Skip to main content
Sign in

Audit log

Every state-changing event for DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-05 17:11:48Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    9TqgxhahEthF…Kox6U6AGsha256 → base58
    verifying row…
    canonical bytes (35826 B) ▸
    {"actor":"system:backfill","investigation_id":"c49012e3-b93a-4bfd-8c00-35468b644e6f","kind":"publish","page_slug":"dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign","published_at":"2026-08-05T17:11:48.561Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign","sections":[{"content":"The April 2026 Lazarus blitz consists of two discrete but linked attacks attributed to North Korea-aligned threat actors. The Drift Protocol hack on April 1, 2026, is attributed by TRM Labs, Elliptic, and Chainalysis to North Korean state-linked operators. Drift Protocol itself stated with 'medium-high confidence' on April 5 that the attack was carried out by 'the same threat actors responsible for the October 2024 Radiant Capital hack,' which Mandiant attributed to UNC4736 (also known as AppleJeus). The KelpDAO hack on April 18, 2026, is attributed by Mandiant, CrowdStrike, and independent security researchers to the DPRK subunit TraderTraitor, also identified as UNC4899. TRM Labs noted in a post-campaign summary that 'North Korea stole 76% of all crypto hack value in 2026 with just two attacks,' and that the two operations together drained $577 million — with some estimates citing up to $635 million when including estimated slippage and downstream liquidation losses. The cumulative DPRK crypto theft total since 2017 now exceeds $6 billion in attributed incidents. Pre-attack funding for both operations has been traced in part to wallets linked to prior DPRK laundering networks, including connections to Wu Huihui, a Chinese broker indicted for laundering Lazarus Group proceeds, via 2018-era Bitcoin wallets.","heading":"Overview and Attribution","severity":"critical","sources":[{"credibility":2,"name":"TRM Labs: North Korean Hackers Attack Drift Protocol in $285 Million Heist","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"credibility":2,"name":"TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 With Just Two Attacks","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Elliptic: Drift Protocol Exploited for $286 Million in Suspected DPRK-Linked Attack","type":"research","url":"https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"},{"credibility":1,"name":"UPI: North Korean hackers tied to $290M crypto heist","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"}]},{"content":"On April 1, 2026, attackers drained approximately $285–286 million from Drift Protocol, Solana's largest decentralized perpetual futures exchange, in approximately 12 minutes. The attack is the largest DeFi exploit of 2026 and the second-largest in Solana history, behind only the $326 million Wormhole bridge hack of 2022. The exploit did not involve any smart contract code vulnerability. Instead, it was a governance-layer attack enabled by months of social engineering. Threat actors are alleged to have posed as representatives of a legitimate quantitative trading firm, building credibility with Drift contributors over six months through industry conferences, Telegram conversations, and live vault integration sessions — a campaign reportedly beginning in autumn 2025. On-chain staging is traced to March 11, 2026, when funds were withdrawn from Tornado Cash to finance attack infrastructure. Attackers exploited Solana's 'durable nonces' feature, which allows transactions to be signed ahead of time and executed later. They induced Drift Security Council multisig signers to pre-authorize transactions they believed were routine governance steps. These hidden authorizations were then used to push a zero-timelock governance migration that stripped the Security Council's ability to detect and reverse malicious transactions. Once governance control was obtained, attackers whitelisted a worthless fabricated asset — the CarbonVote Token (CVT) — manipulated its oracle price via wash trading, deposited 500 million CVT as collateral, and used it to withdraw real assets including