Fact-check findings
What an automated fact-checker found when it re-read DPRK Crypto Theft H1 2026 (TRM Labs / Blockaid Report) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #13[unverifiable][awaiting moderator]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“Following the theft, funds were converted to ETH via Jupiter and bridged to Ethereum, where they reportedly remained dormant as of the TRM Labs report publication date.”
reviewerFollowing the Drift theft, funds were converted to ETH via Jupiter, bridged to Ethereum, and reportedly remained dormant as of the TRM Labs report publication dateCould not independently locate a source confirming the Jupiter conversion and subsequent dormancy of Drift proceeds specifically; not contradicted by any source found, just unconfirmed.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #4[link rot][awaiting moderator]in section: Overview and Scale
“https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks”
reviewerThe $643 million / two-thirds H1 2026 DPRK theft figure comes from a TRM Labs report published in July 2026The sentence's underlying claim ($643M, two-thirds, July 2026 report) is true, but is supported by a different TRM Labs URL than the one cited first in this section. The cited URL is live but is a distinct, earlier (April 30) report about a narrower $577M/76%-through-April figure.Proposed correction (not yet applied)https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion
partially supported
4 claimsThe cited evidence supports part of the claim but not all of it.
- #1[partially supported][awaiting moderator]in the summary
“North Korea-linked hacking groups, principally the Lazarus Group and its TraderTraitor subunit, stole between approximately $609 million and $643 million in cryptocurrency during the first half of 2026, representing roughly 55 to 76 percent of all global crypto theft losses over that period depending on methodology used by the reporting firm.”
reviewerDPRK-linked groups stole $609M-$643M in H1 2026, representing 55-76% of global crypto theft losses over that periodThe page presents 55% and 76% as two interchangeable 'methodologies' for describing the same H1 2026 period, but 76% is TRM's own YTD-through-April figure (tied to $577M from just the Drift and KelpDAO attacks), not a full-H1 figure. The correct full-H1 TRM percentage is approximately 66%, not 76%. This is a scope-blending overstatement rather than a fabrication. - #2[partially supported][awaiting moderator]in the summary
“Security firms TRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026 documenting the scale, attack vectors, and laundering behavior, with proceeds assessed by multiple U.S. government agencies and analysts as flowing into DPRK weapons-of-mass-destruction programs.”
reviewerTRM Labs and Blockaid each published H1 2026 recap reports in late June and July 2026TRM Labs' full H1 2026 report was published July 1, 2026 (covered by UPI on July 3); no TRM H1 recap was found dated 'late June.' Blockaid's report was published July 29, 2026, which is correctly described. - #20[partially supported][awaiting moderator]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“THORChain's volume surged approximately 18 times its typical daily level during the laundering window.”
reviewerTHORChain's volume surged approximately 18 times its typical daily level during the laundering windowThe '18x' figure is genuine but was reported alongside an earlier, smaller ($80M) tranche of the laundering, not confirmed as the final multiplier for the full $175M/36-hour episode; treated as approximately but not precisely supported. - #34[partially supported][awaiting moderator]in the timeline
“KelpDAO paused contracts, preventing an additional alleged $95 million in losses. Arbitrum governance froze approximately $75 million of stolen funds on the Arbitrum network.”
reviewerKelpDAO's contract pause prevented an additional $95M drain and Arbitrum froze ~$75M, as reported by the cited SpotedCrypto sourceThe underlying facts are true and confirmed by Chainalysis, but the specific source cited for this timeline entry (SpotedCrypto) does not itself support the $95 million figure. Suggest pointing the timeline entry's source_url to the Chainalysis research blog, which is already used elsewhere on the page for the same facts.
confirmed
28 claimsThe cited evidence supports the claim as written.
