April 2026 brought steady market activity on the surface, but security reports painted a harsher picture. CertiK reported that crypto-related exploits and incidents during the month produced total losses of over $650 million, a level that shook investor confidence.

The biggest hits

The largest incidents came from KelpDAO and Drift Protocol. CertiK said KelpDAO lost $292 million, while Drift Protocol lost $285.2 million.

CertiK’s breakdown links Drift’s exploit to weeks of setup and months of social engineering used to access protocol signers. It also says the funds were drained in about 12 minutes.

For KelpDAO, CertiK traced the incident to a single-verifier flaw in a LayerZero bridge. CertiK added that attackers later moved funds through THORChain after more than $70 million was frozen on Arbitrum.

Other incidents cited by CertiK included Rhea Finance at $18.4 million and Grinex at $16.2 million.

Losses skew by type and attacker pattern

CertiK said the largest slice of losses hit DeFi, at $609.3 million. Within loss categories, wallet compromises accounted for $611 million, with price manipulation at $18.8 million, code vulnerabilities at $16.9 million, phishing at $3.5 million, and front-end attacks at $544.7k.

Fewer attacks, higher losses

The pattern gets more specific when TRM Labs data is brought in. TRM Labs said North Korean hacking groups made up 76% of all crypto hack losses through 2026 to April. The source text stresses that this did not come from more attacks. Instead, two major incidents alone drove $577 million in losses.

TRM Labs also described a long-running trend tied to that strategy. The source text says North Korea’s share of total crypto theft rose from under 10% in 2020 and 2021 to 22% in 2022, 37% in 2023, 39% in 2024, and 64% in 2025. It attributes the 2025 jump largely to the Bybit breach, where $1.46 billion was taken via a compromised Safe{Wallet} signing interface, noted as the largest crypto hack recorded so far.

The source text adds that North Korea’s total crypto theft has now crossed $6 billion since 2017, according to TRM Labs. It also says experts believe these groups may use AI tools to improve reconnaissance and social engineering for more targeted exploits.