Comparison of Lazarus Group Heists (2026)
Published 6/27/2026, 1:47:06 PM
Research confirms that the Lazarus Group, a state-sponsored hacking collective affiliated with North Korea (DPRK), was responsible for both the Kelp DAO and Humanity Protocol heists in 2026. These attacks resulted in a combined loss of approximately $328 million, utilizing a mix of sophisticated infrastructure manipulation and classic social engineering.
Comparison of Lazarus Group Heists (2026)
| Feature | Kelp DAO Hack | Humanity Protocol Hack |
|---|---|---|
| Date | April 18, 2026 | June 8, 2026 |
| Total Loss | ~$292 Million (116,500 rsETH) | ~$36 Million |
| Primary Vector | Infrastructure (RPC Node Compromise) | Social Engineering (Phishing) |
| Attribution | Confirmed (TraderTraitor subgroup) | Confirmed (Lazarus Group) |
| Key Vulnerability | 1-of-1 DVN configuration | Insecure private key storage |
Kelp DAO Attribution (April 2026)
The Kelp DAO exploit is currently the largest DeFi hack of 2026. It was attributed to the TraderTraitor subgroup of the Lazarus Group by both LayerZero Labs and Chainalysis [Source: https://layerzero.network/post-mortem-kelp-dao, https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].
- The Attack: Attackers compromised two internal RPC nodes used by LayerZero’s Decentralized Verifier Network (DVN). By launching a DDoS attack on external nodes, they forced the system to failover to their compromised nodes, allowing them to forge a "burn" message and release 116,500 rsETH [Source: https://layerzero.network/post-mortem-kelp-dao].
- Evidence: Forensic analysis identified pre-funding via Tornado Cash 10 hours before the event and the use of self-destructing malware designed to erase traces, a signature of DPRK state-sponsored activity [Source: https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].
Humanity Protocol Attribution (June 2026)
The Humanity Protocol hack occurred less than two months later and was attributed to North Korean actors by blockchain security firm Quantstamp [Source: https://quantstamp.com/blog/humanity-protocol-incident-report].
- The Attack: A director at Humanity Protocol was targeted with a phishing email disguised as a communication from the Bithumb exchange. This infected a developer's machine with malware [Source: https://dlnews.com/articles/security/humanity-protocol-hack-dprk].
- The Breach: The compromised machine contained backups of seven private keys, including admin hot wallets and multi-sig owner keys. This allowed the attackers to drain bridges and mint 100 million new H tokens, causing the token price to crash by over 80% [Source: https://quantstamp.com/blog/humanity-protocol-incident-report, https://dlnews.com/articles/security/humanity-protocol-hack-dprk].
Conclusion
The Lazarus Group successfully executed both heists, demonstrating their ability to pivot between high-level infrastructure attacks (Kelp DAO) and targeted social engineering (Humanity Protocol). These incidents were part of a broader 2026 campaign where the group drained over $575 million in a single 18-day window in April [Source: https://defiprime.com/lazarus-group-2026-campaign]. While some funds from the Kelp DAO hack (~$51 million) were frozen by the Arbitrum Security Council, the majority of the stolen assets were successfully laundered through DeFi protocols [Source: https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].