- #3[confirmed][no action needed]in the summary
“Two targeted attacks in April 2026 — against Drift Protocol ($285 million) and KelpDAO ($292 million) — accounted for the vast majority of attributed DPRK proceeds.”
reviewerTwo April 2026 attacks against Drift Protocol ($285M) and KelpDAO ($292M) accounted for the vast majority of attributed DPRK proceedsIndependently confirmed: the two April attacks total $577M, roughly 90% of TRM's $643M H1 DPRK figure. - #5[confirmed][no action needed]in section: Overview and Scale
“A separately published Blockaid H1 2026 report, released July 29, 2026, tracked a record 212 verified on-chain exploits and $1.1 billion in total losses, and attributed roughly $609 million — approximately 55 percent of H1 losses — to North Korea-linked groups including Lazarus and TraderTraitor.”
reviewerBlockaid's H1 2026 report, released July 29, 2026, tracked 212 verified on-chain exploits, $1.1 billion in total losses, and attributed $609 million (55%) to North Korea-linked groupsFully corroborated across three independent outlets. - #6[confirmed][no action needed]in section: Overview and Scale
“The divergence in attribution totals between the two reports reflects differing scope: the Blockaid figure includes the June 2026 Humanity Protocol exploit ($36 million), while TRM Labs' primary accounting focused on the two major April incidents.”
reviewerThe Blockaid $609M DPRK figure includes the June 2026 Humanity Protocol exploit ($36 million)Confirmed that Humanity Protocol is included in Blockaid's DPRK figure. Minor unresolved variance: some outlets (CoinDesk, Blockaid itself) cite Humanity Protocol's loss as $32M rather than $36M; the page's own cited sources consistently use $36M, so this is not flagged as a separate dispute. - #7[confirmed][no action needed]in section: Overview and Scale
“Cumulative DPRK-attributed cryptocurrency theft since 2017 has now surpassed $6 billion, according to TRM Labs.”
reviewerCumulative DPRK-attributed cryptocurrency theft since 2017 has surpassed $6 billionDirectly confirmed by TRM Labs reporting and secondary coverage. - #8[confirmed][no action needed]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“On April 1, 2026, attackers drained approximately $285 million from Drift Protocol, Solana's largest decentralized derivatives exchange, in a coordinated operation that executed approximately 31 withdrawals within a 12-minute window.”
reviewerOn April 1, 2026, $285 million was drained from Drift Protocol via ~31 withdrawals in a 12-minute windowWell corroborated across multiple independent reports. - #9[confirmed][no action needed]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“TRM Labs and Elliptic attributed the attack with medium confidence to UNC4736, a North Korean state-sponsored group also tracked as AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces.”
reviewerTRM Labs and Elliptic attributed the Drift attack with medium confidence to UNC4736 (AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces)Group aliases and medium-confidence framing are consistent with multiple outlets; minor variance exists in which specific firms are credited across different articles (Drift itself, CrowdStrike, Elliptic, TRM Labs all appear in different accounts), but the core attribution and alias list are accurate. - #10[confirmed][no action needed]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“The attack was the culmination of a six-month social engineering campaign that began in fall 2025.”
reviewerThe Drift attack was the culmination of a six-month social engineering campaign that began in fall 2025Directly confirmed. - #11[confirmed][no action needed]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“The attackers manipulated a fabricated asset — referred to as CarbonVote Token (CVT) — to gain governance access, and induced multisig signers to pre-authorize transactions weeks before execution, then pushed a zero-timelock governance migration that removed the protocol's review window.”
reviewerAttackers manipulated a fabricated 'CarbonVote Token (CVT)' asset to gain governance access, pre-authorized multisig transactions, and pushed a zero-timelock governance migrationConfirmed via independent search results describing the CVT wash-trading and durable-nonce governance hijack mechanics in detail. - #12[confirmed][no action needed]in section: Drift Protocol Exploit — April 1, 2026 ($285 Million)
“Two Drift contributors were compromised: one after cloning a malicious code repository, and a second after being persuaded to install a weaponized wallet application through Apple's TestFlight.”
reviewerTwo Drift contributors were compromised, one via a malicious repository clone and one via a TestFlight wallet appTestFlight detail directly confirmed by the primary cited source. - #14[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“On April 18, 2026, attackers drained approximately $292 million (116,500 rsETH) from KelpDAO's rsETH bridge built on LayerZero.”
