No Result
View All Result
  • Login
Tuesday, June 23, 2026
theadvisertimes.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
theadvisertimes.com
No Result
View All Result
Home Cryptocurrency

North Korea stole $500 million from crypto in 20 days

by theadvisertimes.com
2 months ago
in Cryptocurrency
Reading Time: 6 mins read
A A
0
North Korea stole 0 million from crypto in 20 days
Share on FacebookShare on TwitterShare on LInkedIn


Make CryptoSlate preferred on

In just under three weeks, cyber operatives linked to the Democratic People’s Republic of Korea (DPRK) have stolen more than $500 million from crypto DeFi platforms.

This marks a drastic escalation in Pyongyang’s state-sponsored campaign to bankroll its weapons programs through cryptocurrency theft.

Drift and KelpDAO drive North Korea’s over $500 million DeFi exploits

Notably, the twin devastating exploits targeting the Drift Protocol and KelpDAO have pushed North Korea’s illicit crypto haul for the year well past the $700 million mark.

The staggering losses underscore a shift in tactics by Kim Jong Un’s cyber army, which is increasingly weaponizing complex supply-chain vulnerabilities and executing deep-cover human infiltration to bypass standard security perimeters.

On April 20, cross-chain infrastructure provider LayerZero confirmed that KelpDAO suffered an exploit resulting in the loss of approximately $290 million. The breach, which occurred on April 18, now stands as the largest single crypto hack of 2026.

The firm stated that preliminary forensics point directly to TraderTraitor, a specialized cell operating within North Korea’s notorious Lazarus Group.

Just weeks earlier, on April 1, the Solana-based decentralized perpetual futures exchange Drift Protocol was drained of an estimated $286 million.

Blockchain intelligence firm Elliptic swiftly connected the on-chain laundering methodologies, transaction sequencing, and network-level signatures to previously established DPRK attack vectors, noting it was the 18th such incident the firm had tracked this year alone.

Compromised developers lying dormant within crypto projects risks next major crypto exploitCompromised developers lying dormant within crypto projects risks next major crypto exploit
Related Reading

Compromised developers lying dormant within crypto projects risks next major crypto exploit

The bigger risk after Drift may be the access attackers gain before a protocol knows it has a problem.

Apr 8, 2026 · Gino Matos

Exploiting the infrastructure periphery

The methodology behind the April attacks reveals a maturation in how state-sponsored hackers target decentralized finance (DeFi). Instead of attacking hardened core smart contracts head-on, operatives are identifying and exploiting the structural periphery.

In the case of the KelpDAO attack, LayerZero explained that the hackers compromised the downstream Remote Procedure Call (RPC) infrastructure utilized by the LayerZero Labs Decentralized Verifier Network (DVN).

By poisoning these critical data pathways, the attackers manipulated the protocol’s operations without compromising its core cryptography. LayerZero has since deprecated the affected nodes and fully restored DVN operations, but the financial damage had already been finalized.

This indirect approach highlights a terrifying evolution in cyber warfare.

Blockchain security firm Cyvers told CryptoSlate that North Korea-linked attackers are showing increased sophistication and investing more resources, both in preparation and execution, to carry out their malicious attacks.

The firm added:

“We also observe how they consistently find the weakest link. In this case, it was a third party rather than the protocol’s core infrastructure.”

The strategy heavily mirrors traditional corporate cyberespionage and shows that DPRK-linked breaches were becoming harder to stop.

Recent incidents, such as the supply-chain compromise of the widely used Axios npm software package, which Google researchers linked to a distinct DPRK threat actor dubbed UNC1069, demonstrate an ongoing, methodical effort to poison the well before the software even reaches the blockchain ecosystem.

North Korea infiltrates crypto workforce

Beyond technical exploits, North Korea is currently executing a massive, coordinated infiltration of the global crypto labor market.

The threat model has fundamentally shifted from remote hacking campaigns to placing malicious insiders directly onto the payrolls of unsuspecting Web3 startups.

A grueling six-month investigation by the Ketman Project, an initiative operating under the Ethereum Foundation’s ETH Rangers security program, recently concluded with startling findings: roughly 100 North Korean cyber operatives are currently embedded inside various blockchain companies.

Operating under fabricated identities, these sophisticated IT workers routinely pass standard human resources screenings, gain access to sensitive internal code repositories, and sit quietly within product teams for months, or even years, before initiating a calculated attack.

This intelligence-agency-style patience was further corroborated by independent blockchain investigator ZachXBT.

