North Korean Hackers Loot $500 Million in a Single Month, Becoming the Top Threat to Crypto Security

marsbitXuất bản vào 2026-04-23Cập nhật gần nhất vào 2026-04-23

Tóm tắt

North Korean hackers, particularly the notorious Lazarus Group and its subgroup TraderTraitor, have stolen over $500 million from cryptocurrency DeFi platforms in less than three weeks, bringing their total theft for the year to over $700 million. Recent major attacks on Drift Protocol and KelpDAO, resulting in losses of approximately $286 million and $290 million respectively, highlight a strategic shift: instead of targeting core smart contracts, attackers are now exploiting vulnerabilities in peripheral infrastructure. For instance, the KelpDAO attack involved compromising downstream RPC infrastructure used by LayerZero's decentralized validation network (DVN), allowing manipulation without breaching core cryptography. This sophisticated approach mirrors advanced corporate cyber-espionage. Additionally, North Korea has systematically infiltrated the global crypto workforce, with an estimated 100 operatives using fake identities to gain employment at blockchain companies, enabling long-term access to sensitive systems and facilitating large-scale thefts. According to Chainalysis, North Korean-linked hackers stole a record $2 billion in 2025, accounting for 60% of all global crypto theft that year. Their total historical crypto theft has reached $6.75 billion. Post-theft, they employ specialized money laundering methods, heavily relying on Chinese OTC brokers and cross-chain mixing services rather than standard decentralized exchanges. Security experts, while acknowledgi...

Written by: Oluwapelumi Adejumo

Compiled by: Chopper, Foresight News

In less than three weeks, hacker groups linked to North Korea have stolen over $500 million from cryptocurrency DeFi platforms, shifting their attack vectors from core smart contracts to vulnerabilities in the infrastructure's periphery.

Attacks on Drift and KelpDAO

Two major attacks targeting Drift Protocol and KelpDAO have pushed the illicit cryptocurrency gains of North Korean hackers this year past $700 million. The massive losses highlight a tactical shift: they are increasingly exploiting complex vulnerabilities and deep personnel penetration to bypass standard security defenses.

On April 20th, cross-chain infrastructure provider LayerZero confirmed that KelpDAO was attacked on April 18th, resulting in a loss of approximately $290 million, making it the largest single crypto theft case so far in 2026. The company stated that preliminary forensics directly point to TraderTraitor—a specialized unit within North Korea's notorious Lazarus Group.

Just weeks earlier, on April 1st, the Solana-based decentralized perpetual exchange Drift Protocol was robbed of approximately $286 million. Blockchain intelligence firm Elliptic quickly linked the on-chain money laundering techniques, transaction sequences, and network signatures to known North Korean attack patterns, noting this was the 18th similar incident they have tracked this year.

Attack Shift: Infiltrating the Infrastructure Periphery

The methods used in the April attacks demonstrate the increasing sophistication of North Korean hackers' attacks on DeFi. They are no longer directly assaulting core smart contracts but are instead finding and attacking structural edge vulnerabilities.

Taking the KelpDAO attack as an example: the hackers compromised the downstream RPC (Remote Procedure Call) infrastructure used by LayerZero Labs' Decentralized Verification Network (DVN). By tampering with these critical data channels, the attackers manipulated the protocol's operation without breaching the core cryptography. LayerZero has disabled the affected nodes and fully restored the DVN, but the financial losses are irreversible.

This indirect method of attack reveals a frightening evolution in cyber warfare. Blockchain security company Cyvers told CryptoSlate that North Korean-linked attackers are becoming more sophisticated, investing more resources in attack preparation and execution.

The company added: "We also observe that they always manage to pinpoint the weakest link precisely. This time, the entry point was a third-party component, not the protocol's core infrastructure."

This strategy is highly similar to traditional corporate cyber espionage and also means that North Korean-linked attacks are becoming increasingly difficult to prevent. Recent events, such as Google researchers linking the supply chain compromise of the widely used Axios npm software package to the specific North Korean threat group UNC1069, indicate that attackers are systematically sabotaging software before it even enters the blockchain ecosystem.