USDC, SOL, cbBTC, wBTC, and liquid staking tokens from three primary vaults: the JLP Delta Neutral vault (~$155 million in JLP), the SOL Super Staking vault, and the BTC Super Staking vault. A total of 31 withdrawal transactions were executed in roughly 12 minutes. Following the attack, stolen funds were rapidly bridged to Ethereum and remain largely dormant. As of July 2026, the attacker moved approximately $44.4 million (23,095 ETH) through Tornado Cash, the first significant fund movement in three months. Drift's DRIFT token fell more than 40% in the immediate aftermath. Tether and partners announced a $148 million recovery fund on April 16, 2026, with Drift set to relaunch as a USDT-settled exchange; the broader $295 million compensation strategy is structured as a revenue-sharing credit mechanism linked to future trading fees.","heading":"Drift Protocol Hack — April 1, 2026 ($285M)","severity":"critical","sources":[{"credibility":2,"name":"TRM Labs: North Korean Hackers Attack Drift Protocol in $285 Million Heist","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"credibility":2,"name":"Elliptic: Drift Protocol Exploited for $286 Million in Suspected DPRK-Linked Attack","type":"research","url":"https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"},{"credibility":2,"name":"Chainalysis: Drift Protocol Hack — How Privileged Access Led to a $285M Loss","type":"research","url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"credibility":2,"name":"Halborn: Explained — The Drift Hack (April 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-drift-hack-april-2026"},{"credibility":2,"name":"CCN: Drift Protocol Hit by $285M Exploit on April Fools Day","type":"news_article","url":"https://www.ccn.com/news/crypto/drift-protocol-285m-biggest-hack-2026-april-fools-day/"},{"credibility":1,"name":"CoinDesk: Drift Gets $148 Million Funding From Tether and Partners","type":"news_article","url":"https://www.coindesk.com/business/2026/04/16/drift-gets-usd148-million-funding-from-tether-and-partners-as-it-replaces-circle-stablecoin-with-usdt-after-massive-exploit"},{"credibility":2,"name":"CryptoTimes: $44.4M ETH Moved — Drift Protocol Exploiter Breaks 3-Month Silence","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/44-4m-eth-moved-drift-protocol-exploiter-breaks-3-month-silence/"}]},{"content":"On April 18, 2026, at 17:35 UTC, attackers drained 116,500 rsETH — valued at approximately $292 million — from KelpDAO's LayerZero-powered cross-chain bridge. At the time of exploitation, this represented approximately 18% of rsETH's total circulating supply of 630,000 tokens, making it the largest DeFi hack of 2026, surpassing the Drift exploit by approximately $7 million. The root cause was KelpDAO's use of a 1-of-1 DVN (single signer verification) configuration on its LayerZero bridge, where a single node was responsible for verifying cross-chain messages before releasing funds. The attacker did not compromise the verifier node directly. Instead, alleged DPRK-linked actors socially engineered a LayerZero Labs developer beginning March 6, 2026, harvesting session keys and pivoting into LayerZero's RPC cloud environment. Attackers gained access to two internal RPC nodes that KelpDAO's sole verifier relied upon as its data source, then injected fabricated cross-chain messages claiming that 116,500 rsETH had been legitimately locked on the source chain. The compromised verifier attested to these fabricated messages as valid, triggering the bridge to release the rsETH to an attacker-controlled address. A simultaneous DDoS attack against external validators ensured that the poisoned internal nodes were the sole available data source during the attack window. Two follow-up attempts at 18:26 and 18:28 UTC, each targeting approximately 40,000 additional rsETH (~$100 million), were blocked after KelpDAO initiated an emergency pause 46 minutes post-exploit at 18:21 UTC. KelpDAO's public acknowledgment came nearly three hours after the initial drain, at 20:10 UTC. The stolen rsETH was used as collateral for borrowing over 82,600 ETH (approximately $195 million) from Aave, creating approximately $177 million in bad debt on the platform that continues to