Desk live·
ForensicPost
Nation-state/Finance/File 26-0417

Two Hundred and Ninety-Two Million, and No Perimeter to Breach

A reported $292 million exploit of Kelp DAO in April 2026 was attributed to the same DPRK-linked cluster behind earlier exchange thefts. Protocol logic has no help desk to call and no network to segment.

Constructed geometry · not a chart of case data
TargetKelp DAO
ActorDPRK-linked
S. Rosler9 min readConfidence: medium2 sources reviewed

An exploit of the Kelp DAO protocol reported in April 2026 has been described at around $292 million and attributed to the DPRK-linked cluster associated with earlier exchange thefts. Reporting places a further $309 million across twelve incidents in the first quarter of the year, a single protocol exploit accounting for most of it.

Almost everything this desk normally examines is absent. There is no phishing call, no stolen credential, no dwell time, no lateral movement and no log to review.

When The Application Is The Attack Surface

A decentralised protocol is code executing on a public network, holding assets, callable by anyone. There is no perimeter to defend, no privileged administrative path to protect, and no ability to disconnect while you investigate.

The consequence is that classical security controls are largely inapplicable. Segmentation, identity management, monitoring and containment — the substance of most defensive programmes — have no purchase on a flaw in logic that anyone can invoke.

Sophistication Has Moved To Where The Money Is Undefended

The same actors run long social-engineering operations against exchange staff and exploit protocol logic in the same year. That is not two capabilities. It is one objective — revenue — pursued against whichever surface is currently cheapest.

Graded medium. The loss figure and the attribution are consistently reported, but protocol exploit accounting varies between analysts and we have not reconciled the quarterly totals against a single methodology.

How we reported this

Compiled from public reporting and blockchain analysis, listed below. Loss figures vary by methodology; we give them as reported and label the source. Corrections: corrections@forensicpost.com.

Sources
  1. North Korea stole 76% of all crypto hack value in 2026 — with just two attacksTRM Labs
  2. The Lazarus Group and DPRK crypto theft in 2026sanctions.io
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary