An exploit of the Kelp DAO protocol reported in April 2026 has been described at around $292 million and attributed to the DPRK-linked cluster associated with earlier exchange thefts. Reporting places a further $309 million across twelve incidents in the first quarter of the year, a single protocol exploit accounting for most of it.
Almost everything this desk normally examines is absent. There is no phishing call, no stolen credential, no dwell time, no lateral movement and no log to review.
When The Application Is The Attack Surface
A decentralised protocol is code executing on a public network, holding assets, callable by anyone. There is no perimeter to defend, no privileged administrative path to protect, and no ability to disconnect while you investigate.
The consequence is that classical security controls are largely inapplicable. Segmentation, identity management, monitoring and containment — the substance of most defensive programmes — have no purchase on a flaw in logic that anyone can invoke.
Sophistication Has Moved To Where The Money Is Undefended
The same actors run long social-engineering operations against exchange staff and exploit protocol logic in the same year. That is not two capabilities. It is one objective — revenue — pursued against whichever surface is currently cheapest.
Graded medium. The loss figure and the attribution are consistently reported, but protocol exploit accounting varies between analysts and we have not reconciled the quarterly totals against a single methodology.
Compiled from public reporting and blockchain analysis, listed below. Loss figures vary by methodology; we give them as reported and label the source. Corrections: corrections@forensicpost.com.