The Attack Pattern Behind a 55% Share of Losses
Blockaid's H1 2026 security report identified a DPRK-linked attack cluster as responsible for approximately 55% of total on-chain losses, representing around $600 million. Chainalysis investigations into the April 18 KelpDAO incident, which caused approximately $292 million in losses, and the April 1 Drift attack, involving around $295.7 million, both linked the attacks to DPRK-related actors.
In the KelpDAO incident, attackers compromised internal RPC infrastructure and manipulated external node communication, causing a single-validator system to accept fraudulent source-chain messages and release rsETH from Ethereum. In the Drift incident, attackers conducted months of social engineering operations and gained administrative control through pre-signed persistent nonce transactions. Between July 23 and 24, wallets associated with the Drift attacker transferred approximately 23,095 ETH to Tornado Cash, showing that previously dormant stolen assets had entered an active laundering phase.
For institutions, public incident figures are only the starting point for risk analysis. The critical questions are where funds originated, which contracts they interacted with, who controlled the wallets, and where value ultimately moved. Aligning security incidents, market conditions and blockchain activity on the same timeline allows organizations to distinguish temporary volatility from structural risk.
Institutions should also establish behavioral baselines before, during and after major incidents. Tracking normal fund flows, wallet relationships and transaction patterns allows monitoring systems to separate legitimate market activity from abnormal behavior linked to specific threat actors.
Why Social Engineering Is Harder to Defend than Code Vulnerabilities
DPRK-linked attack groups demonstrate several characteristics: long-term persistence, cross-chain dispersion, sophisticated social engineering and significant operational resources. Unlike opportunistic attackers searching for isolated vulnerabilities, these groups often spend months infiltrating organizations, collecting credentials, gaining signing authority and compromising multiple operational layers.
This changes the security priority for blockchain organizations. Smart contract audits alone are no longer sufficient. Even audited protocols can be compromised through administrator credential theft, node infrastructure attacks, multisig compromise or failures in signing workflows.
Because these transactions may remain technically valid on-chain, traditional monitoring methods based on blacklist screening or transaction validity checks often fail to detect the compromise. The challenge is no longer only identifying invalid transactions, but determining whether valid transactions are being executed by unauthorized actors.
Money laundering patterns have also evolved. Attackers frequently keep stolen assets dormant for extended periods before moving funds through Tornado Cash, bridges and other anonymization mechanisms. This combination of long-term inactivity and rapid liquidation makes simple threshold-based monitoring ineffective.
A stronger detection framework should combine transaction velocity, fund concentration, counterparty exposure, contract privileges, historical behavior and wallet relationship graphs into an explainable risk model. Investigators need visibility into why an address is considered risky, how it connects to other entities and what evidence supports each risk decision.
High-impact incidents also require human review and secondary verification to prevent unconfirmed labels from spreading across customer accounts. Confirmed intelligence should feed back into entity profiles so future transactions receive more accurate and consistent assessments.
Tracking Strategies for Dormant Funds and Batch Laundering
Institutions should establish behavioral monitoring frameworks covering administrative wallets, bridge validators, multisig participants and protocol-controlled addresses. Monitoring should focus not only on large transfers but also on dormant wallet activation, transaction splitting, cross-chain movements and interactions with anonymization services.
Trustformer KYT combines risk intelligence, entity clustering, transaction monitoring and cross-chain analysis to help organizations track suspicious fund movements. By identifying relationships between high-risk labels, wallet clusters and transaction paths, institutions can trigger enhanced due diligence before funds enter exchanges, DeFi platforms or additional liquidity channels.
Risk responses should follow a tiered framework:
Low-risk transactions can be automatically approved.
Medium-risk cases should enter enhanced due diligence.
High-risk activities may trigger delays, restrictions or freezing recommendations.
Each alert should preserve timestamps, rule versions, transaction paths and human decisions, ensuring compliance teams, auditors and regulators share the same evidence base. This reduces duplicated investigations and prevents inconsistent risk conclusions across departments.
Management teams should regularly evaluate alert accuracy, investigation efficiency and prevented exposure, then adjust risk thresholds based on measurable outcomes. In this way, KYT becomes more than a compliance checkpoint—it becomes critical infrastructure for business continuity, security operations and risk-based decision-making.