
TRM Labs tracked $972M in H1 hack losses, 66% tied to DPRK. Laundering now favors bridges and no-KYC swaps before OTC cash-out via Chinese brokers.
North Korean state-backed hacking crews have accelerated their laundering flow, compressing the time between exploit and cash-out. TRM Labs counted roughly $972 million in total hack losses during the first half of 2026, with about 66% of that tied to DPRK-linked actors. Two incidents in April – the Drift and KelpDAO exploits – alone totaled roughly $577 million combined, according to the analytics firm.
The pattern follows a compressed sequence. Attackers drain funds from a validator key leak, a bridge bug, or a governance permissions slip, pushing assets to fresh, unlabeled addresses within hours. The scramble phase hits one or more cross-chain bridges before the victim confirms the exploit. TRM Labs said the largest H1 heists moved through bridges first, then no-KYC swap aggregators. Funds later reached exchanges or OTC desks.
Bridges break simple heuristics. Moving assets between chains strips away context tied to the source chain. No-KYC swap aggregators and high-liquidity DEXs convert the stolen tokens into stablecoins and liquid majors, splitting amounts into smaller packets across multiple wallets before reconsolidation. CoinDesk reported July arrests tied to North Korea laundering, where suspects allegedly converted crypto into U.S. dollars and yuan through Chinese OTC brokers. Transfers were split into small amounts to avoid detection, the report said.
The exit relies on human counterparties. OTC desks willing to take stablecoins and return fiat, or brokers providing prefunded exchange accounts and cash-out services, bridge the crypto and cash worlds. The July case outlined a network of brokers who helped convert stolen funds to fiat, the report said.
Regulators have responded. Canada's FINTRAC on July 15, 2026, reiterated FATF concerns and urged enhanced AML and CFT measures for potential DPRK-linked transactions. The advisory pressed reporting entities to screen for sanctions-evasion risk and report anomalies. The messaging tracks broader international guidance to plug OTC gaps and scrutinize cross-chain activity.
Mixers have not disappeared. Bridges and no-KYC swaps are faster and do not block on pool depth or sanctions lists the same way. The mechanics favor whoever acts first. Every additional hop buys the attacker time. TRM Labs said the concentration of losses in a handful of infrastructure compromises compressed attention on the plumbing itself. April had fewer incidents but wildly oversized dollar impact.
For protocols, the defensive toolkit is familiar: rate limits on sensitive contract functions, time-locked admin actions, emergency pause mechanics, and real spending on external audits and live bug bounties. For exchanges and OTC desks, enrichment of deposits with taint-aware scoring at mempool time, triage on bridge-originated flows, and gated withdrawals from fresh accounts receiving suspect funds in the first 24 hours. For users, stingy approvals, blocked defaults on novelty dApps, and monthly revoke checks.
The direction is clear even if enforcement across borders remains uneven. TRM Labs noted the laundering playbook now favors speed and cross-chain agility. The next test will come when a new infrastructure compromise tests how fast defenders can cut the route before the second or third conversion into stablecoins.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.