North Korea's Lazarus Drains $577M in Two Attacks: A Six-Month Playbook Against Drift and KelpDAO

North Korea's Lazarus Drains $577M in Two Attacks: A Six-Month Playbook Against Drift and KelpDAO

N
News Editor 01
2026-07-23 23:00:15
North Korea's Lazarus Group stole $577 million from Drift Protocol and KelpDAO in April 2026, representing 76% of all crypto theft year-to-date, using social engineering and bridge vulnerabilities.
North KoreaLazarus GroupDrift ProtocolKelpDAOcrypto security

In April 2026, two hacks stole $577 million from cryptocurrency protocols, accounting for 76% of all crypto theft year-to-date. Both were the work of North Korea's Lazarus Group.

On April 1 at 16:06:09 UTC, Drift Protocol, Solana's largest decentralized perpetual exchange, lost approximately $285 million in user assets. The first withdrawal moved 41.72 million JLP tokens; the last moved 2,200 wrapped ETH. The entire treasury was drained in twelve minutes. The team's first public post asked if anyone was playing an April Fools' joke. They weren't. It was the culmination of six months of preparation by operatives working for the North Korean government.

Seventeen days later, on April 18, attackers stole $292 million from KelpDAO, a restaking protocol, by exploiting a single-verifier configuration in its LayerZero bridge. The two attacks combined accounted for roughly 95% of April's $625 million total theft, making April 2026 the worst month for crypto security on record. TRM Labs pinned 76% of the entire 2026 total on these two events — both tied to the same threat actor.

The Drift Operation: Six Months to Set Up, Twelve Minutes to Execute

Drift's post-mortem reads like a counterintelligence report. It starts in October 2025 at a major crypto conference. Individuals posing as a quantitative trading firm approached Drift contributors with verified backgrounds, technical fluency, and questions an institutional partner would ask. Drift treated them as a potential partner.

Over six months, the same operatives — or others using the same identities — attended multiple industry events to deepen relationships with specific contributors. A Telegram group was set up for strategy discussions. Between December 2025 and January 2026, the fake firm deposited over $1 million into Drift as a partner vault.

By February-March 2026, trust was sufficient for contributors to share repositories and apps. Attackers used two malware vectors: a repository that triggered silent code execution when opened in VSCode or Cursor, and a wallet app distributed via Apple's TestFlight that compromised the device.

Once attackers had machine access, they targeted wallets. On March 23, over a week before the theft, they set up four wallets using Solana's durable nonce feature — two belonged to compromised Security Council signers, two were attacker-controlled. Through social engineering and compromised devices, they obtained multisig approvals from two of five signers.

On April 1, while the Drift team executed a routine insurance fund withdrawal, attackers executed two pre-signed transactions four block slots apart. They seized admin control, introduced a synthetic token CarbonVote Token (CVT), manipulated its price via wash trading, and raised the USDC withdrawal limit to 500 trillion. CVT was then deposited as collateral to drain the treasury — $285 million gone in 12 minutes. Attackers swapped stolen assets to USDC via Jupiter, then bridged ~129,000 ETH ($270 million) to Ethereum through Circle's CCTP. Circle did not freeze funds.

Not Smart Contract Hacks: A Pattern That Has Worked for Five Years

Every major Lazarus DeFi attack of the past three years shares the same fingerprint: a compromised human signer, a weakened multisig configuration, a missing timelock, and a malicious payload disguised as routine. The $1.5 billion Bybit hack in February 2025 used the same approach. The 2022 Ronin Bridge hack ($625 million) started with fake LinkedIn job offers. The 2024 DMM Bitcoin hack ($300 million) began with a fake recruiter approaching an engineer. The 2023 CoinsPaid attack followed the same playbook.

Smart contract auditing is now standard in DeFi — nearly every protocol has multiple audits and bug bounties. None of that catches a six-month social engineering campaign targeting human signers. The gap between code security and operational security is exactly what Lazarus has industrialized over five years.

Two new wrinkles in 2026: AI-augmented coding tools as an attack vector (opening a repository can trigger silent code execution), and attackers themselves using AI to generate convincing fake personas and speed up reconnaissance.

The United Nations Panel of Experts on North Korea estimates that crypto theft funds a material portion of the DPRK's missile and nuclear weapons development budget. This is not a crypto security problem. This is a state-sponsored intelligence operation.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.