compound. The attacker subsequently laundered approximately $175 million by converting funds to Bitcoin via THORChain. The Arbitrum Security Council froze approximately 30,766 ETH (~$71 million) linked to the exploit on Arbitrum One on April 21, 2026, triggering a governance debate about decentralization. On May 12, 2026, the Arbitrum DAO voted to implement a protocol-level lock. Legal proceedings have further complicated recovery: lawyers representing victims of a 2015 DPRK kidnapping obtained a US court order barring Arbitrum from releasing the frozen funds, claiming them as North Korean state assets under a 2015 judgment against Pyongyang. A dispute also emerged between KelpDAO and LayerZero over responsibility for the configuration, with Kelp claiming LayerZero had approved the 1-of-1 setup and subsequently blaming the victim protocol. KelpDAO announced it would migrate its bridge infrastructure to Chainlink CCIP. The exploit's cross-chain scope affected wrapped rsETH across 20+ blockchains including Base, Arbitrum, Linea, Blast, Mantle, and Scroll, and triggered emergency market freezes at Aave, SparkLend, Fluid, and Upshift.","heading":"KelpDAO Hack — April 18, 2026 ($292M)","severity":"critical","sources":[{"credibility":2,"name":"Chainalysis: Inside the KelpDAO Bridge Exploit","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":1,"name":"CoinDesk: 2026's Biggest Crypto Exploit — Kelp DAO Hit for $292 Million","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"credibility":2,"name":"LayerZero: KelpDAO Incident Report","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":2,"name":"LayerZero: KelpDAO Incident Statement","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":2,"name":"Halborn: Explained — The Kelp DAO Hack (April 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"credibility":1,"name":"TechCrunch: North Korean Hackers Blamed for $290M Crypto Theft","type":"news_article","url":"https://techcrunch.com/2026/04/20/north-korea-hackers-blamed-for-290m-crypto-theft/"},{"credibility":1,"name":"CoinDesk: Arbitrum Freezes $71 Million in Ether Tied to Kelp DAO Exploit","type":"news_article","url":"https://www.coindesk.com/markets/2026/04/21/arbitrum-freezes-usd71-million-in-ether-tied-to-kelp-dao-exploit"},{"credibility":1,"name":"CoinDesk: Kelp Claims LayerZero Approved Setup Blamed for $292 Million Hack","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":2,"name":"BeInCrypto: Arbitrum's KelpDAO Freeze Hit by US Court Order","type":"news_article","url":"https://beincrypto.com/arbitrum-kelpdao-court-order-freeze-recovery/"},{"credibility":2,"name":"KuCoin: KelpDAO rsETH Exploit — How the $292M LayerZero Bridge Attack Created $177M Bad Debt on Aave","type":"news_article","url":"https://www.kucoin.com/blog/kelpdao-rseth-exploit-how-292m-layerzero-bridge-attack-created-177m-bad-debt-in-aave"}]},{"content":"Both attacks demonstrate a shared operational pattern associated with DPRK-linked threat actors: prioritizing human and infrastructure vulnerabilities over technical smart contract exploits. The Drift attack employed a six-month social engineering campaign, with threat actors posing as a legitimate trading firm and meeting Drift contributors in person at industry events. Malware was allegedly delivered to engineering endpoints, enabling credential and signing key access. The KelpDAO attack began with social engineering of a LayerZero Labs developer on March 6, 2026, to harvest session keys. Both attacks involved sustained pre-positioning — Drift staging began on March 11 and the KelpDAO infiltration began on March 6 — suggesting coordinated DPRK operational planning across both targets simultaneously. Security researchers note that these attacks exemplify divergent North Korean laundering philosophies: the alleged Drift operators preferred patient, long-term holds with stolen funds remaining largely dormant for months, while the alleged TraderTraitor group responsible for KelpDAO prioritized rapid conversion and exit after encountering blockchain-level freezes. The use of Tornado Cash for pre-attack infrastructure financing (in the Drift case) and post-attack laundering (Drift, July 2026), combined with THORChain for large-scale cross-chain liquidation (KelpDAO), is consistent with patterns observed in prior DPRK-attributed hacks including the 2024 WazirX and 2025 Bybit incidents.","heading":"Attack Methods — Social Engineering and Infrastructure Compromise","severity":"critical","sources":[{"credibility":2,"name":"TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Chainalysis: Drift Protocol Hack — Privileged Access Led to $285M Loss","type":"research","url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"credibility":2,"name":"CM Alliance: Drift Protocol Hack Explained — $285M Governance Attack","type":"research","url":"https://www.cm-alliance.com/cybersecurity-blog/drift-protocol-hack-explained-285m-governance-attack"},{"credibility":2,"name":"OpenZeppelin: $292 Million Lost, Zero Bugs Found — Lessons From the rsETH Bridge Exploit","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"}]},{"content":"Following the Drift exploit, the majority of stolen assets — approximately $285 million comprising USDC, SOL, cbBTC, wBTC, and liquid staking tokens — were bridged to Ethereum within hours of the attack. The stolen funds remained largely dormant for approximately three months. On July 24, 2026, a wallet linked to the exploit transferred approximately 23,095 ETH ($44.4 million) to Tornado Cash, the first major laundering movement flagged by PeckShield. A separate 0.85 ETH transfer was also sent to Bybit. Security analysts describe Tornado Cash entry as near-terminal for on-chain traceability, though Chainalysis and Elliptic indicate wallet clustering and cross-chain analysis can still trace portions. For the KelpDAO exploit, the attacker converted 116,500 rsETH into approximately $195 million in ETH-denominated collateral on Aave via flash loan operations, then routed approximately $175 million to Bitcoin via THORChain after the Arbitrum Security Council froze $71 million on Arbitrum One. The Arbitrum freeze represents the largest single fund recovery action in the campaign. A US court order has since barred release of those funds, pending a legal claim by victims of a 2015 DPRK kidnapping under an existing federal judgment against North Korea.","heading":"Funds Movement and Laundering","severity":"high","sources":[{"credibility":2,"name":"CryptoTimes: $44.4M ETH Moved — Drift Protocol Exploiter Breaks 3-Month Silence","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/44-4m-eth-moved-drift-protocol-exploiter-breaks-3-month-silence/"},{"credibility":2,"name":"Cryptopolitan: $285M Drift Hacker Is Moving Funds Again After Months of Silence","type":"news_article","url":"https://www.cryptopolitan.com/285m-drift-hacker-funds-after-months/"},{"credibility":2,"name":"KuCoin Blog: Arbitrum Freezes 30,766 ETH From KelpDAO Hacker in May 2026","type":"news_article","url":"https://www.kucoin.com/blog/arbitrum-freezes-30766-eth-from-kelpdao-hacker-in-may-2026"},{"credibility":2,"name":"CryptoTimes: Arbitrum Freezes KelpDAO Hacker's $71M But Sparks Debate on Centralization","type":"news_article","url":"https://www.cryptotimes.io/2026/04/21/arbitrum-freezes-kelpdao-hackers-71m-but-sparks-debate-on-centralization/"},{"credibility":2,"name":"BeInCrypto: Arbitrum's KelpDAO Freeze Hit by US Court Order","type":"news_article","url":"https://beincrypto.com/arbitrum-kelpdao-court-order-freeze-recovery/"}]},{"content":"Drift Protocol secured a $148 million recovery fund on April 16, 2026, anchored by up to $127.5 million from Tether and $20 million from additional partners. The arrangement is structured as a revenue-sharing credit mechanism, directing a percentage of Drift's future trading fees into a designated recovery fund over an extended period. Drift plans to issue transferable 'recovery tokens' to affected users, giving them proportional claims on the recovery fund. The broader compensation target is approximately $295 million — covering the full range of user losses — with Drift planning to relaunch as a USDT-settled perpetual futures exchange, replacing its prior USDC settlement layer. KelpDAO announced a migration to Chainlink CCIP following the LayerZero exploit. Approximately $71 million in KelpDAO-linked funds was frozen by the Arbitrum