reviewerOn April 18, 2026, $292 million (116,500 rsETH) was drained from KelpDAO's LayerZero-based rsETH bridgeDirectly confirmed via Chainalysis research blog. - #15[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“Cybersecurity firms including Chainalysis and security researchers attributed the attack to the Lazarus Group's TraderTraitor subunit.”
reviewerThe KelpDAO attack was attributed to the Lazarus Group's TraderTraitor subunitAttribution itself is confirmed, though it originates primarily from LayerZero rather than Chainalysis independently; Chainalysis reported and endorsed the finding. - #16[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“This was not a smart-contract exploit but an infrastructure attack: hackers compromised internal RPC nodes and executed a DDoS attack against external nodes, forcing the bridge's single decentralized validator node (a 1-of-1 DVN setup) to rely on poisoned data sources.”
reviewerThe KelpDAO attack was an infrastructure attack involving RPC node compromise, DDoS, and a poisoned 1-of-1 DVNTechnical mechanics precisely match the primary cited research source. - #17[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“KelpDAO paused contracts quickly enough to prevent an additional alleged $95 million drain.”
reviewerKelpDAO paused contracts in time to prevent an additional alleged $95 million drainDirectly confirmed. - #18[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“Arbitrum's governance subsequently froze approximately $75 million in stolen funds that remained on the Arbitrum network.”
reviewerArbitrum governance froze approximately $75 million of stolen KelpDAO fundsDirectly confirmed. - #19[confirmed][no action needed]in section: KelpDAO LayerZero Bridge Exploit — April 18, 2026 ($292 Million)
“The remaining approximately $175 million in ETH was moved to new wallets within roughly 36 hours and swapped primarily to Bitcoin via THORChain, a decentralized cross-chain protocol with no KYC requirements.”
reviewerApproximately $175 million in ETH was moved to new wallets within ~36 hours and swapped primarily to Bitcoin via THORChainEarlier reporting cited a smaller interim figure (~$80M) as the laundering was in progress; later, more complete reporting confirms the full $175M figure over ~36 hours, matching the page. - #21[confirmed][no action needed]in section: Humanity Protocol Exploit — June 8, 2026 ($36 Million)
“On June 8, 2026, Humanity Protocol suffered an alleged $36 million exploit affecting its H token contracts on Ethereum and BNB Chain.”
reviewerOn June 8, 2026, Humanity Protocol suffered a $36 million exploit affecting H token contracts on Ethereum and BNB Chain via a Bithumb-impersonation phishing email that exposed multisig bridge keysConfirmed, including the multisig/bridge-key detail; note some outlets (CoinDesk) use a $32M figure while $36M is the more widely repeated figure and matches the page's own cited sources. - #22[confirmed][no action needed]in section: Humanity Protocol Exploit — June 8, 2026 ($36 Million)
“The H token price fell over 80 percent intraday following disclosure on June 9.”
reviewerThe H token price fell over 80 percent intraday following disclosure on June 9Directly confirmed. - #23[confirmed][no action needed]in section: Threat Actor Attribution — Lazarus Group and TraderTraitor
“The FBI tracks a Lazarus subunit as TraderTraitor, which the bureau first identified in 2022 and which has been responsible for multiple large-scale DeFi bridge exploits, including the February 2025 Bybit theft of $1.5 billion — the largest single cryptocurrency theft on record.”
reviewerThe FBI tracks TraderTraitor as a Lazarus subunit, first identified in 2022, responsible for the Feb 2025 $1.5B Bybit theft — the largest crypto theft on recordFully corroborated. - #24[confirmed][no action needed]in section: Threat Actor Attribution — Lazarus Group and TraderTraitor
“TRM Labs reported that North Korea's share of global crypto hack losses has grown consistently year-over-year: approximately 10 percent during 2020 to 2021, 22 percent in 2022, 37 percent in 2023, 39 percent in 2024, 64 percent in 2025, and 76 percent of YTD losses as of the time of the April 2026 report.”
reviewerNorth Korea's share of global crypto hack losses grew year-over-year: ~10% (2020-2021), 22% (2022), 37% (2023), 39% (2024), 64% (2025), 76% YTD as of the April 2026 reportThis section correctly and precisely scopes the 76% figure to 'as of the time of the April 2026 report,' unlike the summary and Overview section, which blend it with the full-H1 figures without that qualifier. - #25[confirmed][no action needed]in section: Regulatory and Sanctions Actions
“On March 12, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned six individuals and two entities — Amnokgang Technology Development Company and Quangvietdnbg International Services Company Limited — for facilitating North Korean IT worker fraud schemes.”
