were completed within under 50 minutes of the final exploit trigger, even as the preparatory phases extended over months.","heading":"Industry-Wide Context — H1 2026 Hack Landscape","severity":"high","sources":[{"credibility":2,"name":"Crypto records most hacked half-year ever with 212 exploits and $1.1 billion stolen | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/crypto-most-hacked-half-year-1b-stolen/"},{"credibility":2,"name":"Security Firm Blockaid Says 212 Onchain Exploits Stole $1.1B as AI and Wallet Attacks Accelerate | Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/security-firm-blockaid-says-212-onchain-exploits-stole-1-1b-as-ai-and-wallet-attacks-accelerate/"},{"credibility":2,"name":"Ethereum, Solana led crypto hack losses in H1 2026: Blockaid | TradingView / CoinTelegraph","type":"news_article","url":"https://www.tradingview.com/news/cointelegraph:b5b0378c6094b:0-ethereum-solana-led-crypto-hack-losses-in-h1-2026-blockaid/"},{"credibility":2,"name":"Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target | TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm"}]}],"sources_used":[{"credibility":2,"name":"North Korea Stole 76% of All Crypto Hack Value in 2026 — With Just Two Attacks | TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Crypto Hacks Cross $1.1B in Record H1 2026 Losses: Blockaid | CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"},{"credibility":1,"name":"North Korea behind two-thirds of crypto theft in H1 2026, report says | UPI","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/07/03/North-Korea-crypto-theft-two-thirds-H1-TRM-Labs/4361783069480/"},{"credibility":2,"name":"$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation | The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html"},{"credibility":1,"name":"The long con: How North Korean spies spent months in-person to drain $285 million from Drift | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/04/30/north-korean-hackers-are-moving-faster-they-account-for-76-of-crypto-exploits-this-year-trmlabs"},{"credibility":2,"name":"Inside the KelpDAO Bridge Exploit | Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"$290 Million Kelp DAO Crypto Heist Blamed on North Korea | SecurityWeek","type":"news_article","url":"https://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/"},{"credibility":1,"name":"OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs | The Hacker News","type":"regulatory","url":"https://thehackernews.com/2026/03/ofac-sanctions-dprk-it-worker-network.html"},{"credibility":1,"name":"U.S. sanctions network that allegedly laundered $800 million in crypto for North Korea | CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/03/13/u-s-sanctions-6-people-2-companies-that-laundered-usd800-million-in-crypto-for-north-korea"},{"credibility":2,"name":"OFAC Targets DPRK IT Workers Using Crypto | Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/ofac-targets-north-korean-it-workers-crypto-march-2026/"},{"credibility":2,"name":"Humanity Protocol Hack Tooling Linked to North Korean Hackers: Quantstamp | CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/humanity-protocol-hack-linked-north-korean-actors-quantstamp"},{"credibility":2,"name":"Kelp DAO Exploiter Moves $175 Million in Stolen ETH Into New Wallets, Routing Funds Through THORChain | Unchained","type":"news_article","url":"https://unchainedcrypto.com/kelp-dao-exploiter-moves-175-million-in-stolen-eth-into-new-wallets-routing-funds-through-thorchain/"},{"credibility":2,"name":"KelpDAO confirms $290M hack linked to North Korea's Lazarus Group | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/kelpdao-confirms-290m-hack-linked-to-north-koreas-lazarus-group/"},{"credibility":2,"name":"Crypto records most hacked half-year ever with 212 exploits and $1.1 billion stolen | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/crypto-most-hacked-half-year-1b-stolen/"},{"credibility":2,"name":"The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know | Sanctions.io","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"TraderTraitor: Deep Dive | Wiz Blog","type":"research","url":"https://www.wiz.io/blog/north-korean-tradertraitor-crypto-heist"},{"credibility":2,"name":"From Digital Kleptocracy to Rogue Crypto-Superpower | 38 North","type":"research","url":"https://www.38north.org/2026/01/from-digital-kleptocracy-to-rogue-crypto-superpower/"},{"credibility":2,"name":"North Korea-linked hackers steal $643M in crypto in H1 2026 | CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/north-korea-hackers-steal-643m-crypto-h1-2026/"},{"credibility":2,"name":"North Korea behind two-thirds of global crypto stolen in H1: report | Korea Herald","type":"news_article","url":"https://www.koreaherald.com/article/10797363"},{"credibility":2,"name":"Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target | TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm"}],"summary":"North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm. Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds. Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.","timeline":[{"date":"2025-09-01","event":"DPRK-linked UNC4736 operators allegedly began a multi-month social engineering campaign targeting Drift Protocol contributors, attending conferences and building Telegram-based relationships with employees.","source":"The Hacker News / CoinDesk","source_url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html"},{"date":"2026-03-01","event":"DPRK proxies made in-person contact with Drift employees at crypto conferences and deposited over $1 million of their own funds into the protocol to appear as legitimate partners.","source":"CoinDesk / BitPinas","source_url":"https://www.coindesk.com/business/2026/04/30/north-korean-hackers-are-moving-faster-they-account-for-76-of-crypto-exploits-this-year-trmlabs"},{"date":"2026-03-12","event":"OFAC sanctioned six individuals and two entities — including Amnokgang Technology Development Company — for facilitating DPRK IT worker networks that allegedly generated $800 million for weapons programs in 2024.","source":"The Hacker News / CoinDesk","source_url":"https://thehackernews.com/2026/03/ofac-sanctions-dprk-it-worker-network.html"},{"date":"2026-04-01","event":"Drift Protocol exploited for approximately $285 million in 12 minutes. Attackers executed pre-signed transactions after a zero-timelock governance migration removed the protocol's review window. Attributed to UNC4736 / Citrine Sleet.","source":"The Hacker News / TRM Labs","source_url":"https://thehackernews.com/2026/04/285-million-drift-hack-traced-to-six.html"},{"date":"2026-04-18","event":"KelpDAO rsETH LayerZero bridge drained of approximately $292 million (116,500 rsETH) in under 46 minutes. Attackers compromised internal RPC nodes and DDoS'd external nodes to poison the bridge's single DVN verifier. Attributed to TraderTraitor / Lazarus Group.","source":"SecurityWeek / Chainalysis","source_url":"https://www.securityweek.com/290-million-kelp-dao-crypto-heist-blamed-on-north-korea/"},{"date":"2026-04-18","event":"KelpDAO paused contracts, preventing an additional alleged $95 million in losses. Arbitrum governance froze approximately $75 million of stolen funds on the Arbitrum network.","source":"SpotedCrypto","source_url":"https://www.spotedcrypto.com/kelpdao-292m-hack-lazarus-defi-recovery-2026/"},{"date":"2026-04-21","event":"KelpDAO hacker began moving approximately $175 million in stolen ETH through THORChain, converting proceeds to Bitcoin over roughly 36 hours. THORChain volume surged approximately 18 times its normal daily level.","source":"Unchained / CryptoTimes","source_url":"https://unchainedcrypto.com/kelp-dao-exploiter-moves-175-million-in-stolen-eth-into-new-wallets-routing-funds-through-thorchain/"},{"date":"2026-06-08","event":"Humanity Protocol exploited for approximately $36 million via a phishing email impersonating Bithumb, installing spyware that exposed multisig bridge keys. Attributed to DPRK-affiliated groups by Quantstamp based on malware tooling.","source":"CoinTelegraph / CryptoBriefing","source_url":"https://cointelegraph.com/news/humanity-protocol-hack-linked-north-korean-actors-quantstamp"},{"date":"2026-07-03","event":"TRM Labs published report attributing $643 million in H1 2026 crypto theft to North Korean hackers, representing approximately two-thirds of global crypto theft losses and 76% of YTD losses at time of April incidents.","source":"TRM Labs / UPI","source_url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"date":"2026-07-29","event":"Blockaid published H1 2026 crypto security report documenting a record 212 exploits and $1.1 billion in total losses, attributing approximately $609 million (55% of total) to North Korea-linked groups.","source":"Blockaid / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/29/crypto-hacks-cross-1-1b-in-record-h1-2026-losses-blockaid/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision ba9a4a32-1d54-4223-8b42-f2dbc0d613b7
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.