North Korea has rejected allegations of sponsoring crypto thefts
Share of crypto losses to DRPK. Source TRM Labs The Drift Protocol hack involved months of social engineering, including what TRM described as in-person meetings between North Korean proxies and Drift employees. On-chain staging began on March 11 with a withdrawal from Tornado Cash, according to TRM Labs. The attacker exploited a Solana feature called a durable nonce to pre-sign transactions, then executed 31 withdrawals in roughly 12 minutes on April 1, leading to $285 million in losses. The KelpDAO breach exploited a single-verifier design flaw in a LayerZero bridge. After Arbitrum froze roughly $75 million of the stolen funds, the attackers pivoted to laundering through THORChain, converting stolen ETH to Bitcoin, with losses reaching $292 million. TRM Labs attributed KelpDAO‘s exploit to TraderTraitor, a Lazarus Group-affiliated operation, and says another North Korean group distinct from TraderTraitor was responsible for Drift Protocol’s exploit. U.S. bodies tie North Korean actors to Ronin, Bybit hacks Over the past years, there have also been official reports by U.S. government agencies linking North Korean hackers to major crypto hacks. In February 2025, the Federal Bureau of Investigation (FBI) released a PSA categorically saying North Korea‘s TraderTraitor was responsible for Bybit’s $1.5 billion hack earlier in the month. North Koreas Lazarus Group