Skip to main content
Sign in

DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign

avoid.net/dprk-lazarus-april-2026-635m-blitz-drift-kelp-combined-campaign0/100·87% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

In April 2026, North Korea-linked threat actors attributed to the Lazarus Group and its subunits executed two separate, high-value cryptocurrency exploits within 18 days — draining approximately $285 million from Drift Protocol on April 1 and approximately $292 million from KelpDAO on April 18. Combined, the two attacks account for an estimated $577–635 million in losses, comprising 76% of all documented cryptocurrency hack value through April 2026 and representing the largest coordinated DPRK crypto theft campaign on record.

Connected Entities

1 entities
Tokens
DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign
Relationships
  • + 4 more
Have evidence about DPRK Lazarus April 2026 $635M Blitz — Drift + Kelp Combined Campaign?

Timeline(14 events)

2025-09-01

Alleged DPRK-linked threat actors begin a six-month social engineering campaign against Drift Protocol, posing as a quantitative trading firm and making contact at industry events.

TRM Labs / Elliptic

2026-03-06

Alleged DPRK-linked actors socially engineer a LayerZero Labs developer, harvesting session keys and gaining access to LayerZero's RPC cloud environment in the early stages of the KelpDAO operation.

Mandiant / CrowdStrike via Chainalysis

2026-03-11

On-chain staging for the Drift hack begins: funds withdrawn from Tornado Cash to finance attack infrastructure. Attacker wallet created approximately 21 days before the attack.

TRM Labs

2026-04-01

Drift Protocol is drained of approximately $285–286 million in 31 transactions over roughly 12 minutes. Stolen assets include USDC, SOL, cbBTC, wBTC, and liquid staking tokens. Stolen funds are bridged to Ethereum within hours. DRIFT token falls over 40%.

Elliptic / TRM Labs / CoinDesk

2026-04-05

Drift Protocol states with 'medium-high confidence' that the attack was carried out by the same threat actors responsible for the 2024 Radiant Capital hack, attributed by Mandiant to UNC4736.

Drift Protocol / Elliptic

2026-04-16

Tether and partners announce a $148 million recovery fund for Drift Protocol. Drift plans to relaunch as a USDT-settled perpetual futures exchange with a $295 million total compensation target.

CoinDesk

2026-04-18

KelpDAO is drained of 116,500 rsETH (~$292 million) via a compromised LayerZero bridge configuration at 17:35 UTC. Two follow-up attempts (~$100M each) are blocked after an emergency pause 46 minutes post-exploit.

CoinDesk / Halborn / LayerZero

2026-04-20

KelpDAO attributes the exploit to LayerZero's default 1-of-1 DVN configuration. LayerZero disputes responsibility. TechCrunch reports North Korean hacker attribution.

TechCrunch / CoinDesk

2026-04-21

Arbitrum Security Council freezes approximately 30,766 ETH (~$71 million) linked to the KelpDAO exploit on Arbitrum One, sparking a debate about decentralization.

CoinDesk / CryptoTimes

2026-04-27

KelpDAO and Aave request Arbitrum to release the $71 million in frozen ETH for recovery and bad debt resolution purposes.

The Coin Republic

2026-05-05

KelpDAO publicly states that LayerZero approved the 1-of-1 DVN setup it later blamed for the $292 million exploit.

CoinDesk

2026-05-12

Arbitrum DAO votes to implement a protocol-level lock on KelpDAO exploit-linked assets.

KuCoin Blog

2026-07-24

A wallet linked to the Drift exploit transfers approximately 23,095 ETH ($44.4 million) to Tornado Cash — the first major laundering movement since the April 1 attack. PeckShield flags the transactions.

CryptoTimes / Cryptopolitan

2026-08-01

A US court order bars Arbitrum from releasing the $71 million frozen after the KelpDAO hack, with lawyers for 2015 DPRK kidnapping victims claiming the funds as North Korean state assets under a pre-existing federal judgment.

BeInCrypto
Provenance & Audit Trail
20 Wayback Archives

Decision Log

  • #1publish⛓ pending8/5/2026, 5:11:48 PM
    hash: 9TqgxhahEthFqL3PNomjbg1cVPK3WAMGfyNoKox6U6AG

20 of 29 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/5/2026, 5:11:37 PM

last updated: 8/5/2026, 6:59:13 PM

avoid.net — verified advice for a post-truth world