
According to security research firm CertiK, the Democratic People's Republic of Korea (DPRK) has transformed crypto thefts into a systematic state revenue mechanism. The firm's analysis reveals that DPRK-linked actors have stolen an estimated $6.75 billion across 263 incidents between 2016 and early 2026. In 2025 alone, North Korea was responsible for $2.06 billion in losses, representing 60% of the sector's $3.4 billion in yearly losses. As reported by CertiK, this systematic approach has elevated North Korean threat actors to become the industry's biggest crypto threat. The firm's latest report, which landed just days after TRM Labs implicated North Korean actors for approximately 76% of money lost to crypto hacks through April 2026, demonstrates that North Korean hackers are moving with better precision, causing far more losses in fewer incidents.
The current year has seen continued significant activity from North Korean threat groups. According to CertiK, so far in 2026, the country's threat actors have accounted for $620 million in losses out of the $1.1 billion in stolen funds. The firm noted that 2026 thefts accounted for 55% of total year-to-date (YTD) losses. Security firm TRM Labs estimates that the actual share of 2026 losses due to North Korean players was approximately 76% on a YTD basis, indicating an even higher impact than reported by CertiK. Counting the $285 million Drift Protocol breach on April 1 and the $292 million KelpDAO bridge exploit on April 18 alone, that's 3% of incident count and 76% of loot stolen in 2026, according to TRM Labs.
The scale of North Korean operations has included some of the industry's most significant breaches. According to CertiK, last year's $1.5 billion Bybit exploit was linked to the notorious Lazarus group, representing the largest single heist. This year's $294 million KelpDAO hack has been their biggest plunder, conducted by a new North Korea group separate from the Lazarus group. The attackers, TraderTraitor, a Lazarus Group-affiliated operation, exploited a single-verifier design flaw in a LayerZero bridge. After Arbitrum froze roughly $75 million of the stolen funds, the hackers pivoted to laundering through THORChain, converting stolen Ether (ETH) to Bitcoin (BTC). As reported by TRM Labs, the $285 million Drift breach followed in-person meetings between North Korean proxies and protocol employees, which the firm called an 'unprecedented' technique in the country's crypto hacking campaign. The $1.5 billion Bybit hack in February 2025, the largest single crypto theft ever recorded, demonstrated that "even institutional-grade multisig wallets can be compromised by targeting trusted third-party infrastructure rather than smart contracts," according to CertiK.
North Korean actors are employing sophisticated social engineering schemes rather than traditional software vulnerabilities. According to CertiK, most major DPRK operations begin with human manipulation, including fake job offers, VC impersonation, and malicious repositories. TRM Labs reported that North Korean proxies held in-person meetings with Drift employees before the breach. Between March 23 and March 30, the attacker exploited Solana's durable nonce feature to get Drift's multisig signers to pre-authorize transactions. Come April 1, the protocol was drained in 31 withdrawals that took roughly 12 minutes. ZachXBT traced $16.58 million in direct crypto payroll payments to North Korean operatives posing as developers between January and July 2025, according to Cryptopolitan's reporting. CertiK reported that DPRK operatives have infiltrated DeFi teams under false identities, in some cases directly enabling the theft of funds from within.
Following successful heists, North Korean threat groups employ sophisticated laundering techniques to obscure the origin of stolen funds. According to CertiK, after the heist, hackers would go quiet for a while before launching a laundering campaign by switching funds to BTC and moving them through crypto mixers such as Thorchain or Tornado Cash, DEXes, and OTC desks. This systematic approach allows the funds to be transferred through multiple platforms before reaching their final destination, making tracking and recovery significantly more difficult. TRM Labs noted that THORChain processed the majority of proceeds from both the Bybit breach and the KelpDAO hack, "converting hundreds of millions in stolen ETH to Bitcoin with no operator willing to freeze or reject transfers." CertiK reported that within one month of the Bybit hack, 86.29% of stolen ETH was converted to Bitcoin using mixers, cross-chain bridges, decentralized exchanges, and over-the-counter brokers.
The crypto industry has begun implementing enhanced security measures to combat North Korean threats. According to reports, there have been concerted efforts towards early threat monitoring across blockchains to mitigate the North Korean risk. Additionally, the U.S government is considering extending threat intelligence shared with financial firms to crypto companies, indicating a broader governmental approach to addressing this systematic threat. These initiatives represent efforts to create a more coordinated defense against North Korean cyber operations targeting the cryptocurrency sector. CertiK noted that U.S. intelligence assessments have indicated that funds stolen by North Korean cyber operations support the country's nuclear and ballistic missile programs, though North Korea has denied involvement, calling the allegations "absurd slander" spread by U.S. "government organs, reptile media organs and plot-breeding organizations."