# North Korea linked to $578 M crypto heists in April after Kelp DAO

**Published:** 2026-07-07T20:18:27.256Z  
**Topic:** Dao Crypto  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/e3b2303a-f5da-437f-8f94-72a1e38c4c95

North Korea hackers tied to $292 M Kelp DAO exploit and $285 M Drift hack push April crypto thefts to $578 M, raising security concerns for DeFi platforms.

A $292 million hack of the Kelp DAO yield protocol on Saturday pushed total crypto thefts attributed to North Korean actors in April to $578 million, the largest monthly sum since the Bybit breach [1]. The breach, traced to a single‑verifier flaw in LayerZero’s cross‑chain messaging, underscores growing state‑backed threats to decentralized finance.  

| At a glance | |
|---|---|
| Total April thefts | $578 M |
| Kelp DAO loss | $292 M |
| Prior biggest April hack | $285 M (Drift) |
| Suspected actor | TraderTraitor (Lazarus Group) |

## How the Kelp DAO exploit unfolded  
LayerZero, the cross‑chain messaging provider, said the attackers abused Kelp DAO’s “1‑of‑1 DVN” verifier configuration, allowing a single compromised node to approve fraudulent messages without a backup check [2]. The hack released $292 million of assets, overtaking the $285 million Drift exploit that occurred on April 1 [1]. Blockchain investigator Tanuki42 linked the stolen funds to the same North Korean subgroup, TraderTraitor, confirming a pattern of commingling across incidents [1].  

## Broader implications for DeFi security  
The incident prompted the Arbitrum Security Council to freeze 30,766 ETH tied to the exploit, a rare governance intervention that highlights tension between decentralization and loss mitigation [1]. Ledger CTO Charles Guillemet called the freeze “probably good” but noted the discomfort it creates for neutral infrastructure [1]. The attacks illustrate a shift from code‑level bugs to vulnerabilities in the underlying infrastructure and verification models, expanding the attack surface for state‑backed actors [1].  

## What to watch  
- **Arbitrum governance actions** – any further fund‑freezing decisions could signal evolving norms for roll‑up security.  
- **LayerZero verifier upgrades** – adoption of multi‑verifier setups may reduce single‑point failures.  
- **North Korean activity spikes** – monitor for additional DeFi exploits or cross‑chain attacks linked to TraderTraitor.  

The April thefts demonstrate that North Korean cyber units are adapting their tactics, targeting not just smart‑contract bugs but the bridges and messaging layers that connect blockchains. Whether the industry will coalesce around stronger governance interventions or accept inevitable losses remains an open question.

## Sources
1. Tradingview — [North Korea tied to heists worth $578M in April after Kelp DAO...](https://www.tradingview.com/news/cointelegraph:5c2d58133094b:0-north-korea-tied-to-heists-worth-578m-in-april-after-kelp-dao-exploit/)
2. Analyticsinsight — [North Korea Tied to Record $290M Kelp DAO Crypto Hack](https://www.analyticsinsight.net/news/north-korea-tied-to-record-290m-kelp-dao-crypto-hack)
3. Newsnow — [APT News | Advanced Persistent Threats News - NewsNow » Latest...](https://www.newsnow.co.uk/h/Technology/Cyber+Security/Advanced+Persistent+Threats?type=ln)

---
Cite as: TrendWatcher, "North Korea linked to $578 M crypto heists in April after Kelp DAO", https://www.trendwatcher.in/article/e3b2303a-f5da-437f-8f94-72a1e38c4c95
