DPRK's Wallet Graph: Crypto Heists Exposed
On-chain evidence links DPRK's cyber operations and IT revenue.
Model Diplomat9 min readAsia

The Drift-Radiant-Amnokgang Triangle: DPRK's Wallet Graph Sanctuary
How on-chain evidence linking two crypto heists to a US-sanctioned IT-worker network exposes a single DPRK wallet graph — and the AI, stablecoin and export-control gaps that keep it alive.
On April 5, 2026, four days after Drift Protocol was drained of $285 million in a 12-minute exploit on the Solana blockchain, the exchange's incident team published a post-mortem that quietly redrew the map of North Korea's crypto-theft apparatus. Drift's engineers wrote that "fund flows used to stage and test this operation trace back to the Radiant attackers" — a direct on-chain link between the April 2026 heist and the October 2024 breach of Radiant Capital, both attributed to UNC4736, Pyongyang's cyber unit tracked variously as Citrine Sleet, AppleJeus and Gleaming Pisces. The load-bearing claim is that the same wallet graph now underpins both DPRK's hack-and-steal operations and its US-sanctioned IT-worker revenue network — meaning the Drift-Radiant chain and the Amnokgang IT-worker chain, treated by regulators as separate problems, are one problem with two exit ramps. That fusion is what makes the next fight over AI-assisted social engineering, stablecoin sanctions enforcement and dual-use export controls the decisive front in the next 12 months.
What the on-chain evidence actually says
Drift's post-mortem is unusually precise. It does not assert behavioral similarity or "threat-actor signature overlap"; it asserts specific hash-level ties between the staging wallets that seeded the April 2026 attack and the wallet cluster that laundered Radiant Capital's roughly $53 million loss 18 months earlier. The intermediate addresses remain restricted to incident-response teams and law enforcement, but the attribution itself is on the record and mapped in detail by the Sanctuary Intelligence desk that first named the triangle.
The operational sophistication is documented in the American Enterprise Institute's Korean Peninsula update for April 14, 2026. UNC4736 spent six months grooming Drift by depositing more than $1 million via a third-party, non-North-Korean broker, minted roughly 750 million fake crypto assets to disguise the operation as legitimate trading, and deleted all broker communications immediately after the heist. According to
Recorded Future, the initial approach happened in person at a cryptocurrency conference — operatives from a fake "quantitative trading" firm that ceased to exist the moment the funds moved. Google Cloud's lead threat-intelligence advisor Jamie Collier, quoted in the AEI briefing, argues Pyongyang reconfigures its tactics roughly every 18 months; the Radiant-to-Drift cycle fits that clock exactly.
The heist's escape route matters as much as its execution. A class-action complaint filed May 15, 2026 in the District of Massachusetts, McCollum v. Circle Internet Group, alleges that over roughly eight hours the attackers swapped stolen Solana assets into USDC, then used Circle's Cross-Chain Transfer Protocol to bridge $230 million to Ethereum without a single freeze. The complaint states Circle's monitoring obligations arise under the Bank Secrecy Act, 31 U.S.C. § 5311 et seq., and notes that public alerts flooded X within an hour of the exploit — including Drift's own 14:10 UTC announcement to 135,000 followers. Circle allowed the bridge transactions to complete uninterrupted.
Amnokgang closes the triangle
The third vertex is a Pyongyang IT firm that most policymakers had never heard of six months ago. On March 12, 2026, OFAC sanctioned Amnokgang Technology Development Company along with six individuals in the DPRK, Vietnam, Laos and Spain, according to the US Treasury press release. The action, taken under Executive Order 13810, identifies Amnokgang as a DPRK IT company "managing delegations of overseas IT workers and conducting other illicit procurement activities to obtain and sell military and commercial technology." Treasury attributes nearly $800 million in 2024 revenue to the broader DPRK IT-worker scheme.
Three elements of the designation matter for the triangle. First, Nguyen Quang Viet — CEO of Vietnam's Quangvietdnbg International Services — is named for converting roughly $2.5 million into cryptocurrency for North Koreans between mid-2023 and mid-2025, including "illicit earnings from IT workers associated with Amnokgang." Second, Yun Song Guk is designated for leading North Korean IT workers operating out of Boten, Laos — the same border free-trade zone that appeared in OFAC's January 16, 2025 designation of Chonsurim Trading Corporation and Korea Osong Shipping Corporation, published in the Federal Register on January 23, 2025. Third, Do Phi Khanh and Hoang Van Nguyen are designated as proxies for the previously-sanctioned Kim Se Un, giving OFAC a documented cutout chain from Pyongyang's Munitions Industry Department to the Vietnamese banks that touch the crypto rails.
Chainalysis, in its supporting attribution for the OFAC action, has flagged that Amnokgang's inbound wallet traffic included proceeds from "a suspected DPRK hack." If the suspected hack is Radiant Capital — the timing, the UNC4736 attribution overlap, and the Vietnam-Laos infrastructure all fit — then Drift's staging chain and Amnokgang's revenue chain draw from a single upstream reservoir. That is not two ecosystems. It is one wallet graph running two products: cryptocurrency heists at the top of the stack, fraudulent labor at the bottom, cashed out through the same handful of Southeast Asian conversion services.

The AI, stablecoin and export-control gap
This is where the story stops being a crypto-security anecdote and starts to be about tech-policy architecture. Three regulatory workstreams — AI safety, stablecoin oversight, and dual-use export controls — are designed to police different actors. Pyongyang has quietly assembled a workflow that touches all three.
On AI, the Observer Research Foundation reports that DPRK's Research Center 227 is a dedicated AI cyber-warfare unit deploying ChatGPT, FaceSwap and generative-coding assistants to build synthetic recruiter personas and automate offensive operations. Microsoft and OpenAI have both publicly confirmed the DPRK-linked Emerald Sleet cluster's use of large language models. The
Henry Jackson Society documents that DPRK operators used ChatGPT in 2025 to forge South Korean military IDs, then supplemented the forgeries with follow-up phone calls and video appearances. The Drift approach — a fake quantitative-trading firm sophisticated enough to survive six months of due diligence — is what industrialized AI social engineering looks like in production. The EU AI Act's high-risk classifications and the model-reporting thresholds in current US executive orders were not designed to catch state actors using off-the-shelf consumer LLMs to build lifelike front companies.
On stablecoins, Circle's inaction during the Drift getaway is the point, not the outlier. A December 2025 arXiv preprint on stablecoin sanctions enforcement, covering more than $1.5 billion in frozen USDT and USDC value between November 2017 and August 2025, finds that at least 7.3% of sanctioned USDT addresses and 18.7% of sanctioned USDC addresses were drained to zero before the freeze took effect. Its game-theoretic model shows that on public blockchains, a compliance freeze is "an ordinary transaction competing with the sanctioned party's transfer for priority" — meaning ordering power, held by block producers, sits above contract-layer authority. The
Belfer Center's June 2026 analysis of the GENIUS Act notes that Chainalysis-tracked crypto value received by sanctioned entities rose 694% in 2025, with nearly 95% of inflows to sanctioned entities now moving in stablecoin. Congress regulated the mint step. The bridge, transfer and redemption steps are still open water.
On dual-use exports, Treasury's earlier designations of Liaoning China Trade for shipping notebooks, graphics cards and HDMI cables to DPRK IT workers show how ordinary consumer electronics fund the WMD program. The MSMT's October 22, 2025 report, released with a joint statement from 11 governments through the
US State Department, documents that Pyongyang stole roughly $1.19 billion in crypto in 2024 and at least $1.645 billion in the first nine months of 2025 — nearly a third of its total foreign-currency revenue for those years. The MSMT was established in October 2024 to fill the gap left when Russia's March 2024 veto disbanded the UN Security Council's 1718 Committee Panel of Experts.
Who benefits, who loses
The immediate winner is Pyongyang, which has demonstrated it can convert a single wallet graph into both a heist yield and a payroll for its overseas labor. According to the Congress.gov transcript of the House hearing on global cyber threats, CrowdStrike Falcon OverWatch responded to 304 incidents from a single DPRK threat actor, FAMOUS CHOLLIMA, in 2024 alone — nearly 40% of them insider operations. That is industrial scale. The BBC reports Lazarus operators worked "nearly 24 hours a day" to launder the $1.5 billion
Bybit haul, successfully moving $300 million into unrecoverable form within two weeks despite a Bybit-funded bounty program. Kim Jong Un's regime is running the world's most profitable cybercrime operation with a state budget behind it.
The clearest losers are US stablecoin issuers and their in-house compliance teams. The McCollum complaint is the first serious attempt to establish that a stablecoin issuer's failure to freeze in real time creates civil liability under the Bank Secrecy Act — and Circle, not Tether, is the test case. A ruling against Circle, or even a costly settlement, would push USDC's freeze-response SLAs toward minutes rather than hours and force competitors to match. Solana is a secondary loser: two of the three largest DeFi exploits of the current cycle, according to the Cross-border Law Enforcement Collaboration report from CSIS, have now happened on its infrastructure. The DeFi bank-run risk that followed the parallel KelpDAO breach is not hypothetical.
