North Korea's Crypto Theft Topped $1 Billion. Crypto Cheered.

North Korea-linked hackers have stolen more than $1 billion in crypto this year, according to Chainalysis. The $387.5 million Bitget breach pushed the total past the mark, while total DeFi exploit losses keep falling, because theft consolidated into one state-run operation.

North Korea's Crypto Theft Topped $1 Billion. Crypto Cheered.

Key Takeaways

- North Korea-linked hackers have stolen more than $1 billion in crypto in 2026, after taking over $2 billion in 2025, according to Chainalysis.

- The September 24 Bitget breach, $387.5 million and the year's largest, pushed the running total past the mark.

- Total DeFi exploit losses are actually falling. The "good news" hides a consolidation of theft into one state-backed, industrialized operation.

- The attack vector has moved from code to people: the Drift Protocol hack involved six months of in-person infiltration, not a smart-contract bug.

- THORChain refused to block the stolen Bitget funds while NEAR Intents blocked $50 million, splitting DeFi into two incompatible futures.

North Korea's hackers have now stolen more than $1 billion in cryptocurrency this year, according to Chainalysis. The number that pushed them over the line was the $387.5 million drained from exchange Bitget on September 24, the largest single hack of 2026. Yet the same week, a good chunk of the industry was quietly patting itself on the back, because total DeFi exploit losses are down.

Both facts are true. That's the problem.

The Bigger Picture: Crypto's Amateur Hour Ended

The headline "hack losses fell" is real but misleading. In the first quarter of 2026, DeFi protocols lost roughly $168 million to exploits, down about 90% from the $1.58 billion stolen in the first quarter of 2025, the quarter that included the record $1.4 billion Bybit hack. Read that naively and it looks like crypto finally got its security act together.

What actually happened is less flattering. The script-kiddie and lone-wolf attacks that used to pad the annual statistics, the $150,000 lending-protocol bugs, the $80,000 quoting-logic flaws, have largely dried up. In their place stands a single, state-funded operation that reliably extracts nine figures at a time. The theft didn't decline. It consolidated.

North Korea treats crypto theft as a state revenue line. The United Nations has repeatedly estimated that stolen cryptocurrency funds a meaningful slice of Pyongyang's weapons programs. This is not a gang of criminals who happened to learn Solidity. It is national industrial policy run through units like Lazarus and TraderTraitor, with a recruiting pipeline, a training curriculum, and a laundering logistics chain that would embarrass most legitimate financial institutions.

Think about what "industrialized" actually means here. The Drift Protocol attack in April wasn't a breach; it was an operation. Attackers spent roughly six months posing as a quantitative trading firm, attending conferences, befriending contributors in person, and even depositing $1 million of their own capital into a project vault to build trust. Then they abused Solana's durable nonce mechanism to seize the Security Council's administrative powers. The smart contracts held up perfectly. The humans didn't.

Why Is North Korea Winning When Hacks Are "Down"?

The answer is that the industry optimized against the wrong enemy. For a decade, crypto poured money into code audits, bug bounties, and formal verification, and that work largely succeeded. Exploiting a well-audited smart contract today is genuinely hard. So the adversary changed targets.

Ledger's CTO Charles Guillemet drew the line explicitly after Drift, linking its method to the Bybit heist: long-term infiltration of the humans who hold the keys, then convincing them to approve malicious transactions. The attack surface moved up the stack, from the code to the people operating it. Crypto spent ten years hardening its contracts and forgot that the weakest input is still a person.

The Bitget breach, by contrast, hit a third-party software vulnerability to lift internal credentials, vendor risk, not a protocol bug. Mandiant and SlowMist are still untangling exactly how. But the pattern is consistent: these are supply-chain and social-engineering attacks aimed at operational humans, the one layer no auditor ever signs off on.

Ripple Effects: The THORChain Contradiction

The story within the story is what happened to the money after Bitget. Within three hours, attackers scattered $387.5 million across four networks, 49.7% to Ethereum, 40.8% to the XRP Ledger, 7.6% to Zcash, 1.8% to Tron. Then they did the thing that has become the Lazarus signature: they ran the XRP through THORChain, converting over 90% of it into native Bitcoin, without ever touching a centralized exchange that could freeze them.

Bitget CEO Gracy Chen publicly asked THORChain to block the flagged addresses. "Decentralization is a design principle," she wrote, "not a shield for facilitating known stolen funds." THORChain refused, arguing it is "permissionless like Bitcoin, Ethereum, and BNB Chain," and asking what responsibility those base layers bear for stolen funds moving through them.