Security Council and subsequently subject to a US court hold; the full recovery of these frozen assets remains unresolved as of August 2026. No confirmed recovery of Drift funds has been publicly announced. The combined recovery efforts remain partial relative to the $577–635 million in total alleged losses.","heading":"Recovery Efforts","severity":"high","sources":[{"credibility":1,"name":"CoinDesk: Drift Gets $148 Million Funding From Tether and Partners","type":"news_article","url":"https://www.coindesk.com/business/2026/04/16/drift-gets-usd148-million-funding-from-tether-and-partners-as-it-replaces-circle-stablecoin-with-usdt-after-massive-exploit"},{"credibility":2,"name":"Blockonomi: Drift Protocol Unveils $295M Recovery Strategy After Devastating Hack","type":"news_article","url":"https://blockonomi.com/drift-protocol-unveils-295m-recovery-strategy-after-devastating-hack/"},{"credibility":1,"name":"CoinDesk: Arbitrum Freezes $71 Million in Ether Tied to Kelp DAO Exploit","type":"news_article","url":"https://www.coindesk.com/markets/2026/04/21/arbitrum-freezes-usd71-million-in-ether-tied-to-kelp-dao-exploit"},{"credibility":3,"name":"KelpDAO on X: Migration to Chainlink CCIP Announcement","type":"social_media","url":"https://x.com/KelpDAO/status/2051755467328913637"}]},{"content":"The April 2026 campaign is the most concentrated single-month DPRK crypto theft event on record. North Korean-linked actors have been attributed with stealing approximately $2.02 billion across 80 incidents in 2025, a 51% year-over-year increase. Their cumulative attributed theft since 2017 has exceeded $6 billion, and some estimates citing the $1.5 billion Bybit hack in February 2025, the April 2026 campaign, and prior incidents push the all-time total to approximately $6.75 billion. The UN Panel of Experts has estimated that crypto theft proceeds fund a material portion of North Korea's ballistic missile and nuclear weapons development programs. The FBI has previously linked Lazarus Group to specific large-scale crypto thefts, including the $41 million Stake.com theft in 2023, and has named specific DPRK operators including Park Jin Hyok and Jon Chang Hyok on its most-wanted list. OFAC has sanctioned DPRK-linked entities and mixers including Tornado Cash and the Sinbad mixer as part of counter-efforts. The T3 Financial Crime Unit — a joint initiative between TRON, Tether, and TRM Labs — has worked to freeze funds linked to DPRK incidents, though its reported success against the April 2026 campaign has not been fully disclosed as of August 2026.","heading":"Broader DPRK Crypto Theft Context","severity":"high","sources":[{"credibility":2,"name":"TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Sanctions.io: The Lazarus Group and DPRK Crypto Theft in 2026","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":2,"name":"Hacken: Inside Lazarus Group — Analyzing North Korea's Most Infamous Crypto Hacks","type":"research","url":"https://hacken.io/discover/lazarus-group/"},{"credibility":1,"name":"FBI: Lazarus Group Cyber Actors Responsible for Theft of $41 Million from Stake.com","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"credibility":2,"name":"TechTimes: Crypto Hacks Hit All-Time High as North Korea Drains Over $600M","type":"news_article","url":"https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm"}]},{"content":"The Drift hack exposed significant risks in DeFi governance design, specifically the elimination of timelocks and the use of durable nonces in multisig configurations. Drift's Security Council had removed timelocks shortly before the attack, eliminating the review window that could have detected and reversed the malicious pre-signed transactions. Security researchers have noted that the attack exploited a combination of procedural and social vulnerabilities rather than technical code flaws, underscoring the limits of smart contract auditing as a security measure. The KelpDAO hack and the Arbitrum Security Council's subsequent decision to freeze $71 million in attacker funds sparked a broad debate within the crypto community about the nature of decentralization and the legitimacy of protocol-level intervention in theft recovery. CoinDesk and other outlets covered the freeze as a demonstration that Layer 2 governance retains meaningful centralized power, with governance votes capable of reversing or overriding on-chain outcomes. KelpDAO's attribution of the exploit to LayerZero's default configuration — and LayerZero's subsequent rebuttal — raised unresolved questions about responsibility assignment in cross-chain bridge security.","heading":"Governance and Decentralization Implications","severity":"medium","sources":[{"credibility":1,"name":"CoinDesk: Inside the $71 Million Freeze on Arbitrum That Has the Crypto World Questioning Decentralization","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/inside-the-usd71-million-freeze-on-arbitrum-that-has-the-crypto-world-questioning-what-decentralization-really-means"},{"credibility":1,"name":"CoinDesk: Kelp DAO Hits Back at LayerZero for Trying to Shift Blame After Massive Exploit","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/kelp-dao-claims-layerzero-s-default-settings-are-what-actually-caused-the-usd290-million-disaster"},{"credibility":2,"name":"OpenZeppelin: $292 Million Lost, Zero Bugs Found — Lessons From the rsETH Bridge Exploit","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"}]}],"sources_used":[{"credibility":2,"name":"TRM Labs: North Korean Hackers Attack Drift Protocol in $285 Million Heist","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"credibility":2,"name":"TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 With Just Two Attacks","type":"research","url":"https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks"},{"credibility":2,"name":"Elliptic: Drift Protocol Exploited for $286 Million in Suspected DPRK-Linked Attack","type":"research","url":"https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"},{"credibility":2,"name":"Chainalysis: Inside the KelpDAO Bridge Exploit","type":"research","url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"credibility":2,"name":"Chainalysis: Drift Protocol Hack — How Privileged Access Led to a $285M Loss","type":"research","url":"https://www.chainalysis.com/blog/lessons-from-the-drift-hack/"},{"credibility":1,"name":"CoinDesk: 2026's Biggest Crypto Exploit — Kelp DAO Hit for $292 Million","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"credibility":1,"name":"CoinDesk: Drift Gets $148 Million Funding From Tether and Partners","type":"news_article","url":"https://www.coindesk.com/business/2026/04/16/drift-gets-usd148-million-funding-from-tether-and-partners-as-it-replaces-circle-stablecoin-with-usdt-after-massive-exploit"},{"credibility":1,"name":"CoinDesk: Arbitrum Freezes $71 Million in Ether Tied to Kelp DAO Exploit","type":"news_article","url":"https://www.coindesk.com/markets/2026/04/21/arbitrum-freezes-usd71-million-in-ether-tied-to-kelp-dao-exploit"},{"credibility":1,"name":"CoinDesk: Kelp Claims LayerZero Approved Setup Blamed for $292 Million Hack","type":"news_article","url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"credibility":1,"name":"CoinDesk: Kelp DAO Hits Back at LayerZero","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/20/kelp-dao-claims-layerzero-s-default-settings-are-what-actually-caused-the-usd290-million-disaster"},{"credibility":1,"name":"CoinDesk: Inside the $71 Million Freeze on Arbitrum","type":"news_article","url":"https://www.coindesk.com/tech/2026/04/22/inside-the-usd71-million-freeze-on-arbitrum-that-has-the-crypto-world-questioning-what-decentralization-really-means"},{"credibility":1,"name":"TechCrunch: North Korean Hackers Blamed for $290M Crypto Theft","type":"news_article","url":"https://techcrunch.com/2026/04/20/north-korea-hackers-blamed-for-290m-crypto-theft/"},{"credibility":1,"name":"UPI: North Korean Hackers Tied to $290M Crypto Heist","type":"news_article","url":"https://www.upi.com/Top_News/World-News/2026/04/22/KelpDAO-LayerZero-North-Korea-crypto-hack-theft-Lazarus-Group/6151776848419/"},{"credibility":2,"name":"Halborn: Explained — The Drift Hack (April 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-drift-hack-april-2026"},{"credibility":2,"name":"Halborn: Explained — The Kelp DAO Hack (April 2026)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-kelp-dao-hack-april-2026"},{"credibility":2,"name":"LayerZero: KelpDAO Incident Report","type":"official","url":"https://layerzero.network/blog/layerzero-labs-kelpdao-incident-report"},{"credibility":2,"name":"LayerZero: KelpDAO Incident Statement","type":"official","url":"https://layerzero.network/blog/kelpdao-incident-statement"},{"credibility":2,"name":"OpenZeppelin: $292 Million Lost, Zero Bugs Found — Lessons From the rsETH Bridge Exploit","type":"research","url":"https://www.openzeppelin.com/news/lessons-from-kelpdao-hack"},{"credibility":2,"name":"Sanctions.io: The Lazarus Group and DPRK Crypto Theft in 2026","type":"research","url":"https://www.sanctions.io/blog/the-lazarus-group-and-dprk-crypto-theft-in-2026"},{"credibility":1,"name":"FBI: Lazarus Group Cyber Actors Responsible for Theft of $41 Million from Stake.com","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-identifies-lazarus-group-cyber-actors-as-responsible-for-theft-of-41-million-from-stakecom"},{"credibility":2,"name":"Hacken: Inside Lazarus Group — Analyzing North Korea's Most Infamous Crypto Hacks","type":"research","url":"https://hacken.io/discover/lazarus-group/"},{"credibility":2,"name":"KuCoin Blog: Arbitrum Freezes 30,766 ETH From KelpDAO Hacker in May 2026","type":"news_article","url":"https://www.kucoin.com/blog/arbitrum-freezes-30766-eth-from-kelpdao-hacker-in-may-2026"},{"credibility":2,"name":"CryptoTimes: $44.4M ETH Moved — Drift Protocol Exploiter Breaks 3-Month Silence","type":"news_article","url":"https://www.cryptotimes.io/2026/07/24/44-4m-eth-moved-drift-protocol-exploiter-breaks-3-month-silence/"},{"credibility":2,"name":"Cryptopolitan: $285M Drift Hacker Is Moving Funds Again After Months of Silence","type":"news_article","url":"https://www.cryptopolitan.com/285m-drift-hacker-funds-after-months/"},{"credibility":2,"name":"BeInCrypto: Arbitrum's KelpDAO Freeze Hit by US Court Order","type":"news_article","url":"https://beincrypto.com/arbitrum-kelpdao-court-order-freeze-recovery/"},{"credibility":2,"name":"Blockonomi: Drift Protocol Unveils $295M Recovery Strategy","type":"news_article","url":"https://blockonomi.com/drift-protocol-unveils-295m-recovery-strategy-after-devastating-hack/"},{"credibility":2,"name":"TechTimes: Crypto Hacks Hit All-Time High as North Korea Drains Over $600M","type":"news_article","url":"https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm"},{"credibility":2,"name":"CCN: Drift Protocol Hit by $285M Exploit on April Fools Day","type":"news_article","url":"https://www.ccn.com/news/crypto/drift-protocol-285m-biggest-hack-2026-april-fools-day/"},{"credibility":2,"name":"DeFiPrime: The KelpDAO rsETH Exploit — $292M Minted From a 1-of-1 Bridge","type":"research","url":"https://defiprime.com/kelpdao-rseth-exploit"}],"summary":"In April 2026, North Korea-linked threat actors attributed to the Lazarus Group and its subunits executed two separate, high-value cryptocurrency exploits within 18 days — draining approximately $285 million from Drift Protocol on April 1 and approximately $292 million from KelpDAO on April 18. Combined, the two attacks account for an estimated $577–635 million in losses, comprising 76% of all documented cryptocurrency hack value through April 2026 and representing the largest coordinated DPRK crypto theft campaign on record.","timeline":[{"date":"2025-09-01","event":"Alleged DPRK-linked threat actors begin a six-month social engineering campaign against Drift Protocol, posing as a quantitative trading firm and making contact at industry events.","source":"TRM Labs / Elliptic","source_url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"date":"2026-03-06","event":"Alleged DPRK-linked actors socially engineer a LayerZero Labs developer, harvesting session keys and gaining access to LayerZero's RPC cloud environment in the early stages of the KelpDAO operation.","source":"Mandiant / CrowdStrike via Chainalysis","source_url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/"},{"date":"2026-03-11","event":"On-chain staging for the Drift hack begins: funds withdrawn from Tornado Cash to finance attack infrastructure. Attacker wallet created approximately 21 days before the attack.","source":"TRM Labs","source_url":"https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist"},{"date":"2026-04-01","event":"Drift Protocol is drained of approximately $285–286 million in 31 transactions over roughly 12 minutes. Stolen assets include USDC, SOL, cbBTC, wBTC, and liquid staking tokens. Stolen funds are bridged to Ethereum within hours. DRIFT token falls over 40%.","source":"Elliptic / TRM Labs / CoinDesk","source_url":"https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"},{"date":"2026-04-05","event":"Drift Protocol states with 'medium-high confidence' that the attack was carried out by the same threat actors responsible for the 2024 Radiant Capital hack, attributed by Mandiant to UNC4736.","source":"Drift Protocol / Elliptic","source_url":"https://www.elliptic.co/blog/drift-protocol-exploited-for-286-million-in-suspected-dprk-linked-attack"},{"date":"2026-04-16","event":"Tether and partners announce a $148 million recovery fund for Drift Protocol. Drift plans to relaunch as a USDT-settled perpetual futures exchange with a $295 million total compensation target.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/04/16/drift-gets-usd148-million-funding-from-tether-and-partners-as-it-replaces-circle-stablecoin-with-usdt-after-massive-exploit"},{"date":"2026-04-18","event":"KelpDAO is drained of 116,500 rsETH (~$292 million) via a compromised LayerZero bridge configuration at 17:35 UTC. Two follow-up attempts (~$100M each) are blocked after an emergency pause 46 minutes post-exploit.","source":"CoinDesk / Halborn / LayerZero","source_url":"https://www.coindesk.com/tech/2026/04/19/2026-s-biggest-crypto-exploit-kelp-dao-hit-for-usd292-million-with-wrapped-ether-stranded-across-20-chains"},{"date":"2026-04-20","event":"KelpDAO attributes the exploit to LayerZero's default 1-of-1 DVN configuration. LayerZero disputes responsibility. TechCrunch reports North Korean hacker attribution.","source":"TechCrunch / CoinDesk","source_url":"https://techcrunch.com/2026/04/20/north-korea-hackers-blamed-for-290m-crypto-theft/"},{"date":"2026-04-21","event":"Arbitrum Security Council freezes approximately 30,766 ETH (~$71 million) linked to the KelpDAO exploit on Arbitrum One, sparking a debate about decentralization.","source":"CoinDesk / CryptoTimes","source_url":"https://www.coindesk.com/markets/2026/04/21/arbitrum-freezes-usd71-million-in-ether-tied-to-kelp-dao-exploit"},{"date":"2026-04-27","event":"KelpDAO and Aave request Arbitrum to release the $71 million in frozen ETH for recovery and bad debt resolution purposes.","source":"The Coin Republic","source_url":"https://www.thecoinrepublic.com/2026/04/27/kelpdao-aave-team-request-arbitrum-to-release-71m-frozen-ethereum-after-292m-hack/"},{"date":"2026-05-05","event":"KelpDAO publicly states that LayerZero approved the 1-of-1 DVN setup it later blamed for the $292 million exploit.","source":"CoinDesk","source_url":"https://www.coindesk.com/web3/2026/05/05/kelp-claims-that-layerzero-approved-the-setup-it-blamed-for-usd292-million-bridge-hack"},{"date":"2026-05-12","event":"Arbitrum DAO votes to implement a protocol-level lock on KelpDAO exploit-linked assets.","source":"KuCoin Blog","source_url":"https://www.kucoin.com/blog/arbitrum-freezes-30766-eth-from-kelpdao-hacker-in-may-2026"},{"date":"2026-07-24","event":"A wallet linked to the Drift exploit transfers approximately 23,095 ETH ($44.4 million) to Tornado Cash — the first major laundering movement since the April 1 attack. PeckShield flags the transactions.","source":"CryptoTimes / Cryptopolitan","source_url":"https://www.cryptotimes.io/2026/07/24/44-4m-eth-moved-drift-protocol-exploiter-breaks-3-month-silence/"},{"date":"2026-08-01","event":"A US court order bars Arbitrum from releasing the $71 million frozen after the KelpDAO hack, with lawyers for 2015 DPRK kidnapping victims claiming the funds as North Korean state assets under a pre-existing federal judgment.","source":"BeInCrypto","source_url":"https://beincrypto.com/arbitrum-kelpdao-court-order-freeze-recovery/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 519eaab5-3e24-4d07-b9a7-96f8989c668e
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.