North Korea-linked hackers stole ~$577M across the Drift Protocol and KelpDAO hacks from January to April, accounting for 76% of total crypto hack losses YTD
Context & Ripple Effects
The reported losses extend a recurring pattern in the related coverage: TRM previously attributed almost a third of 2023 crypto theft to North Korea-affiliated actors, while later Chainalysis coverage described their share of 2024 losses as above 60%.
The concentration of early-2026 losses in two incidents matters because it suggests that a small number of successful attacks can again dominate the sector’s annual security toll, rather than losses being broadly dispersed across many smaller breaches.
First-order effects
- Drift Protocol, KelpDAO and their affected users bear the immediate financial and operational fallout from the reported thefts, including the need to account for and contain compromised assets.
- North Korea-linked actors account for 76% of year-to-date crypto hack losses in the report, making them the dominant identified source of losses in this period.
Second-order effects
- The concentration of losses increases pressure on crypto services and their counterparties to tighten security controls and transaction monitoring around high-value protocol interactions.
- Security vendors, insurers and institutional users are likely to treat protocol-level exposure as more consequential when a small set of breaches can determine most annual losses.
Third-order effects
- If this concentration persists, crypto security risk will increasingly be framed as a persistent, state-linked threat rather than a collection of isolated protocol failures.
- The pattern could widen the crypto legitimacy gap: repeated large thefts may sustain demands for stronger safeguards and more defensible risk management before broader institutional participation.
The trend: This is another data point in the continuing concentration of crypto theft losses among North Korea-linked operations, despite the sector’s evolving security infrastructure.