The reply writes itself. When THORChain was itself drained of $10.7 million in May, the network halted within hours and stayed offline for five weeks. When ThorFi went underwater in January 2025, its nodes voted overnight to freeze withdrawals. As OKX founder Star Xu put it: a network that stops when its own money is at risk but refuses to stop when someone else's is at risk is not "like Bitcoin." It is making a choice.

Here's the fork that matters for the entire ecosystem. NEAR Intents did the opposite of THORChain: its automated SHIELD system blocked about $50 million in Bitget-linked swaps and even turned down the 5% bounty Bitget offered. Bitget thanked them. Decentralization purists attacked them for not being permissionless enough. Two protocols, two incompatible answers to the same question, and every DeFi project now has to pick a side, whether it says so or not.

Historical Context: The Bybit Playbook, Refined

None of this is new; it's just sharper. In February 2025, Lazarus stole $1.46 billion from Bybit and laundered roughly $1.2 billion of it through THORChain, eleven days after THORChain retired its admin key. The Coldcard thief used it. The Bitget thief used it. THORChain has become to crypto laundering what Tornado Cash was to mixer laundering, except Tornado Cash's co-founder was convicted of running an unlicensed money transmitter, while THORChain operates in the open with a top-tier token.

The difference between then and now is scale and permanence. A $1 billion year used to be an anomaly driven by one catastrophic hack. Now it's the running baseline, and the year isn't over. North Korea has turned large-scale theft into a repeatable, quarterly-recurring operation, the closest thing crypto has to a hostile revenue subscription.

The Future Lens: Where This Heads in 1-3 Years

Three trends accelerate from here.

First, the chokepoint moves to the off-ramp. If the protocol layer won't censor, regulators will squeeze the exchanges, OTC desks, and banks that touch the converted Bitcoin. Bitcoin's ledger stays transparent even after conversion, so enforcement concentrates where funds exit into fiat, exactly where investigators have always had the most success.

Second, the NEAR-vs-THORChain split becomes a regulatory line. The Financial Action Task Force's 2026 DeFi framework already says smart contracts aren't subject to its rules, but identifiable people with "sufficient influence" over a protocol may be. THORChain's own May halt proves it has that influence. That's no longer a legal question, it's a scheduling question.

Third, the "declining hacks" narrative will age badly. A single well-timed incident can still make 2026 a record year, because the adversary now runs a repeatable operation rather than a series of lucky exploits. The tail risk got fatter even as the average shrank.

The Trader's Angle: It's Not Price, It's Venue and Asset

This isn't a price story, it's a counterparty-risk story. The Bitget incident is a clean natural experiment in what freezes and what doesn't. Circle and Tether froze attacker-tagged wallets within days, but the total came to about $318,000, or 0.08% of the haul. The remaining 88% sat dormant in ETH, XRP, and Zcash, none of which any centralized issuer can freeze. Attackers know exactly which assets are uncensorable, and they allocate accordingly.

The practical takeaway is boring and useful: treat cross-chain liquidity hubs, privacy coins, and hot-wallet custody as risk variables that can be squeezed by regulation or targeted by a state actor, not just as neutral infrastructure. Diversify across venues. Understand that a venue's compliance posture, or its absence, is now a material fact about your exposure, whether you're laundering anything or not.

Closing

Here's the question crypto keeps refusing to answer. If a sanctioned, nuclear-armed state uses your "permissionless" protocol as its primary money-laundering rail, and your protocol demonstrably can halt transactions when its own funds are at risk, how long before "we can't" stops being a design philosophy and starts being read as a choice?

The industry spent a decade arguing that code is law. North Korea just proved the law has a loophole. And the loophole is us.

Frequently Asked Questions

How much crypto has North Korea stolen in 2026? More than $1 billion, according to Chainalysis, after roughly $2 billion in 2025. The $387.5 million Bitget breach in September was the single incident that pushed the 2026 total past the mark.

Why are total hack losses falling while North Korea theft is rising? DeFi exploit losses fell about 90% year-over-year in Q1 2026 because small-scale, amateur hacks declined. Theft didn't stop, it consolidated into one state-run operation executing fewer, much larger attacks.

Why did THORChain refuse to block the Bitget funds? It argues it is permissionless, like Bitcoin or Ethereum, and cannot censor individual addresses. Critics point out it halted its own network within hours after a $10.7 million exploit in May, and froze its lending product in January 2025.

How did the Drift hack happen without a code bug? Attackers spent about six months socially engineering contributors, posing as a quant firm, meeting in person, depositing $1 million, then abused Solana durable nonces to seize the Security Council's admin powers. The code held; the people didn't.

What is the difference between NEAR Intents and THORChain here? NEAR Intents' SHIELD system blocked roughly $50 million in Bitget-linked swaps and declined the 5% bounty. THORChain declined to act at all. The two responses represent two mutually exclusive futures for decentralized finance.

All RealCryptoCap analysis