He recently exposed a specialized DPRK network that has been generating roughly $1 million a month by using fraudulent personas to secure remote work.

This specific scheme funnels crypto-to-fiat transfers through sanctioned global financial channels and has processed over $3.5 million since late 2025.

Industry estimates suggest that Pyongyang’s broader deployment of IT workers generates multiple seven-figure sums monthly.

This creates a dual-pronged revenue stream for the regime: the steady accumulation of fraudulent wages, paired with the catastrophic windfalls of insider-facilitated protocol exploits.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

North Korea’s laundering Networks and macroeconomic survival

The sheer scale of North Korea’s digital asset operations dwarfs that of any traditional cybercriminal syndicate.

According to blockchain analytics firm Chainalysis, DPRK-linked hackers stole a record $2 billion in 2025 alone, accounting for a staggering 60% of all global cryptocurrency thefts that year. That figure was heavily bolstered by a devastating $1.5 billion raid on the Bybit exchange in February 2025.

Factoring in this year’s brutal campaign, North Korea’s all-time crypto-asset haul is estimated at $6.75 billion.

Once the funds are stolen, Lazarus Group operatives exhibit highly specific, regionalized laundering patterns. Unlike ordinary crypto criminals who frequently utilize decentralized exchanges (DEXs) and peer-to-peer lending protocols, DPRK actors actively avoid them.

Instead, on-chain data reveals a heavy reliance on Chinese-language guarantee services, deep over-the-counter (OTC) broker networks, and complex cross-chain mixing services.

This specific preference points to structural constraints and deeply established, geographically limited off-ramps rather than broad, unrestricted access to the global financial system.

Can these attacks be prevented?

Security researchers and industry executives say the answer is yes, but only if crypto firms address the same operational weaknesses that continue to surface in major breaches.

Terence Kwok, founder of Humanity, told CryptoSlate that the pattern behind many of these North Korea-linked losses still points to familiar weaknesses rather than entirely new forms of cyber intrusion.

In his view, North Korean actors are improving both their access methods and their ability to move stolen funds, but the damage often still traces back to poor access controls and concentrated operational risk.

He explained:

“What’s striking is how often the damage still comes down to the same weak points around access control and single points of failure. That tells you the industry still has some basic security discipline issues it has not solved.”

Considering this, Kwok stated that the industry’s first line of defense is to make asset movement materially harder to compromise. That means imposing tighter controls over private keys, internal permissions, and third-party access across the software stack.

In practice, that would require firms to reduce reliance on individual operators, limit privileged access, harden vendor dependencies, and build more checks around the infrastructure that sits between core protocols and the outside world.

The second priority is speed. Once stolen funds begin moving across chains, through bridges, or into laundering networks, the chances of recovery fall sharply. Kwok said exchanges, stablecoin issuers, blockchain analytics firms, and law enforcement agencies need to coordinate far faster during the first minutes and hours after a breach if they want to improve containment.

His comments point to a broader reality for the sector.

Crypto systems are often hardest to defend where code, people, and operations meet. A compromised credential, a weak vendor dependency, or an overlooked permissions failure can create an opening large enough to drain hundreds of millions of dollars.

The challenge for DeFi is no longer just writing resilient smart contracts. It is securing the operational perimeter around them before attackers exploit the next weak link.



Source link

Tags: CryptodaysKoreaMillionNorthStole
ShareTweetShare
Previous Post

With no ownership prospects, bank advisors leave to form RIA

Next Post

Trump administration discussing currency swap line with UAE

Related Posts

Key Hunters Eye .87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

Key Hunters Eye $58.87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

by theadvisertimes.com
June 23, 2026
0

Key TakeawaysThe Bitcoin Puzzle Challenge holds 916.52 BTC worth roughly $58.87M across 78 unsolved addresses as of June 2026.Puzzle 71...

EU Committee Advances Digital Euro CBDC Bill After Vote

EU Committee Advances Digital Euro CBDC Bill After Vote

by theadvisertimes.com
June 23, 2026
0

The creation of an EU-issued digital euro moved a step closer Tuesday after a key European Parliament committee vote.The EP's...

CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

CZ Says Hyperliquid Found A No-KYC Niche Binance Cannot Touc

by theadvisertimes.com
June 23, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR CZ discussed Hyperliquid’s no-KYC model...

.5M DeFi vault pulled overnight: The wake-up call for traders chasing high yields

$8.5M DeFi vault pulled overnight: The wake-up call for traders chasing high yields

by theadvisertimes.com
June 22, 2026
0

A verification dispute at MainStreet triggered a broader confidence scare across yield-bearing stablecoin products, sending more than 8.5 million USDT...

