Close Menu
Techora News HubTechora News Hub
    Facebook X (Twitter) Instagram
    Techora News HubTechora News Hub
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Techora News HubTechora News Hub
    Home»Crypto News»DeFi»North Korea Tied to Heists Worth $578M in April After Kelp DAO Exploit
    DeFi

    North Korea Tied to Heists Worth $578M in April After Kelp DAO Exploit

    April 24, 2026
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Cointelegraph
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email
    kraken


    Kelp DAO suffered a $292 million hack on Saturday, overtaking Drift as the largest crypto exploit of the year so far. North Korea-linked hackers are suspected to be behind the attack.

    Kelp DAO said Monday that the exploit stemmed from a failure of cross-chain messaging protocol LayerZero’s infrastructure. LayerZero said the breach was enabled by Kelp DAO’s use of a single verifier configuration to approve cross-chain messages.

    LayerZero said that “preliminary indicators” attributed the exploit to TraderTraitor, a subgroup of North Korea’s state-backed hacking unit known as Lazarus Group.

    Blockchain investigator Tanuki42’s findings also found ties to TraderTraitor. Tanuki42 said Tuesday that funds stolen from the Kelp DAO incident have commingled with previous exploits linked to the same group.

    quillbot

    While North Korea’s cyber activity targeting decentralized finance platforms has accelerated in April, its tactics also pose a threat to companies and end users.

    Funds from the Kelp DAO exploit have commingled with wallets linked to the $1.4 billion Bybit hack in February 2025. Source: Tanuki42

    North Korea’s crypto schemes back in focus

    The April Fools’ Day exploit on decentralized exchange Drift totaled $285 million, bringing suspected North Korea-linked crypto theft to at least $578 million across major incidents throughout the month.

    The two attacks are the largest crypto heists attributed to North Korean actors since the Bybit hack.

    By now, the crypto industry has caught on that DPRK-linked operatives pose as IT developers to secure remote jobs at tech companies. Security researchers and the United Nations say that this tactic generates millions of dollars to support North Korea’s weapons programs.

    Weak background checks allow North Korean IT workers to secure remote gigs. Source: Tanuki42

    Related: North Korean cyber spies are no longer just remote threats

    In March, the US Treasury Department sanctioned six individuals and two entities for their alleged roles in North Korean IT worker fraud schemes. The FBI also issued guidance in June, recommending that employers verify candidates’ professional history and require in-person meetings.

    However, the Drift exploit suggests Pyongyang’s cyber operatives are adapting. The DeFi platform said its contributors were approached in person by individuals posing as a quant trading firm at a major crypto conference in November. The attackers continued to communicate and build trust ahead of the breach.

    Smaller-scale attacks have continued in parallel. Crypto wallet provider Zerion said DPRK-linked actors used AI-assisted social engineering to steal about $100,000 in a separate incident.

    North Korea rarely responds to such accusations, though its foreign ministry issued a statement in May 2020 denying involvement in cyberattacks and accusing the United States of attempting to tarnish its image.

    Retail crypto scams surge as DPRK tactics spill over

    The Federal Bureau of Investigation (FBI) reported a 21% increase in crypto-related crime complaints in its 2025 Internet Crime Complaint Center (IC3) report. The FBI launched IC3 in 2000 as a portal for victims in the US to report online fraud.

    Cryptocurrency cases were linked to 181,565 complaints in 2025, resulting in $11.37 billion in losses, more than half of the total.

    Investors aged 60 and above reported the most complaints involving crypto in 2025. Source: FBI

    Related: North Korean spy slips up, reveals ties in fake job interview

    Older Americans aged 60 and above filed the highest number of crypto-related complaints. Investment scams were the largest category, generating 61,559 complaints, including 13,685 from people 60 and older.

    That doesn’t mean the retail sector is untouched by suspected North Korean operations. An investigation published last November found that DPRK-linked operatives also recruit individuals to support remote IT worker schemes.

    Throughout 2025, Heiner García, a cyberthreat intelligence expert at Telefónica, came into contact with a suspected North Korean operative.