North Korea Infiltrates Global Crypto Industry Practitioners

Beyond technical breakthroughs, North Korea is also conducting a large-scale, organized infiltration of the global cryptocurrency labor market.

The threat model has shifted completely from remote hacking operations to placing malicious personnel directly into unsuspecting Web3 startups.

A six-month investigation by the Ketman Project under the Ethereum Foundation's ETH Rangers security program reached a startling conclusion: approximately 100 North Korean cyber operatives are潜伏 (latent - *Note: The original Chinese term "潜伏" is kept here for accuracy, but the intended meaning is "lying dormant" or "embedded") within various blockchain companies. They use forged identities, easily pass standard HR screenings, obtain access to sensitive internal code repositories, lie dormant within product teams for months or even years, and then launch precise attacks.

Independent blockchain investigator ZachXBT further confirmed this intelligence agency-style潜伏 (dormancy). He recently exposed a North Korean special network that generates approximately $1 million per month through remote employment using fraudulent identities.

This scheme processes cryptocurrency-to-fiat transfers through recognized global financial channels and has handled over $3.5 million since late 2025.

According to industry insiders, the overall deployed IT personnel by North Korea generate millions of dollars in revenue monthly. This provides North Korea with a dual income stream: stable salary income + massive protocol thefts assisted by insiders.

$6.75 Billion Total Theft

The scale of North Korea's digital asset operations far surpasses any traditional cybercrime group. According to blockchain analytics firm Chainalysis: in 2025 alone, North Korean-linked hackers stole a record $2 billion, accounting for 60% of the global cryptocurrency theft total that year.

Considering the fierce attacks this year, the total value of crypto assets stolen by North Korea throughout history has reached $6.75 billion.

Once funds are acquired, the Lazarus Group exhibits a highly specific, regionalized money laundering pattern: unlike ordinary crypto criminals who frequently use DEXs and peer-to-peer lending protocols, North Korean hackers deliberately avoid these channels. On-chain data shows they heavily rely on escrow services in Chinese-speaking regions, deep over-the-counter (OTC) broker networks, and complex cross-chain mixing services. This preference points to structural limitations and geographically constrained cashing-out channels, rather than unrestricted access to the global financial system.

Can It Be Prevented?

Security researchers and industry executives believe it can be prevented, but crypto companies must address the same operational weaknesses exposed in multiple major attacks.

Humanity founder Terence Kwok told CryptoSlate that North Korean-linked attacks still point to common vulnerabilities, not new forms of cyber intrusion. He believes North Korean attackers are improving their intrusion methods and illicit fund transfer capabilities, but the root cause remains poor access control and centralized operational risks.

He explained: "What's shocking is that the losses are still attributed to old problems like access control and single points of failure. This shows the industry still hasn't solved the problem of basic security discipline."

Based on this, Kwok pointed out that the industry's first line of defense is to significantly increase the difficulty of unauthorized asset transfers by implementing stricter controls on private keys, internal permissions, and third-party access rights. In practice, companies need to reduce reliance on individual operators, restrict privileged access, harden supplier dependencies, and add more verification checks to the infrastructure between core protocols and the external world.

The second line of defense is speed. Once stolen funds cross chains, bridges, or enter money laundering networks, the probability of recovery drops sharply. Kwok stated that exchanges, stablecoin issuers, blockchain analysis companies, and law enforcement agencies must collaborate extremely quickly in the first few minutes and hours after an attack to increase the success rate of fund interception.

His words highlight an industry reality: the most fragile points of crypto systems are often at the intersection of code, personnel, and operations. A stolen credential, a weak supplier dependency, or an overlooked permission vulnerability is enough to cause losses amounting to hundreds of millions of dollars.

The challenge for DeFi is no longer just writing robust smart contracts, but defending the operational security at the protocol's periphery before attackers exploit the next weak link.

Câu hỏi Liên quan

QWhat is the total amount of cryptocurrency stolen by North Korean hackers in the two major attacks on Drift Protocol and KelpDAO mentioned in the article?