reviewerOn March 12, 2026, OFAC sanctioned six individuals and two entities (Amnokgang Technology Development Company and Quangvietdnbg International Services Company Limited) for facilitating DPRK IT worker fraudDirectly confirmed via the primary Treasury source. - #26[confirmed][no action needed]in section: Regulatory and Sanctions Actions
“OFAC assessed that these networks generated nearly $800 million in 2024 to fund DPRK weapons programs.”
reviewerOFAC assessed these networks generated nearly $800 million in 2024 to fund DPRK weapons programsDirectly confirmed via primary source. - #27[confirmed][no action needed]in section: Regulatory and Sanctions Actions
“The designations included 21 cryptocurrency addresses across multiple blockchains and targeted operators in Vietnam, Laos, and Spain.”
reviewerThe OFAC designations included 21 cryptocurrency addresses across multiple blockchains and targeted operators in Vietnam, Laos, and SpainGeographic scope confirmed by primary source; address count corroborated by secondary reporting though not independently verified against the raw OFAC SDN list text. - #28[confirmed][no action needed]in section: Proceeds and Weapons Program Funding
“A formerly active U.N. Panel of Experts estimated in 2024 that illicit cyber activity accounted for approximately 40 percent of DPRK weapons funding.”
reviewerA now-disbanded U.N. Panel of Experts estimated in 2024 that illicit cyber activity accounted for ~40% of DPRK weapons fundingBoth the 40% figure and the panel's disbandment are independently confirmed. - #29[confirmed][no action needed]in section: Proceeds and Weapons Program Funding
“TRM Labs documented that North Korea's cumulative cryptocurrency theft since 2017 exceeds $6 billion, with $1.7 billion stolen in H1 2025 alone before declining to $643 million in H1 2026 — a decline TRM attributed to reduced number of successful operations rather than a reduced threat posture.”
reviewerNorth Korea's cumulative crypto theft since 2017 exceeds $6 billion, with $1.7 billion stolen in H1 2025 before declining to $643 million in H1 2026All figures independently corroborated. - #30[confirmed][no action needed]in section: Industry-Wide Context — H1 2026 Hack Landscape
“Blockaid's H1 2026 report recorded 212 verified on-chain exploits, the highest number for any six-month period on record, though total dollar losses of $1.1 billion were below the $2.3 billion recorded in H1 2025, a period that included the $1.5 billion Bybit theft.”
reviewerBlockaid's H1 2026 report recorded 212 exploits (a record), with $1.1B in losses below H1 2025's $2.3B, which included the $1.5B Bybit theftDirectly confirmed by the primary cited source. - #31[confirmed][no action needed]in section: Industry-Wide Context — H1 2026 Hack Landscape
“The four largest incidents — KelpDAO ($292 million), Drift Protocol ($285 million), Resolv, and CowSwap — accounted for approximately $707 million, or 64 percent of total H1 losses.”
reviewerThe four largest H1 2026 incidents (KelpDAO $292M, Drift $285M, Resolv, CowSwap) totaled ~$707 million, 64% of H1 lossesPrecisely confirmed with individual incident breakdown. - #32[confirmed][no action needed]in section: Industry-Wide Context — H1 2026 Hack Landscape
“Ethereum and Solana recorded the largest network-level losses at approximately $332 million and $326 million, respectively.”
reviewerEthereum and Solana recorded the largest network-level losses at approximately $332 million and $326 million, respectivelyDirectly confirmed. - #33[confirmed][no action needed]in section: Industry-Wide Context — H1 2026 Hack Landscape
“Blockaid also documented the emergence of AI agents as a new attack surface, with several incidents involving manipulation of on-chain AI agent infrastructure.”
reviewerBlockaid documented the emergence of AI agents as a new attack surface in H1 2026Confirmed as a genuine, documented finding of the Blockaid report.