CoinDesk ties recent DeFi exploits — $270M from Drift (April 1) and $292M from Kelp DAO (April 18) — to a North Korean shift from scanning vulnerable contracts to scanning vulnerable people. The Drift hit was a six-month op where operatives posed as a quant firm, deposited $1M of their own capital, onboarded an Ecosystem Vault, then compromised an admin key to drain five vaults. Chainalysis pegs 2025 North Korean crypto theft at $2.02B, and Q1 2026 alone saw 18 attacks and $300M+ stolen. Takeaway: Lazarus is bringing intelligence-agency patience to DeFi, and teams without rigorous counterintelligence are the soft target.

TLDR by @Benthic

More coverage

Explore the topic

More on Exploit

Comments