The subtler beneficiary is Beijing. The CSIS analysis notes that China is "the principal jurisdiction providing a safe haven for DPRK-affiliated actors," and that both the DPRK and China have signed the UN Convention against Cybercrime adopted by the UN General Assembly in 2024 — while the United States and South Korea have not. If Washington cannot ratify the convention it fears, and Pyongyang can shelter behind the one Beijing has signed, the multilateral chokepoint on DPRK crypto laundering will tighten only as fast as the slowest willing enforcer allows.
The historical parallel
The closest analog is not the Ronin Bridge exploit or the 2016 SWIFT-Bangladesh Bank heist. It is the mid-2000s Banco Delta Asia case, when Treasury named a Macau bank as a "primary money laundering concern" under Section 311 of the USA PATRIOT Act and effectively froze roughly $25 million of DPRK-linked funds. That action forced Pyongyang to the table at the 2007 Six-Party Talks. The lesson North Korea learned was not to stop — it was to disintermediate. The Amnokgang designation is a Section 311-style move applied to a wallet graph rather than a bank. But unlike Banco Delta Asia, which had a physical address and a fiduciary relationship with correspondent banks, Amnokgang's on-chain equivalents can be reconstituted with a new set of Vietnamese and Laotian cutouts within weeks. The Henry Jackson Society notes DPRK has netted over $2 billion in recent attacks against an economy with a GDP of roughly $35 billion — a hack-to-GDP ratio no state has ever matched.
What to watch next
- The MSMT's third report, expected in the second half of 2026, is where the Drift-Radiant wallet ties will be formally consolidated into the multilateral evidentiary record. Watch whether it names specific intermediate wallet addresses; that is the trigger for coordinated freezes across USDC, USDT and non-US exchanges.
- McCollum v. Circle's motion-to-dismiss hearing, likely in Q3 2026 in D. Mass., will set the first legal benchmark for stablecoin-issuer real-time freeze duties. A denial would open Tether to the same theory.
- OFAC's next DPRK IT-worker designation round. The March 12, 2026 sweep hit Vietnam, Laos and Spain; the next logical vector, per the Treasury pattern of steady quarterly designations, is Malaysia, Cambodia (given the Huione precedent) or the UAE.
Diplomat View
The Drift-Radiant-Amnokgang triangle is the first case in which on-chain evidence has explicitly linked a state cyber operation's heist arm to its sanctioned labor arm through a shared wallet graph. That fusion is the story. The forecast: within 12 months, Treasury and MSMT partners will publish at least one designation that names intermediate wallet addresses tied to both the Radiant staging cluster and the Amnokgang revenue chain, and Congress will legislate stablecoin freeze-response duties at the bridge and redemption steps — not just at mint. The forecast fails if the McCollum complaint is dismissed on standing grounds, if China vetoes any UN Security Council follow-up to the MSMT's second report, or if a Circle settlement is structured to avoid establishing a real-time-freeze precedent. The narrower risk is that Pyongyang skips one turn of the 18-month tactical cycle and moves the entire operation to a chain — likely TRON — where USDT dominance and looser issuer posture make freezes structurally harder. If that happens, the triangle becomes a square, and the next Drift will be indistinguishable from noise until the money is already gone.
Discover more

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
700 Activists Accuse PM Modi of MCC Breach
Over 700 activists allege PM Modi breached election code with a televised address attacking opposition parties just before state elections.

US Politics
House Ethics Committee Pushes Sexual Miscond.
The House Ethics Committee has shifted responsibility for sexual harassment settlement records to the Office of Congressional Workplace Rights, complicating disclosure efforts.

Conflict & Security
West Africa Food Crisis: Three Shocks in 2026
Conflict, climate extremes, and the Strait of Hormuz closure drive a severe food crisis in West and Central Africa, with fertilizer prices surging 80% and millions displaced.