Episode Summary
Executive Summary: The episode examines how North Korea, Iran, and other state actors use crypto for cybercrime, laundering, and sanctions evasion. TRM Labs’ Ari Redbord argues North Korea’s Lazarus ecosystem has industrialized theft and now targets DeFi via social engineering, while the best response is a mix of hardened protocol security, real-time interdiction, asset seizures, and public-private offensive cyber coordination.
Main Topics: North Korea’s crypto crime machine (Priority: 5/5): Redbord frames North Korea as a true state actor that has professionalized cybercrime to fund weapons proliferation, with crypto serving as the latest and most scalable theft-and-laundering channel. The Drift hack as a social-engineering watershed (Priority: 5/5): The Drift exploit is described as unusually sophisticated: North Korean proxies allegedly met protocol staff at conferences for months, then used validator access and pre-signed transactions to drain funds quickly. How North Korea launders stolen crypto (Priority: 5/5): The conversation details North Korea’s laundering playbook: rapid movement across chains, use of mixers and bridges, off-ramping through OTC brokers and Chinese laundering networks, and attempts to convert assets into spendable forms quickly. Law enforcement, forfeiture, and Beacon Network (Priority: 4/5): Redbord emphasizes a shift from arrests to asset seizure/forfeiture, and describes Beacon Network as a real-time perimeter for blocking illicit flows across exchanges, fintechs, and some DeFi services. Privacy vs. security in crypto (Priority: 4/5): The discussion explores whether privacy tools like Tornado Cash or shielded transactions are legitimate civil-liberties features or tools that can be abused by criminals, with Redbord arguing privacy and security can coexist. Iran, sanctions evasion, and only-in-crypto enforcement (Priority: 4/5): The episode broadens to Iran’s use of crypto infrastructure, including sanctioned wallets and exchanges, showing how states use blockchain rails to move funds despite sanctions and visibility. Victim restitution and whole-of-government response (Priority: 4/5): Redbord calls for a victim compensation/restoration fund and a broader interagency strategy, arguing that scams and transnational crypto crime should be treated as national security issues.
Key Arguments: North Korea is not merely a proxy actor; Redbord says it is the North Korean government itself operating a professionalized cyber army to steal and launder funds for the regime. Crypto has dramatically improved North Korea’s ability to generate revenue, with roughly $6 billion stolen over five years and about $1 billion per year on average, making it a major funding source for weapons programs. The Drift hack illustrates a new phase of attack: social engineering of people and organizations, not just technical exploits, including conference infiltration and long-term relationship-building. North Korea launders aggressively and quickly, often using bridges, mixers, OTC brokers, Chinese money laundering networks, and centralized services to off-ramp into usable value. The best defense is not to shut down crypto but to harden protocols, share intelligence in real time, seize assets, and use offensive cyber tools against adversaries. Public-private cooperation is essential because blockchain data gives investigators visibility that traditional finance lacks, but law enforcement still needs subpoenas, exchange cooperation, and operational tools. Privacy-preserving technology is not inherently bad; Redbord argues the goal should be lawful privacy with mechanisms to stop sanctioned or illicit flows, not blanket surveillance or blanket bans. Victim restitution should be institutionalized through a dedicated fund so that scam victims can recover losses at scale rather than relying on ad hoc forfeiture outcomes.
Data Points: Drift hack value: $285 million - North Korea drained a perps protocol on April 1 in a 12-minute attack. Share of 2026 hack value from two accounts: 76% - A TRM report said two accounts, including Drift and Kelp DAO, accounted for 76% of hack value so far in 2026. Average annual North Korea crypto theft: about $1 billion per year - Redbord said North Korea has been stealing roughly this amount annually in recent years. Estimated total North Korea crypto theft: $6 billion over the last five years - TRM’s report cited this cumulative figure for North Korean crypto theft. Bybit hack: $1.5 billion - Used as the largest example of a North Korean crypto theft and laundering case. Kelp DAO hack: about $300 million - Referenced as another major recent DeFi exploit tied to North Korea. Ronin Bridge hack: $600 million - Described as a watershed North Korea-linked hack that increased government attention. April hack frequency: one every 27 hours - The hosts described April as a particularly bad month for DeFi hacks. Crypto crime in 2025: $158 billion - TRM’s reported estimate for total crypto crime in 2025. Lawful crypto activity share: 98%-99% - Redbord noted that most crypto activity remains legitimate despite headline crime figures. Illicit crypto activity share: about 1.3% - TRM estimate of illicit activity within the crypto ecosystem. Tether freeze action: $344 million USDT on Tron - Referenced in connection with Iran and sanctions enforcement. Prince Group forfeiture: $15 billion / 127,000 BTC - A DOJ/FBI seizure in a Cambodia-linked pig butchering case. Bybit laundering speed: within 72 hours - Redbord said North Korea converted almost all stolen ETH to Bitcoin in that window. Beacon Network coverage: about 85% of centralized crypto - Redbord said the network includes major exchanges and financial services. North Korea theft from Drift: 31 withdrawals in 12 minutes - Programmatic withdrawals followed pre-signed transactions after access was obtained.
Pivotal Quotes: "These are state actors, hard stop." — Ari Redbord: He rejected softer terminology and insisted North Korea is the regime itself, not merely a proxy or sponsor. "This is bank robbery at the speed of the internet." — Ari Redbord: He used this phrase to explain how crypto changed the scale and speed of North Korea’s theft model. "We need to stop blaming the victims here. Essentially, North Korea is attacking these projects at scale. We got to attack North Korea." — Ari Redbord: He argued for offensive cyber and stronger state response rather than treating protocols as the sole problem.
Implications: The episode argues crypto crime is now a national-security problem, not just a compliance issue. Expect more emphasis on real-time interdiction, protocol hardening, sanctions enforcement, and privacy designs that preserve lawful use while blocking illicit flows.