    García previously told Cointelegraph that the individual attempted to use him as a proxy to bypass VPN restrictions set by freelancing platforms. The tactic involves using a victim’s device in a local jurisdiction by installing remote access software such as AnyDesk.

    In August 2024, the US Department of Justice arrested Matthew Isaac Knoot for running a “laptop farm” that allowed DPRK IT workers to appear as US-based employees using stolen identities. In July 2025, Christina Chapman was sentenced to more than eight years in prison for her role in helping North Korean IT workers earn more than $17 million.

    The tradeoff behind freezing funds stolen by suspected DPRK actors

    A unique element of the Kelp DAO hack was the Arbitrum Security Council’s decision to freeze 30,766 ETH linked to the exploit.

    Crypto’s ethos is decentralization, yet responses to major hacks continue to divide the industry. Some projects lean toward minimal intervention, even as security experts call for action, leaving little consensus on when it is appropriate to step in.

    USDC issuer Circle faced criticism from industry participants for its inaction in the Drift hack. Source: James Seyffart

    Ledger CTO Charles Guillemet said on Tuesday that the outcome was “probably” good, but not a comfortable one. Freezing the funds likely prevented further losses. The discomfort comes from what the action makes explicit.

    The Arbitrum Security Council did not exploit a bug or discover a backdoor. It exercised its intended authority to override the state. That authority exists by design and sits in tension with the idea of credibly neutral infrastructure. In practice, assets on today’s rollups can still be affected by governance decisions under certain conditions.

    Guillemet ties that tradeoff to the threat environment. The Kelp DAO exploit did not rely on a novel smart contract bug. It exposed weaknesses in infrastructure and configuration, showing how attacks are moving beyond code into the systems that support it.

    At the same time, North Korea-linked groups have evolved into well-resourced, persistent adversaries capable of probing those systems across multiple fronts.

    That leaves the industry split between accepting intervention or accepting losses that cannot be undone.

    Magazine: Adam Back says current demand is ‘almost’ enough to send Bitcoin to $1M

    Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.



    Source link

    murf
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    MiCA Architect Says EU Should Prioritize Tokenization Over DeFi Rules

    June 9, 2026

    EdgeX Blames Outsider for EDGE Token Crash as ZachXBT Alleges Insider Manipulation

    June 2, 2026

    Radiant to Wind Down After Failing to Recover From 2024 Hack

    June 2, 2026

    Kelp DAO Recovery Hopes Fade as Hacker Launders About $220 Million

    June 1, 2026

    Circle Blacklists Zama Protocol Address, Freezing $12.6M In User Funds

    June 1, 2026

    Kraken Launches Bitcoin Yield Product

    May 30, 2026
    ledger
    Latest Posts

    MiCA Architect Says EU Should Prioritize Tokenization Over DeFi Rules

    June 9, 2026

    Switzerland Considers Historic Move to Constitutionally Cap Its Population at 10 Million

    June 9, 2026

    5 Cheap Canadian Stocks to Buy Before the Market Notices

    June 9, 2026

    The crucial human component in computing and AI | MIT News

    June 9, 2026

    How Claude AI Helped Me Make $1000 in One Weekend (Step by Step)

    June 9, 2026
    kraken
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    I Just Used Claude AI To Make $10,025 in 24 Hours

    June 10, 2026

    Zcash developers propose ‘Ironwood’ upgrade, ZEC price rebounds, but there is a risk

    June 9, 2026
    bybit
    Facebook X (Twitter) Instagram Pinterest
    © 2026 TechoraNewsHub.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 61,603.00
    ethereum
    Ethereum (ETH) $ 1,635.51
    tether
    Tether (USDT) $ 0.9993
    bnb
    BNB (BNB) $ 590.98
    usd-coin
    USDC (USDC) $ 0.999732
    xrp
    XRP (XRP) $ 1.13
    solana
    Solana (SOL) $ 64.68
    tron
    TRON (TRX) $ 0.322182
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.03
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05