DPRK Calls Cyber Theft Accusations ‘Absurd Slander’ Driven by Reptile Media

UncategorizedMay 4, 2026·5 min read

North Korea-linked cyber actors accounted for 76% of all cryptocurrency hack losses through April 2026, according to blockchain intelligence firm TRM Labs, even as the regime’s Foreign Ministry dismisses the attribution as “absurd slander” and US-driven political propaganda. For institutional investors, this divergence between forensic evidence and official denial underscores both the scale of the threat and the opacity surrounding attribution in cross-border crypto theft investigations.

  • North Korea-linked groups caused 76% of crypto hack losses in 2026 through April, up from 64% in 2025 and under 10% in 2020-2021.
  • Just two attacks in 2026 account for the majority of losses, including breaches of KelpDAO and Drift, signaling a shift toward fewer but higher-value targets.
  • DPRK Foreign Ministry denies all cyber theft allegations as politically motivated, claiming the US uses its control of global IT infrastructure for indiscriminate attacks.
  • 76% Share of crypto hack losses linked to North Korea through April 2026
  • $577M Value of two major attacks driving 2026 losses attributed to DPRK actors
  • 64% North Korea’s share of crypto hack losses in full year 2025

Data released by TRM Labs this week paints a picture of North Korean cyber operations that have grown more sophisticated and lucrative even as their frequency remains stable.

Through the first four months of 2026, actors linked to Pyongyang have been attributed to losses totaling $577 million across just two major incidents, catapulting their annual share to 76% of all cryptocurrency hack losses globally.

The trajectory represents a sharp acceleration: North Korea’s attributed share stood below 10% in 2020 and 2021, climbed to 64% last year, and has now reached levels that make the regime’s cyber operations the single largest source of cryptocurrency theft by loss magnitude.

This concentration of impact into fewer attacks suggests a deliberate operational shift. Rather than conducting numerous smaller heaches across multiple targets, North Korea-linked groups appear to be focusing resources on identifying and exploiting high-value vulnerabilities in major platforms.

TRM Labs analysts noted that the number of attacks has not increased year-over-year, but their average impact has grown substantially, indicating more selective targeting and potentially deeper reconnaissance before execution.

TRM Labs Attributes $577 Million in Losses to Two Targeted Breaches

The scale of damage concentration in 2026 reflects a tactical narrowing that differs markedly from the diffuse attack patterns of earlier years. KelpDAO and Drift, two decentralized finance platforms, became the focal points of what TRM characterized as high-precision operations, each resulting in nine-figure losses.

The Bybit breach, which remains the largest single crypto hack on record by total loss value, established a precedent for targeting major centralized platforms, and the 2026 data suggests North Korean operators have refined their ability to identify and exploit critical infrastructure within the crypto ecosystem.

Analysts at TRM flagged evidence that artificial intelligence tools may now play a role in attack planning and social engineering phases, allowing operators to conduct more effective reconnaissance and craft more convincing phishing campaigns.

This technical evolution, coupled with the regime’s persistent access to international banking networks through shell companies and intermediaries, has amplified both the precision and impact of individual operations.

The shift toward fewer, larger attacks also reduces operational exposure: each successful breach yields enough capital to justify the intelligence investment and operational risk, while minimizing the number of separate intrusions required.

For institutional custody providers, exchange operators, and DeFi protocol developers, the data signals that North Korean targeting is no longer random or broadly dispersed but increasingly strategic, favoring platforms with the largest consolidated asset pools and the highest probability of generating nine-figure returns per operation.

DPRK Rejects Attribution as Part of Sustained US Political Campaign

In an official statement released via state news agency KCNA, North Korea’s Foreign Ministry rejected all accusations linking the regime to cyber theft and fraud as “absurd slander” designed to damage the country’s international standing.

A ministry spokesperson characterized the attribution narrative as the work of “reptile media organs” and “plot-breeding organizations” operating under US direction, part of what the regime described as a continuation of hostile policy aimed at portraying the DPRK as a global cyber threat while shielding the US from scrutiny over its own cyber operations.

It is our consistent policy stand to protect cyberspace, the common wealth of mankind, from all sorts of malicious acts and thoroughly reject any sinister attempt to use the cyber issue as a political tool for violating sovereignty and interfering in internal affairs of others.

DPRK Foreign Ministry Spokesperson, via KCNA

The statement argued that the United States, which the regime characterized as possessing the world’s most advanced cyber capabilities and control over critical global IT infrastructure, conducts “indiscriminate cyber attacks against other countries” with impunity while framing itself as the primary victim of international cyber crime.

By inverting the accusation, the Foreign Ministry positioned North Korea as a defender of cyberspace integrity rather than a threat to it, framing the attribution campaign as a propaganda tool deployed to justify hostile policies and economic sanctions.

The timing and tone of the DPRK statement, which warned that the regime would not tolerate “increasingly confrontational actions by hostile forces across various domains, including cyberspace,” suggested escalating tensions over attribution and potential retaliation.

The regime pledged to “take necessary measures to defend state interests and safeguard the rights of its citizens,” language consistent with past threats of counter-cyber operations, though the statement contained no specific operational announcements.

Attribution Opacity and the Institutional Investment Problem

The deadlock between forensic attribution by private intelligence firms and categorical denial by the DPRK raises a central problem for institutional investors managing crypto exposure: there is no authoritative third-party arbiter of cyber threat attribution, and regulatory frameworks for responding to attributed threats remain fragmented across jurisdictions.

TRM Labs, like competing firms Chainalysis and Elliptic, derives attribution through transaction analysis, cluster identification, and behavioral pattern matching, but these methodologies, while sound, are proprietary and operate outside formal legal or judicial processes.

For custody providers, hedge funds, and institutional exchanges, the absence of a binding attribution standard creates operational ambiguity. If a major platform breach occurs and private intelligence attributes it to North Korea, does that trigger regulatory reporting obligations, sanctions compliance measures, or insurance payouts?

The answer depends partly on whether the institution accepts the private attribution, whether regulators have issued formal guidance on that specific attack, and whether the US Treasury or other authorities have independently corroborated the link. The DPRK’s blanket denial, while not credible to most security professionals, exploits this gap.

Institutional investors should expect regulatory clarity on attribution standards and response protocols to lag behind technical evidence, creating compliance uncertainty in the interim.

The critical question now facing institutional market participants is whether regulators will establish formal attribution standards and response requirements for North Korea-linked incidents before the next major breach occurs. The US Treasury, CISA, and relevant financial regulators have not yet published binding guidance on how institutions should treat private attribution data or what mandatory actions follow from a confirmed North Korean link. Meanwhile, TRM Labs and peer firms continue to release quarterly threat assessments, but these remain advisory rather than regulatory. Institutional custodians and exchanges should monitor pending announcements from the Treasury Department’s Office of Foreign Assets Control (OFAC) and any Congressional action on crypto-specific cyber attribution liability, as these will determine operational and compliance responses to the next confirmed North Korean theft.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe