Banner
NEWS

North Korea's $577M DeFi Blitz: Drift and Kelp Hacked in 18 Days

North Korea's $577M DeFi Blitz: Drift and Kelp Hacked in 18 Days
CoinPlurk News
CoinPlurk News
Verified Source
Apr 20, 2026
0
SUMMARY
Title: North Korea's $577M DeFi Blitz: Drift and Kelp Hacked in 18 Days
Category: NEWS
Author: CoinPlurk News
Publication Date: 20 Apr 2026
SUMMARY: North Korean state-linked hackers have drained over $577 million from two major DeFi protocols in less than three weeks, exposing deep structural vulnerabilities in cross-chain infrastructure and on-chain governance.
Detail

North Korean state-affiliated hackers have executed two of the largest decentralized finance exploits in history within a single month, draining a combined total of over $577 million from Drift Protocol and Kelp DAO. Blockchain analytics firms, cross-chain infrastructure providers, and independent security researchers have attributed both attacks — with varying degrees of confidence — to hacking units operating under the North Korean state apparatus, marking what analysts describe as an escalating, coordinated campaign against DeFi infrastructure.

The Drift Protocol Exploit: A Six-Month Infiltration

On April 1, 2026, attackers drained approximately $285 million from Drift Protocol — the largest decentralized perpetual futures exchange on Solana — in what became the biggest DeFi hack of the year at that point and the second-largest exploit in Solana's history, behind only the $326 million Wormhole bridge hack in 2022.

Drift's post-mortem described the attack as "six months in the making," attributing it with medium confidence to UNC4736, a North Korean state-sponsored threat actor also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces — a group with a documented history of targeting the cryptocurrency sector since at least 2018.

The attack vector was not a smart contract bug. Instead, it combined social engineering, governance manipulation, and a purpose-built fake token:

  • Between December 2025 and January 2026, operatives posing as a quantitative trading firm onboarded an Ecosystem Vault on Drift, submitted strategy documentation, and deposited over $1 million of their own capital to build credibility.
  • The attacker manufactured a fictitious token called CarbonVote (CVT), seeded with minimal liquidity and fake trading volume, then manipulated Drift's oracles into treating it as valid collateral.
  • Between March 23 and 30, the attacker obtained 2-of-5 multisig approvals from Drift's Security Council members by tricking them into pre-signing malicious transactions using Solana's durable nonce feature, which allowed the authorizations to sit dormant until execution day.
  • When triggered on April 1, the vaults were emptied in roughly 12 minutes, with most stolen funds bridged to Ethereum within hours.

The DRIFT token fell over 40% following the exploit, and the protocol's total value locked collapsed from approximately $550 million to under $250 million. A dozen Solana protocols with Drift dependencies paused operations.

The Kelp DAO Exploit: Infrastructure Poisoning at Scale

On April 18, Kelp DAO — a liquid restaking protocol routing user ETH through EigenLayer — fell victim to a $292 million exploit, confirmed as the work of the North Korean state-backed Lazarus Group, specifically its TraderTraitor subunit. This surpassed Drift to become the largest single DeFi exploit of 2026.

Attackers compromised two RPC nodes that LayerZero's verifier relied upon to confirm cross-chain transactions, replacing the node software with malicious versions that reported false data. They then launched a distributed denial-of-service attack against the remaining honest nodes, forcing a failover to the compromised endpoints — tricking LayerZero's verifier into approving a fraudulent cross-chain transaction and releasing 116,500 rsETH to the attackers.

LayerZero attributed the breach partly to Kelp's own security configuration: the protocol ran a 1-of-1 verifier setup, meaning LayerZero Labs was the sole entity verifying messages to and from the rsETH bridge — a configuration LayerZero says it had previously warned against.

The contagion spread quickly across the DeFi sector:

  • The April 18 exploit triggered a $10 billion outflow from Aave amid concerns over potential bad debt.
  • Total value locked across DeFi fell approximately 7% in the 24 hours after the attack, declining from roughly $99.5 billion to $86.3 billion.
  • Several DeFi teams, including Ethena, ether.fi, Tron DAO, and Curve Finance, paused their LayerZero omnichain fungible token bridges in response.