Fed Chair Kevin Warsh Faces Congress On July 14 Amid Rate Hike Debate

Fed Chair Kevin Warsh Faces Congress On July 14 Amid Rate Hike Debate

by theadvisertimes.com
June 22, 2026
0

Federal Reserve Chair Kevin Warsh will make his first monetary policy presentation to Congress on July 14. The testimony comes...

Strategy Adds 0 Million To USD Reserve As Saylor Reports 520 BTC Buy

Strategy Adds $300 Million To USD Reserve As Saylor Reports 520 BTC Buy

by theadvisertimes.com
June 22, 2026
0

Strategy has added more Bitcoin to its treasury, but the bigger signal in Michael Saylor’s latest update may be the...

Next Post
Trump administration discussing currency swap line with UAE

Trump administration discussing currency swap line with UAE

SEC monitoring ’emerging pressures’ in private credit space

SEC monitoring 'emerging pressures' in private credit space

  • Trending
  • Comments
  • Latest
Should You Offer a Concession to Get Your Apartment Leased Faster?

Should You Offer a Concession to Get Your Apartment Leased Faster?

June 15, 2026
6 Hotels Where Chase’s Points Boost Yields 2.5x

6 Hotels Where Chase’s Points Boost Yields 2.5x

May 22, 2026
Understanding risk remains a major investor blind spot: TIAA Institute

Understanding risk remains a major investor blind spot: TIAA Institute

June 5, 2026
Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

Anthropic’s confidential S-1 signals summer AI IPO race could heat up fast

June 2, 2026
Memorial Day 2026: Take Advantage of Food Freebies, Deals

Memorial Day 2026: Take Advantage of Food Freebies, Deals

May 23, 2026
9 Best Cheap Cell Phone Plans That Will Save You Money

9 Best Cheap Cell Phone Plans That Will Save You Money

June 3, 2026
The  GLP-1 Bridge: How to Get Affordable Weight-Loss Meds Starting July 1

The $50 GLP-1 Bridge: How to Get Affordable Weight-Loss Meds Starting July 1

0
Key Hunters Eye .87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

Key Hunters Eye $58.87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

0
A Detroit pension fund just sued Uber’s board for running a ‘serial compliance offender’ culture — and the math behind the lawsuit is what every gig-economy director should be reading tonight

A Detroit pension fund just sued Uber’s board for running a ‘serial compliance offender’ culture — and the math behind the lawsuit is what every gig-economy director should be reading tonight

0
As the shekel nears NIS 3/$, what’s next?

As the shekel nears NIS 3/$, what’s next?

0
The Fed Signals a Reversal in Rates

The Fed Signals a Reversal in Rates

0
Pzena Focused Value Strategy Increased Skyworks Solutions (SWKS) on a Dip

Pzena Focused Value Strategy Increased Skyworks Solutions (SWKS) on a Dip

0
Key Hunters Eye .87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

Key Hunters Eye $58.87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses

June 23, 2026
The  GLP-1 Bridge: How to Get Affordable Weight-Loss Meds Starting July 1

The $50 GLP-1 Bridge: How to Get Affordable Weight-Loss Meds Starting July 1

June 23, 2026
Pzena Focused Value Strategy Increased Skyworks Solutions (SWKS) on a Dip

Pzena Focused Value Strategy Increased Skyworks Solutions (SWKS) on a Dip

June 23, 2026
EU Committee Advances Digital Euro CBDC Bill After Vote

EU Committee Advances Digital Euro CBDC Bill After Vote

June 23, 2026
A Detroit pension fund just sued Uber’s board for running a ‘serial compliance offender’ culture — and the math behind the lawsuit is what every gig-economy director should be reading tonight

A Detroit pension fund just sued Uber’s board for running a ‘serial compliance offender’ culture — and the math behind the lawsuit is what every gig-economy director should be reading tonight

June 23, 2026
Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

Roku (ROKU) Has a CTV Operating-System and Ad Platform Bigger Than a Hardware Narrative

June 23, 2026
theadvisertimes.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Key Hunters Eye $58.87M Bitcoin Puzzle as 916 BTC Sits Unsolved in 78 Addresses
  • The $50 GLP-1 Bridge: How to Get Affordable Weight-Loss Meds Starting July 1
  • Pzena Focused Value Strategy Increased Skyworks Solutions (SWKS) on a Dip
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • About Us
  • Contact Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.