AThe two major attacks on Drift Protocol and KelpDAO resulted in losses of approximately $286 million and $290 million respectively, totaling over $576 million, which contributed to North Korean hackers' illicit cryptocurrency gains exceeding $700 million for the year.

QHow have North Korean hackers shifted their attack strategies according to the article?

ANorth Korean hackers have shifted from directly attacking core smart contracts to exploiting structural edge vulnerabilities in infrastructure, such as compromising downstream RPC infrastructure used by decentralized validation networks (DVNs), as seen in the KelpDAO attack.

QWhat method are North Korean hackers using to infiltrate the global cryptocurrency workforce, as described in the article?

ANorth Korean hackers are conducting large-scale, organized infiltration by placing malicious personnel inside unsuspecting Web3 startups using forged identities, bypassing standard HR screenings, and gaining access to sensitive internal codebases to launch precise attacks after months or years of潜伏 (dormancy).

QWhat is the estimated total amount of cryptocurrency stolen by North Korea historically, as per the article?

AAccording to the article, North Korea has stolen a total of $6.75 billion in cryptocurrency historically, with a record $2 billion stolen in 2025 alone, accounting for 60% of global cryptocurrency theft that year.

QWhat are the key defensive measures suggested in the article to prevent such attacks?

AThe article suggests two key defensive measures: first, significantly increasing the difficulty of asset transfers by implementing stricter controls on private keys, internal permissions, and third-party access, reducing reliance on individual operators, and adding more checks between core protocols and external infrastructure; second, enhancing speed in response, where exchanges, stablecoin issuers, blockchain analysis firms, and law enforcement must collaborate rapidly within the first few minutes or hours after an attack to intercept funds.

Nội dung Liên quan

Tuần tới cần chú ý|Đạo luật CLARITY dự kiến được biểu quyết tại Thượng viện; SpaceX, Circle công bố báo cáo tài chính (3.8-9.8)

**Tóm tắt các sự kiện quan trọng từ ngày 3 đến 9 tháng 8:** **Tuần tới sẽ có nhiều sự kiện đáng chú ý trong lĩnh vực tiền điện tử và công nghệ:** * **Pháp luật & Quy định:** Dự luật CLARITY Act, nhằm thiết lập khung quy định liên bang cho tiền điện tử, có khả năng được đưa ra biểu quyết toàn thể tại Thượng viện Mỹ vào tuần tới. Các nhà đàm phán cần đạt được 60 phiếu ủng hộ trước ngày 7/8. * **Báo cáo tài chính:** Nhiều công ty lớn sẽ công bố báo cáo tài chính quý II/2026, bao gồm **SpaceX (ngày 4/8)**, công ty khai thác Bitcoin **Hut 8 (ngày 4/8)**, **Circle (ngày 5/8)** và công ty khai thác liên quan đến gia đình Trump là **American Bitcoin (ngày 3/8)**. * **Sự kiện SpaceX:** Bên cạnh báo cáo tài chính, cổ phiếu của SpaceX sẽ bắt đầu được mở khóa từ ngày 6/8, với đợt đầu tiên có thể lên tới 12% tổng số cổ phiếu. * **Dữ liệu kinh tế:** Báo cáo việc làm phi nông nghiệp (Non-Farm) quan trọng của Mỹ cho tháng 7 sẽ được công bố vào ngày 7/8. * **Cập nhật công nghệ:** * **XRP Ledger:** Phiên bản mới xrpld 3.3.0 với 5 tính năng mới dự kiến phát hành vào tuần tới. * **Grok:** Elon Musk thông báo Grok 4.6 dự kiến ra mắt vào khoảng ngày 7/8. * **Bitcoin:** Việc gửi tín hiệu bắt buộc cho BIP-110 sẽ bắt đầu vào khoảng ngày 8/8. * **Ngừng hoạt động:** Một số dịch vụ tiền điện tử sẽ ngừng hoạt động vào ngày 3/8, bao gồm công cụ theo dõi danh mục DeFi **Zapper** và ví **Ctrl Wallet**. * **Niêm yết & Hủy niêm yết:** Sàn Upbit Hàn Quốc sẽ hủy niêm yết token AQT và AERGO từ ngày 3/8. Trong khi đó, công ty robot **宇树科技 (Unitree Robotics)** sẽ tiến hành thăm dò giá ban đầu cho đợt IPO trên STAR Market vào ngày 5/8.

