$606M gone in April. Lazarus Group is running a production-grade extraction operation.
North Korea's state hacking unit accounts for 95% of April's crypto losses. The structural gap that made both attacks possible hasn't been patched.

CryptoVibe Desk · defi · security · exploits

- →Two exploits on a Solana-ecosystem protocol on April 1 and an Ethereum-ecosystem protocol on April 18 drained more than $606M, making April the worst DeFi security month in over a year.
- →Lazarus Group's attribution on 95% of April's losses confirms this isn't opportunistic bug-hunting: North Korea is running a resourced, continuous operation against DeFi's deployment surface.
- →Watch for whether either exploited protocol publishes a full contract-level post-mortem, including the diff between audit scope and deployed code, within 60 days of the attacks.
- Lazarus Group → North Korea's state-sponsored hacking unit, attributed by multiple governments and blockchain forensics firms to billions in crypto theft used to fund the regime.
- re-audit → A fresh security review required whenever a smart contract is significantly changed, because the original audit only certifies the version of the code that existed at review time.
- reentrancy bug → A smart-contract vulnerability where an attacker triggers a function to call back into itself before it finishes, draining funds repeatedly before balances update.
- mixers → Services that pool funds from multiple wallets and redistribute them in smaller amounts to obscure who sent what, used to launder stolen crypto.
Two exploits in April drained more than $606M from crypto protocols as of April 22. The first hit a Solana-ecosystem project on April 1; the second targeted an Ethereum-ecosystem protocol on April 18. Together they represent roughly 95% of the month's losses, per chain-analysis attributions. April is on track to be the worst DeFi security month in over a year.
Blockchain forensics firms attribute both attacks to Lazarus Group, North Korea's state-sponsored hacking unit. Lazarus has been converting crypto exploits into regime funding since at least 2017, and the scale has grown over that run, not shrunk. This is not an opportunistic developer stumbling onto a reentrancy bug over a weekend. It is a persistent, well-resourced adversary treating the entire DeFi deployment surface as a production target.
The mechanism matters more than the headline number. Lazarus doesn't rely on exclusive zero-days. Their operational model is closer to supply chain infiltration than brute force: read the public audit reports, map the delta between what was audited and what shipped after, identify contracts holding concentrated liquidity, and wait.
Most protocols create exactly this gap themselves. Fast shipping culture and infrequent re-audits mean an audit covers only a snapshot of the code. Migrations, parameter updates, and governance-approved changes accumulate on top of that snapshot without triggering new reviews.
DeFi security gets media coverage only after a nine-figure loss. By that point the funds are layered through mixers, on-chain attribution is finalized, and the only deliverable left is a post-mortem. The structural conditions haven't changed: protocols still ship contract updates against audits that only covered earlier versions of the code, and Lazarus has the patience and resources to map every one of those gaps.
One audit at launch is a build-time check, not a runtime guarantee. The contract running in production today may not resemble the one anyone signed off on.
Both protocols built their own attack surface by deploying contract changes that post-dated their last public audit. Any post-mortem that omits the full diff between audit scope and the code running at exploit time is a PR exercise, not accountability.
A third Lazarus-attributed exploit before Q3 2026 targeting a protocol that shipped a governance-approved contract migration in the prior 90 days without a publicly logged re-audit.
Primary links and supporting reads used by the desk for this story.
Forward this.