A Shifting and Escalating Threat

The same North Korean unit has now drained more than $577 million from DeFi in 18 days through two structurally different attack vectors: social engineering governance signers at Drift, and poisoning infrastructure RPCs at Kelp.

Analysts note the Kelp exploit signals that North Korea's Lazarus Group is evolving beyond isolated hacks, rapidly shifting tactics from social engineering to exploiting structural weaknesses in crypto infrastructure — suggesting a sustained, state-driven campaign rather than one-off incidents.

If the DPRK attribution holds across both incidents, this would push the regime's confirmed crypto theft total for 2026 past $600 million, proceeds the U.S. government has previously linked to Pyongyang's weapons programs.

LayerZero has since announced it will no longer sign messages for any project operating a 1-of-1 verifier configuration and is accelerating migrations to multi-DVN setups. Security researchers and protocol developers are urging the broader DeFi industry to treat governance timelocks, oracle defense-in-depth, and cross-chain verification redundancy as non-negotiable baseline requirements — not optional configurations.


Published by Coinplurk.com

Editorial Note

We use AI technology to help present information faster and more efficiently. However, all content still goes through a human review process. If you find data errors or factual inaccuracies in this article, please report it to our editorial team via the [Report Article] button.

Published by Coinplurk.com

CoinPlurk News

About the Author

CoinPlurk News

Verified Author

Verified Web3 content architect providing high-impact data analysis and real-time reporting on the global blockchain ecosystem.

More Articles

6
NEWS

Visa, Mastercard, and 140+ Firms Launch Open USD Stablecoin

A coalition of Visa, Mastercard, Stripe, Coinbase, BlackRock, and more than 140 other companies has launched Open USD, a dollar-pegged stablecoin designed to share reserve yield with the businesses that use it.

CoinPlurk News Jul 01, 2026
NEWS

FIFA Taps Avalanche for 2026 World Cup; AVAX Jumps 8%

FIFA's decision to build its 2026 World Cup ticketing, loyalty, and digital collectibles infrastructure on a dedicated Avalanche blockchain has given AVAX its strongest bullish signal in a month — but analysts say sustained demand still needs to be proven.

CoinPlurk News Jun 17, 2026
NEWS

Mastercard Launches AP4M for AI Machine-Speed Payments

Mastercard's new Agent Pay for Machines (AP4M) service enables AI agents to autonomously permission, orchestrate, and settle high-frequency micro-payments across cards, bank accounts, and stablecoins — with more than 30 industry partners already on board.

CoinPlurk News Jun 15, 2026
NEWS

Polymarket Eyes Japan With 2030 Approval Target

Polymarket has appointed a local representative and set a 2030 target for regulatory approval in Japan, even as the country's strict gambling laws and a global wave of prediction market restrictions make the path forward uncertain.

CoinPlurk News May 22, 2026
NEWS

SpaceX IPO Filing Reveals $1.45B Bitcoin Treasury

SpaceX's landmark SEC filing ahead of its Nasdaq debut has disclosed an 18,712 BTC position worth $1.45 billion, placing the aerospace company among the largest known corporate Bitcoin holders.

CoinPlurk News May 21, 2026
NEWS

Revolut's First Physical Crypto Card Goes Live in UK and EEA

Revolut has launched its first physical crypto debit card — a Dogecoin-themed, LED-equipped card accepted anywhere Visa and Mastercard are supported — marking a significant step in the fintech's push to bring digital asset spending into everyday consumer finance.

CoinPlurk News May 19, 2026

Interactive Hub

0 Replies

Have a suggestion, question, or just want to leave a comment on this article? Feel free to write in the discussion section below.

Please login to join the discussion

Login Now

No comments yet. Be the first!

CoinPlurk Web3 Gateway Platform

⚠ Important Disclaimer
Coinplurk is an Web3 Gateway platform providing the latest Web3 news, data, and application reviews. All content is for informational purposes only and does not constitute investment, financial advice, or a solicitation to buy/sell any crypto assets. All financial decisions are solely your responsibility. We strongly recommend conducting your own research (DYOR) before engaging with any Web3 platform.

© 2026 CoinPlurk | All Rights Reserved