/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

North Korea-linked hackers stole ~$577M across the Drift Protocol and KelpDAO hacks from January to April, accounting for 76% of total crypto hack losses YTD

TRM Insights

Context & Ripple Effects

The reported losses extend a recurring pattern in the related coverage: TRM previously attributed almost a third of 2023 crypto theft to North Korea-affiliated actors, while later Chainalysis coverage described their share of 2024 losses as above 60%.

The concentration of early-2026 losses in two incidents matters because it suggests that a small number of successful attacks can again dominate the sector’s annual security toll, rather than losses being broadly dispersed across many smaller breaches.

First-order effects

  • Drift Protocol, KelpDAO and their affected users bear the immediate financial and operational fallout from the reported thefts, including the need to account for and contain compromised assets.
  • North Korea-linked actors account for 76% of year-to-date crypto hack losses in the report, making them the dominant identified source of losses in this period.

Second-order effects

  • The concentration of losses increases pressure on crypto services and their counterparties to tighten security controls and transaction monitoring around high-value protocol interactions.
  • Security vendors, insurers and institutional users are likely to treat protocol-level exposure as more consequential when a small set of breaches can determine most annual losses.

Third-order effects

  • If this concentration persists, crypto security risk will increasingly be framed as a persistent, state-linked threat rather than a collection of isolated protocol failures.
  • The pattern could widen the crypto legitimacy gap: repeated large thefts may sustain demands for stronger safeguards and more defensible risk management before broader institutional participation.

The trend: This is another data point in the continuing concentration of crypto theft losses among North Korea-linked operations, despite the sector’s evolving security infrastructure.