North Korea has been accused of orchestrating more than 75% of the global crypto crime in 2026, with blockchain analytics firm TRM Labs estimating that the stolen funds could reach a whopping $577 million in just the past four months.
Two devastating April exploits targeting KelpDAO and Drift Protocol were used as a prime example of North Korea's cyber attack, with these two cases accounting for the overwhelming majority of the losses this year.
Pyongyang however, is denying all allegations. Through state outlet Korean Central News Agency, officials dismissed the allegations as “absurd slander and a political tool of the United States to justify sanction and demonise the country.
Two Mega Hacks, One Dominant Actor
Rather than a surge in attack volume, 2026’s crypto theft landscape is being defined by scale and concentration. The KelpDAO and Drift exploits alone make up the bulk of global losses, underscoring how a small number of highly sophisticated operations can overwhelm the entire ecosystem.
Blockchain investigators say the tactics bear familiar hallmarks: coordinated exploits, rapid fund extraction, and laundering patterns consistent with previous North Korean-linked operations.
According to Chainalysis, Bitcoin accounted for 63% of stolen assets in 2026, reflecting its unmatched liquidity and ease of conversion. Funds are typically funneled through mixers and cross-chain pathways to obscure their origin before being cashed out.
Since 2017, North Korean-linked groups are believed to have stolen more than $6 billion in crypto, with proceeds allegedly helping to fund state operations under heavy international sanctions.
While North Korea dismisses the accusations as politically motivated, investigators point to growing forensic evidence—from wallet tracing to transaction patterns—linking these attacks to known state-backed actors.
The clash highlights a deeper reality: crypto has become a frontline in geopolitical conflict, where cyber warfare, financial systems, and national security increasingly overlap.
A Growing Threat to Market Confidence
With state-linked actors now blamed for the majority of major hacks, the implications stretch far beyond individual losses. Rising attack sophistication and scale are eroding trust in crypto infrastructure, even as enforcement agencies ramp up sanctions and asset seizures.
For investors and platforms alike, the message is becoming harder to ignore: this is no longer just cybercrime—it’s industrialized, state-level financial warfare.