Go to app

Comparison of Lazarus Group Heists (2026)

Published 6/27/2026, 1:47:06 PM

Research confirms that the Lazarus Group, a state-sponsored hacking collective affiliated with North Korea (DPRK), was responsible for both the Kelp DAO and Humanity Protocol heists in 2026. These attacks resulted in a combined loss of approximately $328 million, utilizing a mix of sophisticated infrastructure manipulation and classic social engineering.

Comparison of Lazarus Group Heists (2026)

FeatureKelp DAO HackHumanity Protocol Hack
DateApril 18, 2026June 8, 2026
Total Loss~$292 Million (116,500 rsETH)~$36 Million
Primary VectorInfrastructure (RPC Node Compromise)Social Engineering (Phishing)
AttributionConfirmed (TraderTraitor subgroup)Confirmed (Lazarus Group)
Key Vulnerability1-of-1 DVN configurationInsecure private key storage

Kelp DAO Attribution (April 2026)

The Kelp DAO exploit is currently the largest DeFi hack of 2026. It was attributed to the TraderTraitor subgroup of the Lazarus Group by both LayerZero Labs and Chainalysis [Source: https://layerzero.network/post-mortem-kelp-dao, https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].

  • The Attack: Attackers compromised two internal RPC nodes used by LayerZero’s Decentralized Verifier Network (DVN). By launching a DDoS attack on external nodes, they forced the system to failover to their compromised nodes, allowing them to forge a "burn" message and release 116,500 rsETH [Source: https://layerzero.network/post-mortem-kelp-dao].
  • Evidence: Forensic analysis identified pre-funding via Tornado Cash 10 hours before the event and the use of self-destructing malware designed to erase traces, a signature of DPRK state-sponsored activity [Source: https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].

Humanity Protocol Attribution (June 2026)

The Humanity Protocol hack occurred less than two months later and was attributed to North Korean actors by blockchain security firm Quantstamp [Source: https://quantstamp.com/blog/humanity-protocol-incident-report].

Conclusion

The Lazarus Group successfully executed both heists, demonstrating their ability to pivot between high-level infrastructure attacks (Kelp DAO) and targeted social engineering (Humanity Protocol). These incidents were part of a broader 2026 campaign where the group drained over $575 million in a single 18-day window in April [Source: https://defiprime.com/lazarus-group-2026-campaign]. While some funds from the Kelp DAO hack (~$51 million) were frozen by the Arbitrum Security Council, the majority of the stolen assets were successfully laundered through DeFi protocols [Source: https://blog.chainalysis.com/reports/kelp-dao-exploit-2026].