marsbit18 phút trước

Tuần tới cần chú ý|Đạo luật CLARITY dự kiến được biểu quyết tại Thượng viện; SpaceX, Circle công bố báo cáo tài chính (3.8-9.8)

marsbit18 phút trước

Cổ phiếu giảm mạnh hơn cả tiền điện tử, tiền đã đi đâu?

Tác giả: Cathy, Baihua Blockchain Vào ngày 28 và 29 tháng 7, chỉ số Kospi của Hàn Quốc hai ngày liên tiếp kích hoạt cơ chế ngắt mạch (circuit breaker), một sự kiện chưa từng có trong lịch sử. Cổ phiếu bán dẫn toàn cầu lao dốc, đặc biệt là SK Hynix – cổ phiếu trọng số lớn nhất, giảm khoảng 23% sau hai ngày. Điều trớ trêu là, trong khi thị trường chứng khoán biến động dữ dội như tiền mã hóa, Bitcoin lại thể hiện sự ổn định tương đối, phục hồi gần 15% từ mức thấp tháng 7. Bài viết phân tích rằng đợt sụt giảm này không phải là sự hoảng loạn toàn thị trường, mà là một cuộc "giải tỏa đòn bẩy cưỡng chế" nhắm vào các giao dịch đầu cơ tập trung nhất, như lĩnh vực bán dẫn và AI. Các yếu tố thúc đẩy bao gồm báo cáo lợi nhuận không đạt kỳ vọng của SK Hynix, sự cạnh tranh tiềm tàng từ Trung Quốc, và việc Ngân hàng Nhật Bản tăng lãi suất khiến các khoản đầu tư mang theo (carry trade) bằng Yên phải thoái vốn. Vậy tiền từ thị trường chứng khoán có chảy vào Bitcoin không? Câu trả lời là không. Bitcoin "kháng sụt giảm" vì nó đã trải qua đợt bán tháo lớn vào tháng 5 và tháng 6, với dòng tiền ròng rút kỷ lục khỏi các ETF Bitcoin Mỹ. Tiền thực sự đã chảy vào tài sản an toàn truyền thống như vàng, với hệ số tương quan giữa Bitcoin và vàng giảm xuống mức rất thấp. Điều này cho thấy Bitcoin hiện được coi là tài sản mạo hiểm để tìm kiếm lợi nhuận, chứ không phải nơi trú ẩn an toàn. Bài viết kết luận rằng để dòng tiền thực sự quay trở lại với Bitcoin, cần ba điều kiện: áp lực thanh khoản toàn cầu giảm bớt, Fed cắt giảm lãi suất mà không gây ra suy thoái, và Đạo luật CLARITY được thông qua để giải tỏa lo ngại về quy định. Mặc dù tiền chưa chảy vào, Bitcoin đã tự định vị mình như một tài sản có tương quan thấp với Nasdaq, một đặc điểm mà các tổ chức có thể tìm kiếm để đa dạng hóa danh mục đầu tư sau cú sốc AI.

marsbit19 phút trước

Cổ phiếu giảm mạnh hơn cả tiền điện tử, tiền đã đi đâu?

marsbit19 phút trước

Đối thoại với Ray Dalio: Chúng ta đang ở trong bong bóng AI, 1% danh mục đầu tư của tôi là Bitcoin

Ray Dalio, người sáng lập Bridgewater Associates, trong một cuộc phỏng vấn đã chỉ ra rằng thế giới hiện tại đang trong một "AI bubble" (bong bóng AI) cổ điển, với giá tài sản tăng vọt và đầu cơ quá mức. Ông cảnh báo bong bóng có thể vỡ do lãi suất tăng, nguồn cung cổ phiếu dư thừa hoặc khi nhà đầu tư cần tiền mặt trả nợ, dẫn đến suy thoái kinh tế. Đồng thời, Dalio mô tả một "chu kỳ lớn" kéo dài khoảng 80 năm, bao gồm ba động lực chồng chéo: khoảng cách giàu nghèo và xung đột nội bộ, thâm hụt ngân sách chính phủ khổng lồ và thay đổi địa chính trị. Ông nhấn mạnh rằng Mỹ và Anh đang đối mặt với những thách thức trong giai đoạn suy yếu này. Để bảo vệ của cải, Dalio khuyến nghị đa dạng hóa danh mục đầu tư với cổ phiếu, vàng, trái phiếu, bất động sản thay vì chỉ giữ tiền mặt. Ông tiết lộ khoảng 1% danh mục của mình là Bitcoin, nhưng vẫn ưa chuộng vàng vật chất hơn do tính ổn định và vai trò tiền tệ dự trữ. Về tác động của AI, Dalio cho rằng nó không chỉ thay thế lao động chân tay mà còn cả tư duy, làm trầm trọng thêm bất bình đẳng thu nhập. Con người cần phát huy trí tuệ cảm xúc và trực giác - những thứ AI chưa có - và học cách hợp tác với AI. Cuối cùng, ông phân tích những rủi ro của thuế tài sản và xu hướng thế giới có thể trở nên "khu vực hóa" hơn, với các khối như châu Mỹ và châu Á - Thái Bình Dương, trong bối cảnh sự thống trị toàn cầu của Mỹ đang suy yếu.

marsbit4 giờ trước

Đối thoại với Ray Dalio: Chúng ta đang ở trong bong bóng AI, 1% danh mục đầu tư của tôi là Bitcoin

marsbit4 giờ trước

Hơn 7.2 nghìn tỷ won trong một ngày, ngoại hải nước ngoài mua ròng kỷ lục vào thứ Sáu! Phố Wall: Cơn gió ngược về mặt vốn của thị trường chứng khoán Hàn Quốc đã tan biến

Dòng vốn nước ngoài đổ mạnh vào thị trường chứng khoán Hàn Quốc (KOSPI) với mức mua ròng kỷ lục 7,2 nghìn tỷ won chỉ trong ngày 31/7, đánh dấu sự đảo chiều rõ rệt sau nhiều tháng bán ròng mạnh. Theo báo cáo từ Citigroup, áp lực bán từ dòng vốn nước ngoài đã giảm đáng kể, với mức bán ròng tháng 7 thu hẹp còn 9,8 nghìn tỷ won so với mức 48,4 và 44,5 nghìn tỷ won trong tháng 6 và tháng 5. Đồng thời, các quỹ hưu trí và quỹ đầu tư trong nước cũng chuyển sang vị thế mua ròng 1,0 nghìn tỷ won trong tháng 7. Một yếu tố hỗ trợ khác là quy định mới từ Ủy ban Dịch vụ Tài chính Hàn Quốc (FSC), có hiệu lực từ 31/7, siết chặt điều kiện đầu tư vào các ETF có đòn bẩy đối với nhà đầu tư cá nhân. Quy định này đã ngay lập tức làm giảm khoảng 50% khối lượng giao dịch của các ETF này, góp phần kỳ vọng giảm bớt biến động cho thị trường. Citigroup duy trì mục tiêu chỉ số KOSPI ở mức 10.000 điểm, dựa trên các yếu tố thuận lợi như ngành chip bán dẫn ổn định, định giá thị trường thấp, nền tảng kinh tế vững mạnh và các chính sách hỗ trợ. Họ nhận định áp lực dòng vốn ngược chiều đang giảm dần, tạo điều kiện cho các yếu tố cơ bản và chính sách tích cực phát huy tác dụng.

marsbit4 giờ trước

Hơn 7.2 nghìn tỷ won trong một ngày, ngoại hải nước ngoài mua ròng kỷ lục vào thứ Sáu! Phố Wall: Cơn gió ngược về mặt vốn của thị trường chứng khoán Hàn Quốc đã tan biến

marsbit4 giờ trước

Giao dịch

Giao ngay
活动图片